AI and Data Protection for Businesses

The moment employees start pasting customer data, contract drafts, or internal figures into ChatGPT or Claude, a question comes up that many companies still haven't answered: is that actually allowed? The short answer is yes, but only once a few things are sorted out before the data leaves the building.

We break down which data protection questions actually matter when using AI language models, and how InnoGE/deckname makes sure personal data never reaches someone else's cloud unprotected in the first place.

The topic in brief

  • Using ChatGPT and Claude is fundamentally permitted: what matters is which data you enter and whether a data processing agreement exists with the provider.

  • The most robust solution is technical, not just contractual: if personal data never reaches the provider in plain text in the first place, most of the legal uncertainty disappears.

  • InnoGE/deckname handles exactly that: it detects and replaces sensitive data before a text ever leaves your own infrastructure.

Expert tip: a data processing agreement governs what the provider is allowed to do with the data. It doesn't stop an employee from accidentally entering too much. Both together make the real difference.

Tim Geisendörfer

Tim Geisendörfer

Founder & CEO

Shadow AI: the underestimated risk

Even if a company has a clean agreement with OpenAI or Anthropic, that doesn't mean employees actually use it. In practice, many keep working with their private ChatGPT account, because it's already set up, the switch to the company account never got communicated, or logging in there feels like more hassle. For IT and data protection teams, this is invisible, until something goes wrong.

Technology alone can't solve this. It takes a clear, communicated rule: which tools are approved, with what access, and what should never be entered under any circumstances. Without that rule, any agreement with the provider stays theoretical, the real decision happens at each employee's own computer.

The practical solution: anonymization before the cloud

Contracts and legal grounds are one side of this. The more robust solution sits one layer earlier: if an AI language model never sees personal data in plain text, many of the questions above stop being sharp problems in the first place.

That's exactly why we built InnoGE/deckname: our own AI model for text anonymization that detects personal data and replaces it with consistent placeholders, before a text ever reaches a cloud language model like ChatGPT or Claude. Deckname runs entirely in your own infrastructure, no GPU needed, in milliseconds. For more on how it works, benchmarks, and a live demo, see our in-depth article on InnoGE/deckname.

In practice, it looks something like this: "Mr. Weber from 12 Bahnhofstraße in Kassel is asking for a callback about invoice 4471" becomes "PERSON_1 from ADDRESS_1 is asking for a callback about invoice NUMBER_1" for the language model. The model still answers the actual request correctly, but never sees who the real person is. On the way back, Deckname swaps the placeholders for the real values again.

Data processing agreement alone vs. with anonymization

A DPA and a technical anonymization layer solve different problems, they work best together.

Protection against accidental input

Data processing agreement only

Only takes effect after the data has already reached the provider

DPA + anonymization (InnoGE/deckname) Recommended

Personal data is detected and replaced before transmission

Effort when switching providers

Data processing agreement only

Needs review and signing for every new provider

DPA + anonymization (InnoGE/deckname) Recommended

Works regardless of which language model is behind it

Relevance for international transfers

Data processing agreement only

Governs the transfer, but doesn't reduce it

DPA + anonymization (InnoGE/deckname) Recommended

Less personal data leaves the region in the first place

Special requirements by industry

The points above apply to every business. Some industries add stricter requirements on top. We've written dedicated guides for three of them:

  • AI in healthcare – health data counts as especially sensitive under GDPR Art. 9

  • AI in finance – banking secrecy, DORA, and third-party risk

  • AI in banking – automating customer service and credit checks securely

The internal AI policy as the foundation

Contracts with providers and a technical anonymization layer together solve most of the problem. What's often missing is the third layer: a short, clear policy that tells every employee which AI tools they can use, with what access, and which data should never be entered.

A policy like this doesn't need to run twenty pages. What matters more is that it actually gets read and understood: which tools are approved, how access through the company account works, and who to ask when unsure. Without that framework, every technical and contractual safeguard depends on individual discipline.

Expert tip: when it comes to personal data, a tool that makes big promises with no evidence to back them up doesn't help. Ask for benchmarks, not claims.

Tim Geisendörfer

Tim Geisendörfer

Founder & CEO

Ready to roll out AI in your business, compliantly?

Let's talk through, in a free, no-obligation conversation, where AI can start safely in your business, including anonymization through InnoGE/deckname.

FAQ – AI and data protection

ChatGPT itself can be used in a data-protection-compliant way if a data processing agreement exists with OpenAI, an appropriate legal basis covers the transfer to the US, and training-data use is contractually excluded. Compliance depends on how it's actually used, not on the tool alone.

Whenever personal data is transmitted to the provider. For fully anonymized input, this requirement no longer applies, since no personal data is being processed anymore.

Legally, yes. In practice, it doesn't stop employees from accidentally entering overly sensitive data. A technical anonymization layer like InnoGE/deckname reduces that risk further, regardless of the contractual situation.

InnoGE/deckname has been benchmarked on German text-anonymization datasets and outperforms Microsoft Presidio and open specialist models there. See our article on InnoGE/deckname for details. As with any detection system, we also recommend testing it against a sample of your own documents.

Healthcare, finance, and banking come with additional requirements, see our industry-specific guides for details. For most other industries, the general data protection basics described here apply.

Shadow AI means using AI tools through private accounts or without IT's knowledge, for example when employees use their personal ChatGPT account for work. The best defense is usually a combination of approved, easily accessible company accounts and a clear, communicated policy, rather than banning AI tools outright.

Yes. The data processing agreement governs the relationship between your company and the provider. It says nothing about what individual employees actually enter. An internal policy closes exactly that gap.

Let's talk about your project

Book a free appointment directly or send us a message. We'll get back to you within one business day.

Calendar not loading? Open in a new tab

Optional
Max. 500 characters