August 29, 2026

GDPR-Compliant AI: Why It Matters More Than Ever

Your employees are already using ChatGPT and Claude — often with customer data. What that means legally, where business plans stop helping, and how your own AI infrastructure solves it.

Taha Bisgin 8 min read

Over the past few months, we kept coming back to one question:

How can we help companies adopt AI without giving up data protection and security?

To answer it, you first need to understand why the question matters at all.

Why companies can’t simply use ChatGPT and Claude directly

The biggest problem isn’t the quality of the answers. That has long been good enough to make a real difference in almost any workflow.

The problem is where the data goes along the way.

When an employee pastes a customer list, a draft contract, or a sick note into a public AI tool, that information leaves your company. As a rule, it also leaves the EU. And at that moment, a productivity question turns into a legal one.

That exact point — the transfer of personal data to the US — produced the largest GDPR fine ever issued: €1.2 billion against Meta, handed down by the Irish Data Protection Commission in 2023. Not for a hack. Not for a data leak. But because Europeans’ data ended up on systems that US authorities can access.

Let’s be honest: your employees are already using AI

Most managing directors we speak to underestimate how widespread this already is inside their own company.

Figures from the German industry association Bitkom, based on a representative survey of 604 companies with 20 or more employees, paint a clear picture:

  • 4 in 10 companies assume employees use private AI accounts for work
  • In 8 percent of companies this is widespread — twice as many as the year before
  • Yet only 26 percent provide their staff with official AI access at all
  • And only 23 percent have established rules for using AI

That gap is the actual problem. Your employees want to work faster. If you don’t give them an approved tool, they’ll reach for the next best thing — through a private account, around IT, with no record of what was typed into it.

It’s called shadow AI. And it’s expensive.

What data protection violations involving AI actually cost

The framework is well known: the GDPR allows fines of up to €20 million or 4 percent of global annual turnover — whichever is higher.

Since 2 August 2025, the EU AI Act adds its own, sharper regime on top: up to €35 million or 7 percent of global annual turnover for prohibited practices, and up to €15 million or 3 percent for breaches of other obligations.

Those are ceilings. What actually gets imposed is more instructive:

  • €1.2 billion against Meta for the unlawful transfer of user data to the US (May 2023)
  • €15 million against OpenAI from the Italian authority Garante — in part for processing personal data in ChatGPT’s training without a valid legal basis (December 2024)

And then there are the costs no regulator imposes. IBM’s Cost of a Data Breach Report 2025 lists shadow AI among the three most expensive breach factors for the first time. Organisations with high levels of shadow AI paid on average $670,000 more per incident than those with little or none.

For context: a data breach costs a German company an average of €3.87 million.

It isn’t only about customer data

Personal data gets all the attention because it’s regulated. The second kind of loss is routinely overlooked.

When an employee pastes your pricing model, your proposal template, your source code, or your sales strategy into a public tool, they are handing over a trade secret. No regulator will fine you for it — but it can cost you considerably more than a fine would.

Under German trade secret law, a secret is only protected for as long as you can demonstrate appropriate confidentiality measures. A company with no rules for AI use loses exactly that evidence when it matters.

What about the business plans from OpenAI, Anthropic, and Google?

That’s the obvious question — and the good news is that business and enterprise plans genuinely solve a large part of the problem.

They typically include:

  • a data processing agreement (DPA) under Art. 28 GDPR
  • a contractual commitment that your inputs are not used to train the models
  • admin controls, logging, and central user management
  • with some providers, the option to have data processed inside the EU

For a large share of mid-sized companies, this is a sensible and workable path. We recommend it regularly. A company that has shadow AI today and a clean business plan with clear rules tomorrow has cut its risk substantially.

But for some industries, it isn’t enough.

Where business plans stop helping

There are two reasons a DPA alone doesn’t always do the job.

1. Server location isn’t what decides

The US CLOUD Act of 2018 obliges US providers to hand over data on the order of US authorities — regardless of where that data is stored. What matters is not the storage location but control over the provider. A data centre in Frankfurt offers no protection if the parent company is subject to US law.

The EU-US Data Privacy Framework cushions this legally and remains valid. But it stands on noticeably shakier ground than it did at adoption: Philippe Latombe’s challenge was dismissed by the EU General Court on 3 September 2025, but the appeal is now before the Court of Justice. The PCLOB — one of the US oversight bodies the European Commission explicitly relied on in its adequacy decision — has lacked a quorum since January 2025. And in July 2026, the European Data Protection Board asked the Commission to review the framework again.

Nobody knows how that ends. But if your entire AI strategy rests on an adequacy decision that is currently under review, you’re carrying concentrated risk.

2. For professional secret holders, this is criminal law — not just GDPR

This is the part most companies miss.

In Germany, tax advisors, lawyers, doctors, and auditors are professional secret holders under § 203 of the Criminal Code (StGB). Disclosing someone else’s secret without authorisation is a criminal offence, punishable by up to one year’s imprisonment or a fine. In this constellation, a public AI service is legally a third party.

Since the 2017 reform, external service providers may be brought in as cooperating persons. But that comes with an additional requirement many firms aren’t aware of:

A GDPR data processing agreement is not sufficient. A separate confidentiality undertaking is required — for tax advisors under § 62a StBerG, with an explicit reference to the criminal consequences of a breach.

For banks, insurers, and parts of the healthcare sector, supervisory requirements come on top. For these organisations the question isn’t which plan to buy. The question is whether the data may leave the building at all.

Often, the answer is no.

The solution: your own AI infrastructure

The approach that solves this at the root is your own AI infrastructure — open models running on your own server or on a VPS with a German hosting provider.

The obvious advantage: the data stays where it is. No third-country transfer, no CLOUD Act, no reliance on an adequacy decision that’s currently in court. What you type in doesn’t leave your infrastructure.

The less obvious advantage is, in our view, the more important one.

When the infrastructure is yours, you can build specialised agents instead of using a general-purpose chat window. An agent for proposals that knows your pricing logic and your standard wording. An agent for incoming mail that pre-sorts documents and files them against the right cases. An agent for searching your own records that only reaches what a given role is allowed to see.

Each agent gets a clearly bounded scope, its own permissions, and its own data. That isn’t just safer — it’s simply better, because a specialised agent produces better results than a chat window every employee has to re-explain the business to each morning.

Over time, this builds something a subscription never can: a chain of working steps that actually reflects how your company operates.

And getting it running is the start, not the finish. Models get updated, permissions change, processes shift. That’s exactly why we see our job as running it, not setting it up.

How to get started

You don’t need to rebuild your entire IT for this. In most cases it starts with three steps:

  1. Take stock — which AI tools are actually in use in the building, and with what data?
  2. Stop the bleeding — one clear written rule and one approved access point, so the shadow AI ends
  3. Build — your own infrastructure wherever the data isn’t allowed to leave the building

Step 2 is often done within days and takes the pressure off immediately. Step 3 is an investment decision — and one you should only make if it genuinely pays off in your specific case.

Conclusion

AI use is no longer a question about the future of your company. It’s already happening — the only question is whether it happens under your rules or without them.

For many companies, a properly configured business plan with clear policies is the right answer. For law and tax firms, banks, insurers, and anyone handling professional secrets, there is usually no way around your own infrastructure.

If you’d like to know which of the two is right for you: book a free initial consultation. In under 15 minutes we’ll tell you honestly whether your own AI infrastructure is worth it — or whether the simpler route serves you better.


This article is not legal advice. To assess your specific situation, please speak with your data protection officer or legal counsel.

Sources: Bitkom, shadow AI (October 2025) · IBM Cost of a Data Breach Report 2025 · PwC Legal on the Meta fine · GDPR portal on the OpenAI fine