ChatGPT in the team — without rules?
Growing wild is not a motivation problem, it is a liability risk. What to do now.
Answer · Data protection · GDPR
The short answer: with tiers instead of a ban. Local models where data has to stay in-house. Large models where performance counts. Public data may go into any AI, internal data only into systems covered by a business contract, confidential data stays on your own infrastructure — and personal data needs a legal basis and a data processing agreement. Anyone who knows these four tiers can use AI to the full without risking customer data.
When someone in the office pastes a customer list into a free chatbot, the data leaves the house — onto servers you do not control, under terms you have never read. With free chat versions, inputs can be used for training. The problem is not the tool, it is the route the data takes.
That is why one simple rule applies in my own business — and it runs entirely on AI, from the quote to the translation:
Local models where data has to stay in-house. Large models where performance counts. A local model runs on your own hardware — nothing leaves the building. A large cloud model only gets data that can take it, contractually and legally.
That this is not theory is shown by two cases: a service provider now translates confidential documents with an internal tool — the formatting is preserved, 100 % of the content stays in-house. And my own business has been working to exactly these tiers for years.
Evidence: case 301 — confidential documents, translated in-house
Evidence: case 313 — my own business runs on this rule
The tiers
Not every piece of information needs the same protection. What matters is what is in it — not how convenient the tool would be right now.
Website copy, published price lists, general technical questions: what anyone can read anyway may also be read by any model. This is where the large cloud models play out their full performance — with no risk.
Process descriptions, working notes, drafts with no personal reference: allowed in large models, but only via business or API access with a data processing agreement and training use ruled out. An employee's free private account is neither of those.
Calculations, contracts, designs, formulations: whatever a competitor must never see belongs on your own infrastructure — local models or an internal tool with a controlled connection. That is exactly how case 301 keeps all documents in-house.
Customer, employee or even health data: here the GDPR requires a legal basis and a data processing agreement — no matter how good the tool is. When in doubt that means: process locally or anonymise first. No deadline pressure justifies the shortcut.
These four tiers fit on a single page — and that is exactly how they belong in the team: as a set of rules everyone understands. In the AI Day we work them out together
The GDPR does not ban AI. It requires you to know and control where personal data is processed. In practice, when using AI, that means:
And the honest counter-list — what to leave alone: customer data in a private chatbot account, job applications uploaded "just quickly", health data in some free tool. That is not a minor slip, it is a notifiable loss of control.
"Data protection is not a brake. It only decides which tool you pick."
The bigger risk, incidentally, rarely comes from bad intent but from things growing wild: your people are already using AI — the question is whether with or without guardrails. What unmanaged AI use in the team means →
Common questions
Into free chat versions: no. There is no data processing agreement, and inputs can be used for training. Business or API access with an agreement in place and training use ruled out is a different matter — but for personal data the strictest tier still applies: when in doubt, local or anonymised.
For clearly defined tasks, yes: translating, sorting, summarising, pulling data out of documents. Case 301 shows it in practice — 100 % of the documents stay in-house. For the hardest tasks you use large models: and then with data that allows it.
Three things: a legal basis for the processing, a data processing agreement under Article 28 GDPR with the provider, and control over the inputs — no use for training, clear deletion periods. If you cannot evidence that, it is better not to put personal data into the cloud at all.
Not as a 40-page policy that nobody reads — but as a one-page set of rules in plain language, worked out on your real tasks. That is exactly one building block of the AI Day, including proof for the training obligation under Article 4 of the EU AI Act.
30 minutes, three starting points in writing — free and with no sales pressure.