Anyone working with ChatGPT, Copilot or another AI tool can quickly paste a whole case into the prompt: a customer email, meeting notes, a job application. Personal data then ends up with a provider without anyone having consciously decided that it should.
Yet most tasks can be done without any personal data at all. If you check briefly before sending and replace names and details, you need no special rules for everyday work. For the remaining cases, you need an approved tool, a contract and a legal basis.
How to recognise personal data
Personal data is anything that can be linked to a person, directly or with reasonable effort: names, email addresses, customer numbers, but also a precise description that fits only one person. Special categories of personal data include health data, religious beliefs, trade union membership and biometric data (Article 9 GDPR).
Germany's federal and state data protection authorities point out that removing names and addresses is usually not enough. The link to a person often comes from the context. Their example is a request for an employment reference for a customer adviser at a particular car dealership: if it is clear which company the request came from and when, the person can be identified.
In everyday work, personal data often hides in these places:
- customer numbers, file references, contract or invoice numbers
- roles in small teams, such as “the head of our accounts department” when only one person holds that role
- signatures, headers and quoted threads in pasted emails
- rare events with a date and place, such as a specific accident or a dismissal in a small department
The output counts too. An AI can produce information about real people even though the prompt contained none, for example when the question is aimed at specific people. A legal basis may then be needed for any further processing as well.
Remove data before you start
For many tasks the AI does not need real people: drafting a reply, shortening a text or outlining a structure works just as well with placeholders such as “Customer A”. The GDPR requires you to limit data to what is necessary for the purpose in any case (Article 5, data minimisation).
For you, such data remains personal data as long as you know who it refers to. The AI provider should not be able to identify anyone. So replace everything that points to the person, details as well as names. Only truly anonymous data falls outside the GDPR.
Three questions before sending:
- Does the task need real people? For tone, structure and wording, almost never. For merging real customer data, yes.
- Could someone outside the organisation tell who this is about? Read the text once through a stranger's eyes, including the signature and any attachment.
- Is the tool approved for this kind of data? If not, replace the details or do the task without AI.

Example: replying to a complaint
A clerk at a mail-order business with twelve employees has to reply to an angry customer email. The goods arrived late, and the customer writes that she needs them urgently because of an operation.
Before: She copies the entire email into an AI assistant, with name, address, customer number, order date, the mention of the operation and the signature. This also sends health information to the provider, even though the reply does not need it.
After: She describes the case in her own words and enters only what the text needs:
“A customer is complaining about a late delivery. She needs the goods urgently. We can redeliver within two working days and will cover the shipping costs. Write a friendly, clear reply with an apology and a new delivery date, no more than 120 words, addressing her as [Name].”
She then adds the name and the exact date in her own email software. The draft is just as useful, and the provider has not seen a single person. This pattern works for many tasks: describe the case in your own words, state the goal and the constraints, use placeholders in square brackets.
When real data is needed
Some tasks cannot be done without real data, such as summarising a customer file or analysing feedback that includes names. You then need a tool that is approved for this:
- a business account instead of private accounts
- a data processing agreement (DPA) under Article 28 GDPR
- no use of your prompts for training
- processing in the EU or a verified basis for transfers
On top of that you need a legal basis for the processing itself, such as the performance of a contract or legitimate interests (Article 6 GDPR). Which one applies depends on the purpose. The data protection authorities also recommend providing business accounts and configuring them during setup so that no prompts are used for training. How to check the contract is explained in the article Data processing agreements with AI providers.
Some cases require more:
- If special categories of personal data are involved, such as health information, processing them is prohibited in principle and only allowed under the exceptions in Article 9 GDPR. Check this case by case before such data goes into an AI tool.
- If an output has legal effects for people, a human must genuinely make the decision. In the view of the data protection authorities, an AI that assesses job applications and invites candidates to interviews on its own breaches Article 22 GDPR.
- If the processing is likely to result in a high risk to the people concerned, a data protection impact assessment (DPIA) is required beforehand (Article 35 GDPR). In the authorities' assessment, this is often the case when AI is used.
A rule you can adopt
A simple rule is the traffic-light principle: green is public and general content. Amber is internal documents, which may only go into approved tools. Red is personal and confidential data, which belongs only in applications with a suitable contract. Special categories of data such as health information only go into an AI tool after a case-by-case check.
The data protection authorities advise describing permitted and prohibited uses with concrete examples. You can adopt this version and fill it with your own examples:
- Green, in all approved tools: text from our website, subject-matter questions unrelated to a specific case, outlines, help with wording using placeholders.
- Amber, only in [name of approved tool] with a company account: internal processes, draft concepts, minutes without names.
- Red, only in [tool with a data processing agreement]: customer data, HR records, quotes with customer names. If in doubt, ask [contact person].
- Never without a prior check: health information, information on religion or trade union membership, children's data, passwords and login details.
Record the rule with a date and explain it to the team once using a real case.
Next steps
- List which AI tools your team actually uses, including any that people have set up privately.
- For each tool, record: business account, data processing agreement, training excluded, place of processing.
- Adopt the traffic-light rule and fill in your tools and contact person.
- Work through the complaint example with your team, using one of your own typical cases.
If you would like to cover the topic with your whole team, take a look at our talk on AI and data protection. Which case in your organisation most often ends up unchanged in an AI prompt?
Frequently asked questions
Can I use AI to improve a letter to a customer?
Yes, if you first replace names, contact details and anything else that points to the person, or use an approved tool with a data processing agreement. Often it is enough to describe the case in your own words and use placeholders.
Is it enough to leave out the surname?
Often not. If the person can be identified from the context, the text is still personal data. Also look out for customer numbers, signatures and rare details.
What about photos and recordings?
Photos, voice recordings and videos of people are personal data. If they are analysed to identify people, they count as biometric data, a special category of personal data.
Can we let AI pre-sort job applications?
Only with caution. Decisions with legal effects must in principle be made by people, with real room for judgement. In the view of the data protection authorities, an AI that invites candidates to interviews on its own is not permitted. Such a use may also count as high-risk AI under the EU AI Act.
Do we have to tell people when their data goes into an AI tool?
Yes. Anyone who processes personal data in AI applications must inform the people concerned transparently. Check whether your privacy notice covers this use.
Sources
- GDPR, Articles 4, 9 and 28, EUR-Lex
- CJEU, judgment of 4 September 2025, C-413/23 P (pseudonymisation)
- Orientation guide on artificial intelligence and data protection, German Data Protection Conference (DSK), 6 May 2024 (in German)
Updated: . This article is not legal advice.



