GDPR-compliant AI use: step by step for SMEs

GDPR-compliant AI use does not start with a tool, but with clear decisions about data, purpose, providers and responsibility. Small and mid-sized companies need a practical path, not a heavy theoretical framework. The goal is simple: make AI useful in daily work without losing control over customer data, employee data or internal business knowledge.

Why does GDPR-compliant AI use matter for SMEs now?

Many companies are already using AI more than they officially admit. Someone improves a proposal text, summarizes a customer email, drafts meeting minutes, translates a technical document, prepares a job ad or asks a chatbot to structure a complaint. The individual action may look harmless. The risk starts when nobody knows which data goes into which system, which provider processes it, whether it is stored, whether it may be used for model improvement and whether it later becomes part of a business workflow.

AI Compliance by KrambergAI

Use AI with clear rules and responsibilities

KrambergAI helps companies establish practical AI compliance structures for internal rules, data handling, approvals, responsibilities and responsible use in daily work.

Structured guidance · Responsible implementation · Made in Germany

This is where GDPR-compliant AI use becomes practical. It is not about slowing down every idea. It is about making AI controllable. A company must know whether personal data is processed, which purpose applies, which legal basis is used, whether a data processing agreement is required and whether data leaves the EU or the European Economic Area. These questions may sound legal, but they become very concrete in everyday operations: Can an employee paste a customer email into an AI system? Can a service technician analyze a photo if an address or meter number is visible? Can HR use AI to summarize applications? Can sales automatically analyze call notes?

SMEs face pressure from both sides. On one side, the business expects AI to improve productivity, response times and knowledge work. Bitkom reports that 36 percent of companies in Germany already use AI. On the other side, privacy remains a real decision factor: in Bitkom’s 2025 privacy study, 58 percent of companies agreed that data protection creates legal certainty for AI development. That is the productive way to look at it. Privacy is not only a restriction. It is a structure that helps AI move from experimentation into reliable operations.

What is the difference between casual AI use and GDPR-compliant AI use?

Casual AI use often means that employees try whatever helps them finish a task faster. GDPR-compliant AI use means that the use case is described, limited, technically secured and organizationally approved. It may feel less spontaneous at first, but it prevents confusion later.

Take a simple example. A customer complaint is pasted into a free AI chatbot for summarization. The text contains a name, address, contract number, technical details and possibly payment or health-related information. Without a company rule, nobody knows whether the tool uses prompts for training, where the data is processed, how long it is stored and who can access it. That is not a stable setup.

The situation changes when a company defines approved AI tools, blocks sensitive input, anonymizes data where possible, sets roles, activates logging and defines clear business purposes. Then AI becomes part of a managed process instead of an uncontrolled side channel. GDPR-compliant does not mean AI is locked away. It means AI is introduced in a way that management, IT, privacy, security and business teams can understand and defend.

AreaUncontrolled AI useGDPR-compliant AI use
Tool selectionEmployees choose random servicesApproved providers with reviewed contracts
Data inputCustomer, employee and business data are entered case by caseData classes define what is allowed, masked or blocked
ResponsibilityUnclear ownershipDefined roles for business, IT, privacy and management
TraceabilityHard to check what happenedLogs, approvals and processing documentation
RiskShadow AI, data leakage, unreliable resultsLimited use cases, controls and escalation paths
Business valueFast, but unpredictableScalable, auditable and repeatable

How should an SME start with an honest AI inventory?

The first step is not a vendor comparison. The first step is an honest inventory. Which AI systems are already in use? Which employees use chatbots, translation tools, writing assistants, meeting transcription, image analysis, coding tools or automation services? Which tools are officially purchased, which are tolerated and which are unknown?

This inventory should not feel like an investigation. If it does, people will hide what they actually do. A better approach is a pragmatic survey: Where is AI already useful? Which tasks became faster? Which data is entered? Which risks do teams see themselves? In many companies, this is the first moment when management gets a realistic view of AI use.

In industries such as field service, construction-related trades, electrical services, public works, security services, customer support and administration, data is rarely neatly separated. A single request may contain technical information, contact details, photos, location data, order numbers and internal comments. GDPR-compliant AI use must be designed around that reality. Abstract discussions about “data” are not enough.

The result should be easy to read: tool, provider, department, purpose, data categories, user group, contract status, processing location, risk and decision. That is enough for a first version. Without this list, however, AI governance remains theoretical.

Which data should be entered into AI systems?

The more useful question is: Which data is actually necessary? GDPR starts with data minimization. If an AI tool is supposed to improve the wording of a proposal, it usually does not need the customer’s full name, private phone number or exact address. If a technical error description is summarized, anonymized details may be sufficient. If a meeting note is created, confidential HR or customer details do not have to be sent into every system by default.

A practical data classification works better for SMEs than a complex policy architecture. Four categories are enough for a strong start.

The first category includes public or low-risk information, such as published product descriptions or general company texts. The second category covers internal business information, such as processes, pricing logic, proposal templates or operational know-how. The third category contains personal data, such as customer names, employee data, applications or contact details. The fourth category contains highly sensitive or strictly confidential information, such as health data, payment data, trade secrets, security concepts or employment-related assessments.

For each category, the company should define whether input into AI systems is allowed, allowed only after anonymization, or prohibited. The rule does not have to be long. It has to be understood. A technician, office employee, sales manager and executive should all be able to decide what they may enter during real work.

How do you choose an AI provider in a privacy-safe way?

An AI provider is not suitable just because the product is well known. What matters are the specific contractual and technical conditions. Companies should check whether the provider offers a data processing agreement under Article 28 GDPR, where data is processed, which subprocessors are used, whether prompts and outputs are used for training, which retention periods apply and which admin controls are available.

For many SMEs, practical enterprise functions are just as important: tenant separation, role-based access, logging, single sign-on and central administration. A single-user chatbot account may be fine for testing. It is usually not enough for production use across a company. Once customer data, employee data or internal knowledge is processed, the company needs controls.

Interfaces are especially important. An AI system connected to email, CRM, ticketing, calendars, file storage or ERP does not just process individual text snippets. It touches workflows. General privacy statements are not enough in that situation. The company must know which data can be read, written, stored, transferred and logged.

Cisco’s 2025 Data Privacy Benchmark Study reports that 90 percent of surveyed organizations expanded their privacy programs because of AI. This matters for SMEs because it shows that AI adoption is not just a software decision. It affects privacy governance, IT security, procurement, business processes and management responsibility at the same time.

Company Brain by KrambergAI

Make company knowledge easier to access

The KrambergAI Company Brain makes scattered knowledge from documents, projects, processes and internal sources easier to find and prepares answers with traceable context.

Implemented pragmatically · Source-based answers · Made in Germany

Which GDPR legal basis applies to AI?

There is no single legal basis for AI. The legal basis depends on the purpose. If AI helps process a customer request, contract performance or pre-contractual steps may be relevant. If AI supports internal efficiency, legitimate interest may be considered. If AI processes applications, employee data or sensitive data, the assessment becomes more demanding. Consent often looks easier than it is, because it must be voluntary, informed and withdrawable.

The purpose must be defined before processing starts. “We want to see what the AI can do with the data” is not a clean purpose. A better purpose is: “summarizing incoming service requests to route them faster to the right department” or “drafting customer replies based on approved knowledge articles.” Purposes like these can be assessed, limited and documented.

In many AI projects, a data protection impact assessment may also be relevant, especially where processing is extensive, sensitive, evaluative or strongly automated. This is particularly important for HR, scoring, monitoring, automated decisions or deep integrations into customer systems. SMEs should not leave this review until the end. Once the architecture is built, changes become expensive.

What does a practical step-by-step process look like?

GDPR-compliant AI use becomes easier when it is treated as an implementation path. Not every company needs a large governance manual from day one. But every company needs a repeatable process.

Step one is the inventory of AI tools already in use. Step two is the selection of a few high-value use cases, such as email summaries, internal knowledge search, proposal drafts, support responses or call notes. Step three is data classification. Step four is provider review, including contract, processing location, subprocessors and training settings. Step five is role definition: who approves, who administers, who checks privacy, who handles errors?

Step six is technical implementation. This includes access rights, logging, deletion rules, secure interfaces and ideally separate test and production environments. Step seven is user training. Training should not only explain which tool to use. It should also explain which data is prohibited, how to anonymize inputs and why AI outputs require review. Step eight is documentation. This includes processing records, risk assessment, possible data protection impact assessment, vendor documentation, approval lists and internal policy.

The decisive point is step nine: periodic review. AI systems change. Providers add features. Employees find new use cases. Business teams connect new systems. A one-time assessment is not enough. GDPR-compliant AI use is not a project with a neat finish line. It is an operating model.

What role does the EU AI Act play next to GDPR?

GDPR governs personal data. The EU AI Act governs AI systems through risk categories and specific obligations. They are not the same, but in practice they often overlap. An AI system can be relevant under GDPR without being a high-risk AI system under the AI Act. The reverse can also happen: an AI system may trigger AI Act obligations and process personal data at the same time.

For SMEs, the main point is simple: the AI Act does not replace GDPR. Privacy obligations remain. The European Commission states that the AI Act entered into force on August 1, 2024 and will generally become fully applicable on August 2, 2026, with certain exceptions. Companies should therefore classify AI projects not only by privacy relevance, but also by AI risk.

In simple cases, such as drafting text or internal knowledge search, the GDPR assessment may be the main focus. In more sensitive cases, such as HR, access control, evaluation of individuals, safety-related processes or automated decisions, the AI Act perspective becomes more important. A clean AI inventory built today will also make future AI Act classification easier.

How can companies prevent shadow AI?

Shadow AI appears when employees use AI without company oversight. Usually this does not happen because people want to break rules. It happens because official tools are missing, too slow or disconnected from real work. A pure ban rarely solves the problem. It often pushes AI use into private accounts, browser extensions or mobile apps.

A better answer is a controlled offering. Employees need approved AI tools, understandable rules and examples from their own work. It is not enough to say “do not enter sensitive data.” People need to know how to anonymize a customer email, which documents must not be uploaded and when they should ask for approval.

IBM’s 2025 Cost of a Data Breach analysis reports an average global breach cost of 4.44 million US dollars. This figure is global and not specific to every SME, but it shows that data incidents are economically relevant. The risk becomes worse when a company only discovers after an incident that nobody knew which AI tools were used internally.

How can AI use be documented without creating bureaucracy?

Documentation does not have to be beautiful. It has to be useful. An SME does not need an 80-page AI policy that nobody reads. It needs a few documents that work.

An AI register shows which systems are used. A data classification explains which information may be entered. An approval list names allowed tools. A short policy describes permitted, restricted and prohibited uses. A process description explains how new AI use cases are requested and reviewed. Training records, provider documents and technical settings should be stored in the same place.

Language matters. If a policy reads like a legal memo, people will not use it. Concrete rules work better: “Remove customer names before input,” “Do not upload applications into unapproved AI tools,” “Review AI replies before sending,” “Do not make automated decisions about people without approval.” These sentences help more than abstract principles.

Which mistakes happen most often during AI adoption?

The first mistake is tool obsession. Companies compare features, prices and models before clarifying which data will be processed and which workflows will be affected. The second mistake is assuming that a large provider is automatically compliant for every purpose. Privacy depends on the actual contract, configuration and use case.

The third mistake is missing training. Many risks are not caused by the AI system itself, but by wrong input. The fourth mistake is missing output review. AI can sound confident and still be wrong. In service, technical work, legal contexts, HR or safety-related processes, output must not be accepted without human review.

The fifth mistake is unclear ownership. If IT, privacy, management and business teams each assume someone else is handling the issue, a governance gap appears. GDPR-compliant AI use needs a clear responsibility model. It does not have to be complicated, but it must be explicit.

How can an SME start tomorrow?

A pragmatic start consists of three decisions. First: Which AI uses are allowed, restricted or stopped immediately? Second: Which two or three use cases create real value without starting in the highest-risk areas? Third: Who is responsible for implementing them properly?

A good first use case is often internal knowledge search on approved documents. Drafting non-sensitive emails, summarizing internal meetings or structuring service requests can also be useful. More difficult areas include HR assessments, customer scoring, health data, monitoring and automated decisions about people. These should not be the first projects.

GDPR-compliant AI use is not a barrier to progress. It is the condition that allows AI to scale beyond individual experiments. Once data, providers, purposes and responsibilities are clear, companies can implement AI faster because every new use case does not start from zero.

Which numbers show the relevance?

Four figures show why the topic is concrete for SMEs:

36 percent of companies in Germany already use AI, according to Bitkom. AI is no longer a marginal experiment.

58 percent of companies say data protection creates legal certainty for AI development, according to Bitkom. Privacy can therefore act as a framework, not only as a constraint.

90 percent of organizations surveyed by Cisco say AI has expanded their privacy programs. AI changes governance and operations, not just software portfolios.

4.44 million US dollars was the average global cost of a data breach in IBM’s 2025 reporting. This is a global figure and not SME-specific, but it shows the economic scale of data risk.

Further reading

German Data Protection Conference: Guidance on artificial intelligence and data protection
https://www.datenschutzkonferenz-online.de/media/oh/20240506_DSK_Orientierungshilfe_KI_und_Datenschutz.pdf

European Data Protection Board: Opinion 28/2024 on AI models and personal data
https://www.edpb.europa.eu/our-work-tools/our-documents/opinion-board-art-64/opinion-282024-certain-data-protection-aspects_en

European Commission: Regulatory framework on artificial intelligence
https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai

Sources for the statistics used

Bitkom: Artificial Intelligence 2025
https://www.bitkom.org/sites/main/files/2026-02/bitkom-studienbericht-ki.pdf

Bitkom: Data Protection in the German Economy 2025
https://www.bitkom.org/sites/main/files/2026-02/bitkom-studienbericht-datenschutz.pdf

Cisco: 2025 Data Privacy Benchmark Study
https://investor.cisco.com/news/news-details/2025/Ciscos-2025-Data-Privacy-Benchmark-Study-Privacy-landscape-grows-increasingly-complex-in-the-age-of-AI/default.aspx

IBM: Cost of a Data Breach Report 2025
https://www.ibm.com/think/x-force/2025-cost-of-a-data-breach-navigating-ai

What does GDPR-compliant AI use mean in practice?

GDPR-compliant AI use means that personal data is processed only with a clear purpose, suitable legal basis, reviewed providers and appropriate safeguards. Using a well-known AI tool is not enough. Companies must understand which data is entered, where it is processed, whether it is retained and who is responsible for control and documentation.

Can employees use ChatGPT or other AI tools at work?

Yes, but not without rules. Companies should define which AI tools are approved, which data may be entered and which purposes are allowed. Customer data, employee data, applications, contracts and trade secrets are especially sensitive. Without a clear policy, shadow AI can develop quickly and outside official control.

Does every AI project need a data protection impact assessment?

No, not every AI project automatically requires a data protection impact assessment. It becomes relevant when processing is likely to create a high risk for the rights and freedoms of individuals. This may apply to sensitive data, profiling, HR processes, systematic evaluation or extensive automation. A preliminary risk check should always be part of the process.

Which AI use cases are best for a first implementation?

Good first use cases have clear value and limited privacy risk. Examples include internal knowledge search on approved documents, drafts for general business texts, summaries without sensitive information or structured service requests. HR decisions, customer scoring, health data, monitoring and automated decisions about individuals are usually not suitable as first projects.

How should companies protect personal data before using AI?

Companies should avoid, reduce or anonymize personal data before entering it into AI systems. Customer names, addresses, phone numbers, contract numbers and sensitive details are often unnecessary for the task. Additional protection comes from role-based access, logging, deletion rules, reviewed providers, secure interfaces and clear bans on highly sensitive data.

What should an internal AI policy include?

An internal AI policy should clearly describe approved tools, permitted data inputs, allowed purposes and situations requiring approval. It should also define rules for reviewing AI outputs, handling errors, documenting use and assigning responsibility. The policy must be understandable in daily work. Otherwise employees will ignore it or create their own informal rules.

How do GDPR and the EU AI Act work together?

GDPR protects personal data. The EU AI Act regulates AI systems based on risk and adds obligations for certain AI applications. Both can apply at the same time. An AI system may be low-risk under the AI Act but still process personal data. A more sensitive AI system may trigger both AI Act and GDPR obligations.

What is the biggest practical mistake with AI and privacy?

The biggest mistake is implementing AI first and checking privacy later. By then, tools, workflows, data flows and habits may already be established. A better approach is a lean review before production use. It should clarify purpose, data categories, provider setup, risk, legal basis and responsibility without turning every idea into a long project.


All Articles about AI Governance and Compliance

All Articles about Digitalization for SMBs

KrambergAI AI Compliance Services

KrambergAI Strategy Consulting