Data privacy and AI: what a European business owner needs to know
Every founder we talk to on Mallorca eventually asks a version of the same question: if I put customer data into an AI tool, am I breaking GDPR? The honest answer is "not automatically, but it's easy to get wrong." Here's what actually matters, without the legal-newsletter tone.
The one-sentence version
GDPR doesn't stop you using AI. It requires that any tool touching customer data has a lawful basis for processing it, a proper data processing agreement in place, and, where the tool sends data outside the EU, a valid legal mechanism for that transfer. Most AI privacy problems in small businesses come from skipping that third piece, not from using AI itself.
Why this comes up so often
A small business owner tries a consumer AI chatbot, pastes in a customer's enquiry to draft a reply, and doesn't think about it again. That single action can touch three separate GDPR obligations at once: the legal basis for processing that person's data, whether the AI provider is a proper "processor" under a signed agreement, and where the data physically goes. None of this is complicated once it's laid out, but almost nobody lays it out before they start using the tool.
What GDPR actually requires when an AI tool is in the loop
| Requirement | What it means in practice |
|---|---|
| Lawful basis | You need a valid reason to process the customer's data at all (typically "legitimate interest" for replying to an enquiry, or "contract" once they're a client). This exists before AI enters the picture, and it doesn't change because a tool is involved. |
| Processor agreement | If a third-party AI tool processes personal data on your behalf, GDPR Article 28 requires a written data processing agreement (a "DPA") with that provider. Most serious AI vendors publish a standard one; consumer-tier plans often don't offer one at all. |
| International transfer mechanism | If the AI provider's servers sit outside the EU (most US-based models do, by default), the transfer needs a valid legal basis: either the EU-US Data Privacy Framework (for certified US providers) or Standard Contractual Clauses. |
| Data minimisation | Only send the AI tool the data it actually needs to do the job. A reply-drafting assistant doesn't need a customer's full purchase history if it's answering a general enquiry. |
Where consumer AI plans get businesses into trouble
The free or personal tier of most AI chatbots is built for individual use, not business processing. Two things commonly go wrong. First, many consumer plans reserve the right to use your conversations to train future models, meaning a customer's message could, in principle, become training data. Enterprise and business-tier plans from the same providers almost always carry an explicit no-training clause; the free tier usually doesn't. Second, consumer plans rarely offer a signed DPA at all, which means there's no Article 28 agreement in place even if you wanted one.
The fix isn't avoiding AI. It's using the business tier of whichever tool you choose, reading the data processing terms once, and keeping a copy of the signed DPA somewhere findable.
The Schrems II problem, briefly
In 2020 the EU's top court struck down the previous EU-US data transfer agreement (Privacy Shield) in a case known as Schrems II, on the grounds that US surveillance law didn't offer EU citizens equivalent protection. That created several years of genuine uncertainty for any EU business sending data to US-based tools. The European Commission adopted a replacement framework, the EU-US Data Privacy Framework, in July 2023. If an AI provider is certified under it, transfers to that provider have a recognised legal basis again. Worth checking before you commit to a vendor, not after.
How this interacts with the EU AI Act
GDPR and the EU AI Act are separate laws that both apply the moment an AI system touches customer data. GDPR governs where the data lives and under what basis it's processed. The AI Act governs the AI system's risk category and what transparency it owes the person interacting with it. We covered the AI Act side in detail in our plain-English guide to the EU AI Act. The two rules are complementary, not competing, and a well-built system satisfies both at once.
A practical checklist
- Are you on a business or enterprise tier of the AI tool, not the free consumer plan?
- Does the provider offer a signed data processing agreement, and do you have a copy of it?
- Is the transfer mechanism valid: EU-US Data Privacy Framework certification or Standard Contractual Clauses?
- Are you only sending the AI tool the data it actually needs for the task?
- Can a customer ask what data of theirs was processed and by what system, and can you actually answer them?
If you can tick all five, you're in reasonable shape. If you can't tick the first two, that's the place to start.
What we do, practically
Every system we build runs on infrastructure we host ourselves on European servers, so customer data doesn't leave the EU by default. Where we use a third-party AI API, it's always the business or enterprise tier with an explicit no-training clause, and we keep the signed processing agreement on file. It's a fairly boring set of habits. That's the point: privacy compliance for AI tooling isn't a research project, it's a short checklist applied consistently.
The businesses that get into trouble aren't the ones using AI. They're the ones using AI on the free tier and never asking where the data goes.
What to actually do about this
If your business is using or considering AI tools: confirm you're on a business tier with a signed processing agreement, confirm the transfer mechanism to any non-EU provider is valid, and only send the tool the data it needs. That's the practical floor. This isn't legal advice (for a formal opinion on your specific setup, talk to a data protection lawyer), but it's the starting point that resolves most of the actual risk.