As soon as employees put customer data, job applications or other documents containing personal data into an AI tool, the provider processes this data on your behalf. For this, the GDPR requires a data processing agreement (DPA) under Article 28 GDPR.
You rarely have to negotiate this contract. Most providers make it available to business customers, often as part of their terms. Your job is to find it, conclude it, check it on a few AI-specific points and file it.
When you need a contract
When a service provider processes personal data on your behalf, it acts as your processor. This also applies to AI services as soon as employees use them to work on customer data, job applications or internal documents containing personal data. The German Data Protection Conference (DSK) describes the external provider of an AI application, for example a cloud solution, as an extended arm of the controller. In that case the provider is often a processor, and an agreement under Article 28 GDPR must be concluded with it.
- If your team only works with content that contains no personal data, such as subject-matter questions, website copy or outlines, no processing on your behalf is involved. Use a business account all the same.
- If personal data goes in, even only occasionally, you need the contract before that happens.
- If you run an AI application solely for your own purposes on your own servers, the DSK considers you to be, as a rule, the sole controller. A contract may still be needed with service providers who supply servers or maintenance.
- If the provider does not offer a contract, no personal data belongs in that tool.
What the contract must contain
You may only work with providers that offer sufficient guarantees of appropriate technical and organisational measures (Article 28(1)). Audit reports and certificates, which many providers publish in their trust centre, help with this assessment. Article 28(3) GDPR then sets out what the contract must cover:
- subject matter, duration, nature and purpose of the processing
- type of data and categories of people concerned
- processing only on your documented instructions
- confidentiality of the people involved
- technical and organisational measures
- rules for sub-processors
- support with requests from the people concerned, data breaches and impact assessments
- deletion or return of the data at the end
- evidence of compliance and audits by you
The contract must be in writing, and an electronic format is expressly permitted (Article 28(9)). Many providers therefore let you conclude it online. OpenAI, for example, concludes its Data Processing Addendum for ChatGPT Business, ChatGPT Enterprise and the API via a form. For Copilot, Microsoft refers to its existing commitments to commercial Microsoft 365 customers, set out in its Product Terms and Data Protection Addendum.
What else to check with AI
- Training: The contract should rule out your prompts being used to train the models. If this is only a setting, check who can change it. If training cannot be excluded and personal data is involved, the DSK considers that a separate legal basis is needed for this purpose.
- Storage location: Processing in the EU or a verified basis for transfers to other countries.
- Retention: How long are prompts and outputs stored?
- Sub-processors: Many AI services use data centres or models from other companies. The provider may only engage further processors with your prior authorisation. Under a general authorisation, it must inform you of every intended change so that you can object (Article 28(2)). It must impose the same data protection obligations on its sub-processors.
On storage location: a transfer to a country outside the EU is possible if the European Commission has found an adequate level of protection there or appropriate safeguards are in place, such as standard contractual clauses (Articles 45 and 46 GDPR). For the USA, the European Commission adopted an adequacy decision on the EU-U.S. Data Privacy Framework on 10 July 2023. It only covers companies that have certified with the US Department of Commerce. You can check whether a provider is included in the public list at dataprivacyframework.gov.

Checklist for the provider
You can put these questions to the provider or look them up in its documentation. Most answers are in the contract, on the privacy page or in the trust centre.
- Is there a data processing agreement for the plan we want to use?
- Is training on our prompts excluded, in the contract or by default?
- In which countries is the data processed, and on what basis for countries outside the EU?
- Where is the current list of sub-processors, and how does the provider announce changes?
- How long are prompts, outputs and uploaded files stored, and can we configure this?
- Who at the provider can access content, and under what circumstances?
- What information on how the system works does the provider make available in case we need a data protection impact assessment?
On the last question: if you use someone else's AI system, you depend on the provider's information for a risk assessment or impact assessment. The DSK therefore advises paying attention to this when choosing a provider.
Example: a property management company
A property management company with 20 employees wants to introduce an AI assistant for everyone. It will be used to answer tenant enquiries, so personal data will go into it.
Before: Three employees already use private accounts. Nobody knows whether prompts are used for training. There is no contract.
After: The management chooses a business plan, concludes the data processing agreement via the provider's form and works through the checklist. The private accounts are no longer used for work. The assistant is entered as a recipient in the record of processing activities, with details of transfers outside the EU where applicable. The contact person files a note with this structure:
- tool and plan, date the contract was concluded, where the contract is filed
- what the tool is used for and which data may go into it
- result of the checklist, one point per question with where the answer was found
- retention period and who internally can view conversations
- date of the next review, for example after a change of plan or a change to the list of sub-processors
This lets the company show what was checked if customers, its data protection officer or the data protection authority ask.
Next steps
- List the AI tools that personal data goes into or could go into.
- For each tool, find the data processing agreement or conclude one.
- Work through the checklist and file the note using the structure above.
- If your profession is bound by a duty of confidentiality, also check the rules of your professional regulations.
Which data belongs in a prompt in the first place is explained in the article AI and the GDPR: which data you may enter. For tax advisory firms there is a separate article on client data and AI. For which of your AI tools is the contract already in your files today?
Frequently asked questions
Is the contract also available for free accounts?
Usually not. Providers generally only offer data processing agreements to business customers.
Is the contract enough for professional secrecy?
Not always. If you are bound by professional secrecy, you must also observe the rules of your professional regulations, for tax advisory firms for example § 62a StBerG (German Tax Advisory Act).
Does the contract have to be signed on paper?
No. The GDPR requires the contract to be in writing and expressly allows an electronic format. Many providers let you conclude it online. Even so, file the document where you can find it again.
What if the provider adds a new sub-processor?
Under a general authorisation, it must inform you in advance so that you can object. Check how the provider sends these notices. Read them.
Is it enough for the provider to be based in the EU?
Not necessarily. It depends on where the data is processed and whether sub-processors outside the EU are involved. Ask about this and record the answer.
Sources
- GDPR, Articles 28, 30, 45 and 46, EUR-Lex
- Orientation guide on artificial intelligence and data protection, German Data Protection Conference (DSK), 6 May 2024 (in German)
- German Federal Commissioner for Data Protection (BfDI): Adequacy decision on the EU-U.S. Data Privacy Framework has entered into force (in German)
- OpenAI: Enterprise privacy
- Microsoft: Data, privacy and security for Microsoft 365 Copilot
Updated: . This article is not legal advice.



