Focus area

AI and GDPR: use AI without putting personal data at risk

GDPR does not prohibit AI. It sets requirements for how you use it — which data is sent where, on what basis, and with which agreements behind you. I build AI solutions where compliance is designed in from day one: from data processing agreements and EU hosting to AI agents that run locally, so data never leaves the building.

AI without GDPR governance
  • Employees paste customer data and CPR numbers into private chatbot accounts without a data processing agreement.
  • Nobody knows which data is sent to which providers — or whether it is used to train the models.
  • Personal data is processed without a purpose, legal basis or documentation — and cannot be deleted again.
  • Risk of orders and fines from the Danish Data Protection Agency — and of losing customer trust that is hard to rebuild.
GDPR-safe AI
  • Data processing agreements with all AI providers — and guarantees that your data is not used for training.
  • Personal data is minimised, pseudonymised or kept entirely out of what is sent to the model.
  • Data is processed in the EU — or entirely locally on your own server, where nothing leaves the building.
  • Documented data flows, clear guidelines for employees and logging of what the AI has access to.

How to stay GDPR compliant with AI

1

Map data and purpose

Before anything is sent to an AI model, you need to know which data is involved: Is there personal data in emails, documents or customer history? What will the AI use it for? Without that overview you cannot be compliant — with it, the rest is manageable.

2

Legal basis and data minimisation

All processing of personal data requires a legal basis — typically contract, legitimate interest or consent. And the AI should only see the data the task requires: if it is drafting a reply, it does not need the customer’s entire case history.

3

Data processing agreement and provider choice

The AI provider is your data processor, and a data processing agreement (DPA) must be in place. I choose set-ups where your data is not used for model training, where storage can be switched off (zero data retention), and where processing can take place in EU data centres.

4

Pseudonymisation and access control

Names, CPR numbers, email addresses and other identifiers can be masked automatically before the text is sent to the model — and reinserted in the reply. And the AI must never be able to see more than the employee using it: access control follows through all the way.

5

Risk assessment when required

If the solution processes sensitive information or many data subjects, a data protection impact assessment (DPIA) may be required. I provide the technical documentation — data flows, storage, security measures — that the assessment builds on.

6

Guidelines, logging and deletion

Employees get clear rules for what may and may not be shared with AI. The solution logs what has been processed, so you can respond to subject access requests — and deletion routines ensure data is not kept longer than allowed.

I am an engineer, not a lawyer: I build the solutions so they can meet the requirements, and I provide the documentation — the legal assessment is something you do with your DPO or adviser.

Run AI locally — when data must not leave the building

The strongest GDPR guarantee is that data is never sent out of the company at all. Modern open-source models have become so good that AI agents can now run on your own hardware — and there are several levels to choose from:

Local models on your own server

Open-source models such as Llama, Mistral and Gemma run on your own machine or server — via tools like Ollama or vLLM. No data leaves the network, and there is no per-call usage billing.

Local AI agents

Agents that read documents, answer emails and write minutes can run entirely locally: the model, your documents and the agent’s memory all stay on your own infrastructure — including search across your own data (RAG).

Self-hosted in EU cloud

If you lack the hardware, the same set-up can run on rented servers in European data centres — with a data processing agreement and full control over where data resides. You get the flexibility of the cloud without sending data out of the EU.

Hybrid: local + cloud

The most pragmatic option for many: personal data and confidential documents are processed locally, while general tasks without personal data go to the big cloud models. You get the best of both worlds — compliantly.

Which level is right depends on your data, budget and quality requirements — local models have become impressive, but for the hardest tasks the cloud models are still ahead. I help you find the right balance.

Typical tools in the toolbox

Data processing agreements (DPA)EU data centresZero data retentionNo training on your dataPseudonymisationOn-prem LLM (Ollama/vLLM)RAG with access controlAudit logDeletion routinesAI policy for employees

And remember: GDPR is no longer the only rulebook. The EU’s AI Act is being phased in over the coming years and includes requirements for transparency and risk management. Build your solution properly from the start and you are well placed there too.

What it means for you

Peace of mind

You know exactly which data is processed where — and can document it to customers, your DPO and the Danish Data Protection Agency

Data in-house

With local models and agents, the most sensitive tasks can be handled without a single document leaving your infrastructure

Full speed on AI

Compliance becomes a framework, not a brake — employees can use AI safely instead of in secret

The content here is technical guidance, not legal advice — the specific assessment always depends on your data and set-up.

Want to use AI — without the GDPR headache?

Free of charge, I review your use of AI and personal data — and show what a compliant solution could look like, in the cloud or on your own server.

Book a free AI discovery call →