Module
Module 3 of 5Lesson 1 of 2~15 min

GDPR for AI users, five questions before you paste

Lesson 1 of the module "Personal data" in the course "Use AI at work without exposing your data or your company".

Lesson objective

By the end of this lesson, you will be able to say whether an AI use involves personal data, whether some of it is sensitive, whether the purpose and the amount of data are justified, and whether the tool provides the necessary contractual framework.

Where it fits

Personal data

What does the GDPR change for me when I use an AI tool, and how do I prepare data before pasting it?

Lessons in this module

  1. GDPR for AI users, five questions before you paste (this lesson)
  2. Pseudonymise before pasting, and know what it does not do

What you will learn in the course

This lesson is part of the course Use AI at work without exposing your data or your company

  • Sort the information in your work into green, amber or red based on its nature (public, internal, personal, sensitive, trade secrets, contractual commitments) and the tool considered.
  • Check and configure, for each tool and plan, what happens to your inputs (training, retention, human review, business terms), based on the vendors' dated pages.
  • Apply GDPR basics to the use of an AI tool (personal data, purpose, minimisation, sensitive data, processor, transfers) and prepare data by distinguishing pseudonymisation from anonymisation.
  • Protect the company in everyday AI use (trade secrets, contractual confidentiality, shadow AI, rights over generated content and third-party content).
  • Decide when to disclose the use of AI and who approves an output, placing the AI Act obligations in context (Article 50 transparency, Article 4 AI literacy).
  • Write a team AI policy (green, amber, red data, tools and settings, transparency, human approval, incidents, review) and organise its adoption.