AI in business: What needs to be taken into account regarding data protection

AI tools have long been part of everyday working life in many companies – from drafting texts and conducting research to analysing customer data. However, as soon as personal data is processed, data protection becomes a key consideration.

It is therefore not only crucial which AI tool is used, but also what data is processed with it and how its use is organised.

Personenbezogene Daten vermeiden

Names, email addresses, customer data or documents containing personal information should not be entered into AI tools without careful consideration.

Use only approved tools

Organisations should clearly define which AI applications may be used for which purposes.

Anonymise data as far as possible

Wherever possible, personal information should be removed or anonymised before it is transmitted to an AI.

Check providers and data paths

It is important to know where data is processed, whether it leaves the EU, and what contracts are in place with the provider.

Record usage

AI applications should be integrated into existing data protection processes, and their use should be documented in a way that allows for proper traceability.

Data protection in AI is not a one-off check

Simply testing an AI tool once and then approving it permanently is not enough. This is because AI systems are constantly evolving: models are updated, functions are added, settings are changed and, in some cases, the conditions governing the storage or use of data are also adjusted. That is why, in addition to selecting the right tool, ongoing documentation and version control are also important. Organisations should be able to trace which AI application was used at what point in time, for what purposes it was authorised, and which data protection and security settings applied at the time. If a provider, model or pricing plan is changed, it should be checked whether the previous assessment remains valid.

Internal AI guidelines, therefore, should not be viewed as a one-off document. They must evolve in line with the tools used and new use cases. The same applies to staff: anyone working with AI needs a basic understanding of which data may be used, what risks exist and when further scrutiny is required. In this way, individual AI tools are gradually transformed into a controlled process – with clear responsibilities, traceable approvals and regular reviews.

Is our use of AI compliant with data protection regulations?

To enable organisations to quickly review their own use of AI, we have summarised the key points in a concise checklist.

From data processing and vendor assessment to internal policies, version control and staff training.

→ Download the ‘Data Protection in AI Use’ checklist free of charge

Nicht pauschal. Sobald personenbezogene Daten verarbeitet werden, müssen die Anforderungen der DSGVO berücksichtigt werden. Unternehmen sollten deshalb genau prüfen, welche Daten wirklich notwendig sind und ob sie vor der Nutzung anonymisiert oder pseudonymisiert werden können.

Besonders vorsichtig sollte man mit Kunden-, Mitarbeiter-, Bewerber-, Gesundheits-, Vertrags- oder Rechnungsdaten umgehen. Auch interne Geschäftsgeheimnisse und vertrauliche Dokumente sollten nicht ungeprüft verarbeitet werden.

Ja, eine nachvollziehbare Dokumentation ist sinnvoll. Unternehmen sollten festhalten, welche Tools für welche Zwecke freigegeben sind, welche Daten verarbeitet werden und welche Datenschutz- und Sicherheitseinstellungen gelten.

KI-Systeme verändern sich laufend. Neue Modelle, Funktionen oder geänderte Nutzungsbedingungen können Einfluss auf Datenschutz und Datenverarbeitung haben. Deshalb sollte dokumentiert werden, welche Version oder Konfiguration geprüft und freigegeben wurde.

Ja, interne Regeln und Schulungen sind wichtig. Mitarbeitende sollten wissen, welche Tools erlaubt sind, welche Daten verwendet werden dürfen und wann eine zusätzliche Prüfung notwendig ist.

Es sollten nur jene Informationen verarbeitet werden, die für den jeweiligen Zweck wirklich notwendig sind. Personenbezogene Angaben können häufig entfernt, ersetzt oder anonymisiert werden, bevor Inhalte an ein KI-System übergeben werden.

AI and data protection

AI tools have long been part of many work processes – and this means that data protection is becoming increasingly important. What data may be processed, how should tools be documented and regularly reviewed, and why does version control also play a role? This article highlights what companies should bear in mind and also provides a concise checklist for their own use of AI.