General

GDPR-Compliant AI: A 5-Line AI Policy for SMEs

Peter Sigmond
September 23, 2026
4 min read

How SMEs use AI in line with the GDPR: a 5-line AI policy, EU hosting, data minimisation, vendor checks and human review before outputs reach customers.

You can use AI in line with the GDPR if you control which data goes into which tool, have a data processing agreement with every AI vendor that handles personal data, keep data in the EU where possible and let a person check AI output before it reaches customers. For most SMEs, a written policy of five lines covers the biggest risks. You don't need a 50-page manual.

Is using AI allowed under the GDPR?

Yes. The GDPR doesn't prohibit AI; it regulates how personal data is processed. Problems start when employees paste customer lists, contracts or support requests into a public chat tool that has no contract with your company and may use the input for other purposes. At that point you lose control over where personal data goes and can no longer meet your obligations towards the people concerned.

The difference lies between a consumer chat tool and an AI integration with a proper contract. With the latter you know where data is processed, how long it is kept and whether it is used for training.

What should a company AI policy contain?

Many SMEs use AI every day without a single written rule. These five lines cover most of the real-world risk:

  • Data boundary: define exactly what may go into public AI tools. No personal data, no pricing, no client data.
  • Review rule: every AI-generated output sent to a client is reviewed by a person first.
  • Audit trail: AI-assisted decisions are logged in a shared place, so there is a record.
  • Human in the loop: high-stakes actions such as contracts or payments always need a manual click.
  • Vendor ownership: one person manages AI subscriptions, contracts and renewal dates.

Write them down, share them in your team wiki and revisit them every quarter. They prevent client data leaks, invented numbers in customer documents and GDPR headaches before they become expensive.

Which technical measures make AI GDPR-compliant?

A policy only works if the systems support it. When we build AI automations, these points are defaults, not extras:

  • EU hosting and data residency: infrastructure in the EU by default.
  • Data minimisation: an agent only gets the data it needs for its task, not the whole database.
  • Separate roles: customer-facing agents are kept apart from internal processing agents.
  • Logging: every automated action is logged, so you can trace what happened and answer access requests.
  • Human approval for critical steps: anything that touches money, contracts or customer communication can be gated behind a person.

What should you check with AI vendors?

Before an AI tool processes personal data, clarify:

  • Is there a data processing agreement under Article 28 GDPR?
  • Where is data processed and stored, and is any of it transferred outside the EU?
  • Is your input used to train the vendor's models, and can you switch that off?
  • How long is data retained, and how is it deleted?
  • Which sub-processors are involved?

If an AI system processes personal data on a large scale or in sensitive ways, a data protection impact assessment may be required. Your data protection officer or adviser can tell you whether that applies to you.

How do the GDPR and the EU AI Act fit together?

They complement each other. The GDPR governs personal data; the AI Act governs AI systems according to their risk, including transparency duties for chatbots and AI literacy for staff. A short AI policy and a list of the AI tools you use serve both.

In practice, most compliance work for an SME is the same work that makes AI useful in the first place: knowing which tools are in use, what data they touch and who is responsible for the result.

FAQ

Can we use ChatGPT or similar tools with customer data?

Not through a public consumer account. Use business offerings with a data processing agreement, or an integration where you control what data is sent, and apply the data boundary rule.

Does the data have to stay in the EU?

The GDPR allows transfers outside the EU under certain conditions, but keeping data in the EU is the simplest way to stay on the safe side. We use EU-hosted infrastructure by default.

Is a 5-line policy enough?

It covers the most common risks for a typical SME. Companies with sensitive data or high-risk use cases need more. The policy is the start, not the end.

This article is general information, not legal advice.

Book a free call

Tags:

#gdpr#dsgvo#ai policy#data protection#compliance

Related Posts

Ready to automate?

Let's talk about how we can help you.

Book a Call