


AI in business: What needs to be taken into account regarding data protection
AI tools have long been part of everyday working life in many companies – from drafting texts and conducting research to analysing customer data. However, as soon as personal data is processed, data protection becomes a key consideration.
It is therefore not only crucial which AI tool is used, but also what data is processed with it and how its use is organised.
Data protection in AI is not a one-off check
Simply testing an AI tool once and then approving it permanently is not enough. This is because AI systems are constantly evolving: models are updated, functions are added, settings are changed and, in some cases, the conditions governing the storage or use of data are also adjusted. That is why, in addition to selecting the right tool, ongoing documentation and version control are also important. Organisations should be able to trace which AI application was used at what point in time, for what purposes it was authorised, and which data protection and security settings applied at the time. If a provider, model or pricing plan is changed, it should be checked whether the previous assessment remains valid.
Internal AI guidelines, therefore, should not be viewed as a one-off document. They must evolve in line with the tools used and new use cases. The same applies to staff: anyone working with AI needs a basic understanding of which data may be used, what risks exist and when further scrutiny is required. In this way, individual AI tools are gradually transformed into a controlled process – with clear responsibilities, traceable approvals and regular reviews.
Is our use of AI compliant with data protection regulations?
To enable organisations to quickly review their own use of AI, we have summarised the key points in a concise checklist.
From data processing and vendor assessment to internal policies, version control and staff training.
→ Download the ‘Data Protection in AI Use’ checklist free of charge
Nicht pauschal. Sobald personenbezogene Daten verarbeitet werden, müssen die Anforderungen der DSGVO berücksichtigt werden. Unternehmen sollten deshalb genau prüfen, welche Daten wirklich notwendig sind und ob sie vor der Nutzung anonymisiert oder pseudonymisiert werden können.
Besonders vorsichtig sollte man mit Kunden-, Mitarbeiter-, Bewerber-, Gesundheits-, Vertrags- oder Rechnungsdaten umgehen. Auch interne Geschäftsgeheimnisse und vertrauliche Dokumente sollten nicht ungeprüft verarbeitet werden.
Ja, eine nachvollziehbare Dokumentation ist sinnvoll. Unternehmen sollten festhalten, welche Tools für welche Zwecke freigegeben sind, welche Daten verarbeitet werden und welche Datenschutz- und Sicherheitseinstellungen gelten.
KI-Systeme verändern sich laufend. Neue Modelle, Funktionen oder geänderte Nutzungsbedingungen können Einfluss auf Datenschutz und Datenverarbeitung haben. Deshalb sollte dokumentiert werden, welche Version oder Konfiguration geprüft und freigegeben wurde.
Ja, interne Regeln und Schulungen sind wichtig. Mitarbeitende sollten wissen, welche Tools erlaubt sind, welche Daten verwendet werden dürfen und wann eine zusätzliche Prüfung notwendig ist.
Es sollten nur jene Informationen verarbeitet werden, die für den jeweiligen Zweck wirklich notwendig sind. Personenbezogene Angaben können häufig entfernt, ersetzt oder anonymisiert werden, bevor Inhalte an ein KI-System übergeben werden.











