AI tools and the GDPR: what companies really have to check
Not every AI tool is ruled out on data protection grounds, but every one needs a check. An overview of the points that actually count.

The data processing agreement is the entry ticket
As soon as personal data reaches an AI tool, and that starts with a name in a cover letter, you need a data processing agreement under Article 28 GDPR. Most large vendors provide one for their business plans; consumer plans generally do not include it.
That is the fastest filter: no agreement, no professional use involving personal data. Check the list of sub-processors as well, since models frequently run at a different provider than the one you signed with.
Where is the data processed?
Processing in the United States is possible under the EU-US Data Privacy Framework if the vendor is certified. Do not rely on marketing claims: certification can be looked up in the official list kept by the US Department of Commerce.
Several vendors now offer processing exclusively within the EU. For public bodies, healthcare and legal services that is often the most pragmatic route, as are open models running on your own infrastructure.
Switch off training on your inputs
The single most important switch: are your inputs used to improve the models? In business plans that is usually disabled by default, in free and consumer plans frequently not.
Check retention as well. Some vendors keep inputs for a few weeks for abuse detection even when they do not feed training. For particularly sensitive data you may need a contractually assured zero-retention setup.
Records, impact assessment, data subject rights
Every AI use involving personal data belongs in your record of processing activities. Extensive or systematic processing, screening job applications for instance, additionally triggers a data protection impact assessment.
Remember data subject rights: access, rectification and erasure must remain possible even when data has been processed in an AI service. Clarify in advance how the vendor handles deletion requests.
The AI Act: a second layer
Since 2024 the AI Act sits on top. Two points are relevant for most companies: systems with unacceptable risk are prohibited, and synthetically generated or manipulated content must be labelled. Anyone letting staff use AI must also ensure sufficient AI literacy.
High-risk applications, in HR or credit decisions for example, carry considerably stricter obligations. Check early whether your use case falls into that bracket.
This text does not replace legal advice. It names the points to bring into a conversation with your data protection officer.
Order of checks: data processing agreement in place? Processing location clarified? Training switched off? Recorded in your processing register? Labelling duties under the AI Act considered?
Tools discussed in this article
Each tool has a full review with scores and pricing.
Le Chat
Mistral AIA European alternative with EU servers and open models.
DeepL
DeepL SETranslation at reference level, from Cologne, with European data protection.
Stable Diffusion
Stability AI / Open SourceOpen models for your own hardware: maximum control, maximum effort.
ElevenLabs
ElevenLabsSpeech synthesis that barely sounds synthetic any more, including in German.
We test AI tools on real work, with accounts we pay for ourselves, and write down what comes out of it, even when that is unspectacular. [Setup note: replace with the real author.]

