Why generative AI has become a quiet data protection risk
Generative AI has quickly become a natural part of many employees’ daily work. They paste in a customer contract to have it summarised, an HR matter to get help with wording or a requirements specification to have it improved. Productivity rises immediately, and that is precisely why the risk is so easy to miss. With every such input, sensitive data may leave the company’s control, often without anyone having made a deliberate decision about it.
The problem is not the technology itself, but where and how it is used. When personal data or trade secrets are fed into a tool that is neither bound by confidentiality nor guarantees that the data is not stored or used to train the model, the company risks breaching data protection. This article explains where the risks lie, how supplier contracts for AI should be designed and how you let employees benefit from generative AI without exposing the company.
Where GDPR meets generative AI
Data protection does not care whether a tool is new or clever, but about what happens to the personal data. Generative AI challenges several of the framework’s cornerstones at once.
Legal basis and purpose
All processing of personal data requires a legal basis and a clear purpose. Feeding data into an AI tool is processing, and if the purpose is unclear or the legal basis is missing, the processing is itself problematic, however useful the result feels. Companies therefore need to know not just that they use AI, but on what basis and for what purpose.
Where does the data end up?
The decisive question is what the tool does with what is entered. Is the data stored? Is it used to train the model? Is it transferred to countries outside the EU? A general consumer tool rarely gives clear guarantees on these points, and without them the company loses control of the data the moment it is pasted in. Specialised solutions that have contracted away storage and training, and that keep data within the right geography, do the same job without the same exposure.
The supplier contract is where the risk is decided
For most companies the data protection risk is decided not by how AI works technically, but by what the contract with the supplier says. A well-considered contract clarifies whether the supplier is a processor and binds it to handle the data only on instruction. It governs confidentiality, prohibits or limits the use of your data for model training, establishes where the data may be processed and secures your rights to erasure and review.
Without these terms the company carries a risk it may not even be aware of. With them, generative AI is transformed from an uncontrolled exposure into a tool on the company’s terms. Reviewing and negotiating these contracts is therefore not a technical detail but the core of responsible AI use.
A practical example: the summary that became a data protection breach
Imagine a company where the HR department has started using a general AI tool to summarise and structure sensitive personnel matters, including information about health and conflicts. It saves time, and the practice quickly spreads through the team.
What no one has considered is that the tool is neither contracted as a processor nor guarantees that the data is not stored or used for training, and that particularly sensitive personal data has thereby left the company’s control without a legal basis. When the question is raised internally, the company faces an ongoing unlawful processing, an unclear picture of where the data has gone and a notifiable incident to handle. A clear policy on what may be entered where, and a tool with the right contract, would have delivered the same time saving without the breach.
Common mistakes companies make
The first mistake is to treat AI tools like any office tool and overlook that every input of personal data is processing governed by GDPR.
The second mistake is to lack a policy on what employees may enter into which tools. Without clear rules, shadow use arises, where well-meaning employees expose the company in the pursuit of efficiency.
The third mistake is to rely on a tool’s general marketing about security rather than on what the contract actually says. It is the contractual terms, not the promises, that determine where the data ends up.
Legal risks
The risks are concrete and cumulative. Processing without a legal basis, insufficient information to data subjects or transfer of data outside the EU without the right protection are all breaches covered by the data protection sanctions regime, with significant maximum fines. Feeding trade secrets into a tool without confidentiality can also reveal information the company has a strong interest in protecting.
Beyond the sanctions there is the trust risk. Customers, employees and partners expect their data to be handled with care, and a company found to have leaked sensitive information through careless AI use damages a trust that takes a long time to rebuild.
Recommended actions
Start by mapping where in the organisation generative AI is already used and what data is being entered. Then establish a clear policy on what may be entered into which tools, and make sure employees understand it.
Review and negotiate the contracts with your AI suppliers so that they govern the processor relationship, confidentiality, training, geography and your rights. Choose specialised solutions for sensitive data, and secure a legal basis and information to data subjects where required. Treat this as a living issue and revisit both policy and contracts as use and the rules evolve.
Frequently asked questions about generative AI and GDPR
Is it illegal to use generative AI in our company?
No, but it must happen within the bounds of data protection. With a legal basis, a clear policy and the right supplier contract, generative AI can be used lawfully. The risk arises when sensitive data is fed into tools without these protections.
What is the most dangerous mistake?
Pasting personal data or trade secrets into a general AI tool that is neither bound by confidentiality nor guarantees that the data is not stored or used for training. The data then leaves the company’s control.
How do we know if our AI tool is safe from a GDPR perspective?
The answer lies in the contract, not the marketing. Check whether the supplier acts as a processor, whether your data is used for training, where it is processed and what rights you have to erasure and review.
Do we need a data processing agreement with our AI supplier?
If the supplier processes personal data on your behalf, such an agreement is generally required. It binds the supplier to process the data only on your instructions and with the right safeguards.
Is it enough to train staff?
Training is important but not sufficient. It needs to be combined with a clear policy and with supplier contracts that actually protect the data, because even a well-trained employee needs secure tools to work in.
Summary
Generative AI is a powerful tool, but it meets data protection the moment personal data is entered. The companies that get into trouble rarely do so out of malice, but because well-meaning employees sought efficiency in tools that were never contracted for the company’s sensitive information. Those who instead set a clear policy, choose the right tools and negotiate the right contracts can make full use of generative AI without losing control of their data.
Lawgent helps companies use generative AI in a way that holds up legally, from policy and mapping to review and negotiation of supplier and processor contracts. We combine experienced business-law advice with AI-driven efficiency, so you get clear, practical guidance faster and more cost-effectively than at a traditional firm. Want to know whether your AI use measures up under GDPR? Contact Lawgent for a review.
