AGIDAT – Datenschutz | Informationssicherheit

AI & Data Protection

Using artificial intelligence with legal certainty — GDPR, the EU AI Act, and practical guidance.

AI in the workplace — opportunities and risks

Artificial intelligence is already part of daily business for many organizations: ChatGPT for drafting text, Microsoft Copilot for office tasks, AI-powered CRM systems, automated decision-making. These tools deliver enormous efficiency gains — but they also raise serious data protection questions.

Anyone entering personal data into AI systems must ensure this is done lawfully.

Typical risks of using AI

  • Entering customer data into ChatGPT → AI models may be trained on your data
  • No DPA with the AI provider → missing contractual safeguards
  • AI-driven HR decisions → potential discrimination, transparency obligations
  • Third-country transfers → data ends up on US servers without adequate safeguards
  • No employee policy → uncontrolled and risky use of AI

What we do for you

AI tool check

We analyze which AI tools are used in your organization — both officially sanctioned and "shadow IT" — and assess them from a data protection perspective:

  • What data is being processed?
  • Is the data used for training purposes?
  • Is there a DPA or comparable agreement in place?
  • Does a third-country transfer take place?

AI usage policy

Clear rules for your employees: what may be done with AI tools — and what may not? We create a practical policy that balances data protection with productivity.

EU AI Act

The EU AI Act is coming into force in stages and classifies AI applications into risk categories. We inform you of your obligations — particularly if you use AI systems that make decisions about individuals.

Training

We raise your employees' awareness of the data-protection-compliant use of AI tools — in a clear, practical way.