Under the GDPR, personal data must be processed lawfully, minimised and protected. Generative AI does not create an exception. If prompts contain personal data, you are still responsible as a controller.
Core GDPR questions for AI projects
- What personal data enters prompts?
- Who is the processor for the model provider?
- Can we minimise or anonymise before transfer?
- How do we demonstrate accountability?
Practical controls
- Separate public research from private documents.
- Mask PII before model calls (AI Vault).
- Prefer approved enterprise workspaces over personal accounts.
- Keep logs and policies for accountability.
- Align high-risk use cases with DPIA thinking.
International note
Many Swiss SMEs must also consider the revised FADP when personal data of Swiss residents is processed, and the EU AI Act for governance of AI systems used in the organisation.
Conclusion
GDPR-ready AI is not a slogan. It is process + tooling. TrustAI helps SMEs combine productivity with minimisation and evidence.
CTA: Start TrustAI and document AI usage with Vault and admin controls.
FAQ
Does GDPR apply to ChatGPT usage?
Yes when personal data is processed. The company remains responsible for purpose, minimisation, security and processor choices.
Is anonymisation enough?
Tokenisation and masking before the model reduce exposure. You still need policies, access control and documentation for accountability.