---
title: AI &amp; Data Protection 2025: How to Use LLMs in Compliance with the GDPR—and Get a Handle on Shadow AI in Your Organization — isla Studio
url: https://isla-stud.io/allgemein/ki-datenschutz-2025-wie-sie-llms-dsgvo-konform-nutzen-und-schatten-ki-im-unternehmen-in-den-griff-bekommen/
date: 2025-12-12
---

# AI &amp; Data Protection 2025: How to Use LLMs in Compliance with the GDPR—and Get a Handle on Shadow AI in Your Company

It’s highly likely that someone in your company has already been using AI—without any guidelines, approval, or data processing agreement.



In marketing, texts are polished with ChatGPT; in sales, customer data ends up in prompts; and in development, code is double-checked using AI tools. While well-intentioned, from the perspective of the GDPR, the EU AI Regulation, and corporate compliance, this is a ticking time bomb: shadow AI.



At the same time, it would be absurd to forgo the productivity gains offered by modern large language models (LLMs). The trick lies in reconciling AI and data protection—with a clear framework that allows for innovation while limiting risks.



As a certified AI expert (MMAI® Business School Certificate, Academy4AI) and a future member of the German Federal AI Association, I guide companies precisely at this intersection of technology, law, and governance—and as a WooCommerce specialist and WordPress developer for small and medium-sized businesses and industry, I have a very clear understanding of the practical aspects from my project experience.



This article covers:




how the GDPR and the EU AI Act interact,



which risks are truly relevant when using ChatGPT, Claude, Gemini, and similar tools,



what best practices you should implement for data-protection-friendly AI use,



and why a platform like InnoGPT is an exciting option if you want to provide your teams with a GDPR-compliant AI environment.




In this article, I share my professional perspective as a certified AI expert. However, this post is not a substitute for individual legal advice. If you need a binding assessment under data protection law, I recommend consulting a qualified attorney or data protection officer.





1. The Binding Legal Framework for 2025: GDPR + EU AI Regulation (AI Act)



1.1 The GDPR Remains the Foundation for All Personal Data



As soon as you feed personal data into AI systems—whether for training, responding to queries, or analysis—the GDPR applies. Among other things, you must:




have a legal basis under Article 6 of the GDPR,



ensure transparency toward data subjects,



comply with data minimization,



implement technical and organizational measures (TOMs),



and, where applicable, conduct data protection impact assessments (DPIA). (Handelsblatt Live)




In 2024, the German Data Protection Conference (DSK) published a detailed guidance document titled „AI and Data Protection.“ It makes it clear that whoever selects and uses AI applications is responsible for ensuring that this selection complies with data protection regulations—including the choice of provider, data flows, and configuration. (Data Protection Conference)



The EDPB (European Data Protection Board), through its ChatGPT task force, has also addressed specific questions regarding the legality of web scraping, transparency, and accuracy requirements for LLMs. (EDPB)



In short: Even though AI is new, it is not a legal vacuum when it comes to data protection.



1.2 EU AI Regulation (AI Act): Risk-Based &amp; Governance-Driven



With the EU AI Regulation (Regulation (EU) 2024/1689), the EU adopted the world’s first comprehensive legal framework for AI systems in 2024. The AI Act has been in effect since August 1, August 2024 and is based on a risk-based approach: ranging from minimal risk to limited risk to high-risk AI and prohibited practices. (EUR-Lex)



Key points:




Certain prohibitions on specific AI practices (e.g., certain forms of manipulative systems) and requirements for AI literacy have been in effect since February 2, 2025. (EU Artificial Intelligence Act)



Most of the obligations—particularly those for high-risk AI—will take effect gradually through August 2, 2026, with further details and guidelines to be provided by the European Commission and the new European AI Office. (AI Act Service Desk)



Among other things, the AI Act establishes requirements for risk management, data quality, logging, technical documentation, transparency, human oversight, and governance structures. (EUR-Lex)




The EU is currently discussing extending certain obligations for high-risk AI until 2027 to give companies more time to comply. As of today (December 11, 2025), this is a political proposal that still needs to go through the legislative process. (Reuters)



Important for you: The GDPR remains fully applicable; the AI Act supplements it. When in doubt, keep this in mind:




„The AI Act regulates what an AI system is allowed to do—the GDPR regulates how you are allowed to handle personal data.“ (Handelsblatt Live)




1.3 AI Literacy &amp; Governance Obligations: Why Companies Will Need Demonstrable AI Competence Starting in 2025



The EU AI Regulation establishes, for the first time, a clear framework for the organizational responsibilities of companies that use AI systems—regardless of whether they develop their own models or use external tools.



Two points will be particularly important starting in 2025:



AI Literacy Requirement (Art. 4 AI Act)—effective February 2025



Companies that provide or deploy AI systems („providers“ and, above all, „deployers“) must ensure that their employees possess a sufficient level of AI literacy. In practice, this means:




Employees must understand how AI works in general, where the risks lie, and how to work with it safely.



Companies must provide training, awareness-raising measures, and internal guidelines.



These measures must be documented in such a way that they can be verified as part of the accountability requirements.




In other words:




Since February 2025, „using AI“ has been inextricably linked to „demonstrating AI competence.“




AI Governance – Relevant for General-Purpose AI Since August 2025



With the implementation of the regulations on General-Purpose AI (GPAI) in August 2025, additional organizational requirements will apply—particularly for providers, but indirectly also for companies that use such systems in production:




structured documentation of the models used,



monitoring and logging of usage,



processes for incident management, risks, and complaints,



clear roles and responsibilities in AI deployment.




Even though the full set of obligations for high-risk AI will not take effect until 2026/2027, one thing is clear: Without an AI governance framework—that is, documented responsibilities, guidelines, processes, and training—it will become increasingly difficult for companies to credibly demonstrate AI Act- and GDPR-compliant use.



2. What Regulatory Authorities Specifically Say About AI &amp; LLMs



To put this into perspective, let’s briefly look at three key sources:




DSK Guidance Document „AI and Data Protection“ (2024)—provides companies and government agencies with criteria for selecting and deploying AI systems: purpose limitation, legal basis, data minimization, transparency, data processing on behalf of others, and technical and organizational measures. (Data Protection Conference)



EDPB ChatGPT Task Force Report (May 2024) – highlights, among other things:

how training using web scraping of personal data should be assessed from a legal perspective,



what transparency and information obligations exist toward users,



what requirements apply to the accuracy and fairness of LLM responses. (EDPB)




National guidance documents, e.g., HWR Berlin / Data Protection Officer – provide very specific guidance on what data is generated when using generative AI and how this use can be made data-protection-friendly (e.g., no direct identifiers, pseudonymization, no sensitive data in freely available tools). (Data Protection HWR Berlin)




The message is similar across the board:




Principle: Input as little personal data as possible into AI systems.



Companies need clear rules regarding which tools may be used and how.



„Just trying it out quickly“ is not a legal justification.




3. Typical Risks: How „Shadow AI“ Emerges in Companies



Here are some typical situations I see time and again:




Marketing uploads customer data (e.g., CRM exports) into any AI web app to „quickly create segments.“



HR has ChatGPT evaluate employment contracts or job applications—including complete personal data.



Sales copies entire email threads containing personal information into LLMs to formulate „better responses.“



Business units use free LLM tools without a corporate account, without a data processing agreement, and without knowing where the data is being processed.




From a data protection perspective, this raises several issues:




unclear roles and responsibilities (controller/processor),



potential transfers to third countries (e.g., the U.S.),



unclear storage and use of data for training purposes,



and a lack of or insufficient information provided to data subjects.




It is precisely these cases that data protection supervisory authorities have been focusing on more closely in recent months—even going so far as to impose short-term restrictions and conduct audits on individual providers. (StreamLex)



4. 10 Basic Rules: Using LLMs in a Data-Protection-Friendly Manner (Individually &amp; as a Team)



Whether you’re a sole proprietor or an IT department at a small-to-medium-sized business—the following rules are very helpful in practice for using LLMs in a GDPR-compliant manner:




No sensitive personal data in consumer accounts—Health data, special categories under Article 9 of the GDPR, confidential employee information, internal contracts, etc., have no place in freely accessible AI front ends. (Data Protection, HWR Berlin)



Pseudonymize or anonymize wherever possible. Instead of „Max Mustermann, IBAN, Project XY for Client Z,“ use: „Client A, Budget B, Project in the field of mechanical engineering, Export Country D.“



Clear tool strategy: separate personal and professional use. No „I’ll just use my personal ChatGPT account.“ Define approved tools—and, when in doubt, block problematic domains via the company proxy. (North Rhine-Westphalia State Database)



Create a company-wide policy („AI Policy“)—keep it short, understandable, and practical: Which tools are allowed? What data is permitted? Who is the point of contact for questions? An AI policy is no longer just a „nice-to-have“ but a central element of AI governance.



Clarify the legal basis: Within the company, you will often rely on legitimate interests (Art. 6(1)(f) GDPR), contract performance, or, where applicable, consent. It is important to maintain clear documentation in the record of processing activities. (Data Protection Conference)



Conduct a Data Protection Impact Assessment (DPIA)—especially for sensitive scenarios. When AI systems significantly impact business processes or involve profiling, a Data Protection Impact Assessment is often mandatory. (Data Protection Conference)



Log activities and ensure traceability. Who uses which system and for what purpose? Logging is not only an IT security issue but also a governance issue—and aligns well with the documentation-oriented logic of the AI Act. (EUR-Lex)



Choose Models &amp; Providers CarefullyCheck the following: hosting (EU/EEA?), data processing agreement, storage and training policies, transparency, and technical security features. Some providers now explicitly advertise „zero retention“ and „no training on customer data.“ (ASCOMP)



Train employees—legally required starting in February 2025. Short training sessions, live demos, small use-case workshops—goal: understanding where opportunities lie and where the red lines are drawn.Since February 2025, the EU AI Act has explicitly required companies to ensure an adequate level of AI literacy. Training, internal guidelines, and documented participation thus effectively become a mandatory component of AI compliance—comparable to data protection or information security training.



Integrating AI &amp; Data Protection with Your Existing Web and SEO Strategy: Those who already work effectively with technical SEO, performance optimization, and structured data management have a solid foundation for seamless AI integrations. Have you seen my guide to technical SEO and my article on the top SEO trends for 2024? Visibility, trust, and legally compliant technologies are all interconnected. (saskialund.de)




5. Why Consumer Accounts (Free or Basic Accounts) from ChatGPT &amp; Co. Are Problematic for Businesses



Even with improvements to privacy settings, the use of traditional consumer accounts remains problematic in many business contexts:




Data transfers to third countries and complex sub-processor chains,



limited or absent data processing agreements,



unclear transparency for data subjects,



partial use of user input for model training (depending on the provider/plan), even though many providers now offer „opt-out“ or business options. (eRecht24)




This doesn’t mean you’re not allowed to use such tools at all, but:




In a business context, they often require significant coordination efforts, contract reviews, and additional measures to ensure proper compliance.



Especially in a business context, it is therefore often worthwhile to switch to dedicated AI platforms that are explicitly designed for GDPR-compliant use.




6. Data Protection-Compliant AI Platforms—A Focus on InnoGPT and Langdock



There are now platforms that bundle various LLMs in an EU-hosted, GDPR-compliant environment. Two of these are InnoGPT and Langdock.



6.1 What Sets InnoGPT Apart?



Based on publicly available descriptions, here is a brief summary:




InnoGPT bundles leading language models (e.g., GPT-4, GPT-5, Gemini, Claude, Mistral, etc.) into a platform specifically targeted at German and European companies. (sysbus.eu)



The platform relies on hosting in Europe and advertises a contractually guaranteed „zero-retention policy,“ meaning that customer inputs are not used to train AI models and are processed exclusively on European servers—so the inputs do not end up with the original third-country provider. (ASCOMP)



It addresses typical business requirements such as team features, workflows, and integration into existing processes.




If you’d like to take a closer look, feel free to use the link below:



Get to know InnoGPT (partner link)











For companies looking to replace shadow AI while equipping their teams with modern tools, this approach is particularly compelling:




Your teams continue to work with powerful models—but in a controlled, auditable, and GDPR-compliant environment.








7. Real-World Examples: How SMEs and Industry Could Use InnoGPT



Here are some scenarios I’ve encountered in projects and discussions with clients:




Technical Sales &amp; Proposal Preparation

Technical texts, product descriptions, and proposals are prepared using InnoGPT.



Internally used documents can be integrated via retrieval techniques without the company losing control over the data. (arXiv)




Knowledge Management &amp; Documentation

Internal guidelines, manuals, and SOPs are made available for Q&amp;A in a secure environment.



Employees ask questions such as „What testing steps apply to product line X?“—InnoGPT provides answers based on internal documents without sharing them with external training systems. (arXiv)




Marketing &amp; Content for B2B Websites and Online Stores

Content drafts for WooCommerce stores, product pages, and blog articles are created and then reviewed by subject matter experts.



Because data is stored and processed in Europe, this integrates much more seamlessly into an existing data protection and compliance strategy than the use of disparate consumer tools. (Capterra)




8. Governance &amp; AI Strategy: From Individual Tool to Enterprise Solution



If you don’t want to leave AI implementation in your company to chance, you’ll need more than just a single tool:




Assessment

Who is already using which AI tools, and for what purposes?



What data flows where?




Define the Target Vision

Which use cases should be officially supported (e.g., text, code, research, meeting notes)?



How does AI fit into your existing digital and SEO strategy?




Consolidate the Tool Landscape

Instead of five different AI services operating in the background: a single approved platform, such as InnoGPT, supplemented by clearly defined specialized tools.





Establish Guidelines &amp; Processes

AI policy, data processing agreements, record of processing activities, training.



AI policy, role model, escalation and approval processes.





Monitoring &amp; Continuous Adaptation

AI Act implementation, new guidelines from regulatory authorities, technical advancements—governance is not a one-time project, but an ongoing process. (AKEuropa)




Why this is more than just „best practice“: The AI Act requires—phased in between 2025 and 2027—a documented governance system for companies that use AI. Without an internally embedded AI governance structure (policies, training, monitoring), it will become very difficult in the medium term to demonstrate to regulatory authorities and business partners that AI is being used in a controlled, responsible, and compliant manner.







9. Checklist: Making AI in Your Company GDPR &amp; AI Act-Ready



A brief checklist to get you started today:




Take stock—Where is AI already being used in the company (tools, data types, processes)?



Conduct a risk assessment – Which uses are non-critical, and which involve sensitive data or core processes?



Review legal frameworks &amp; contracts – GDPR, data processing agreements, data flows, transfers to third countries.



Define an approved platform – e.g., InnoGPT as a central, GDPR-compliant AI solution for teams



Adopt an AI policy – clear, practical, with examples and dos and don’ts.



Training &amp; Enablement – Empower employees to use AI in a targeted, responsible, and efficient manner – and document these training sessions (AI Literacy).



Documentation &amp; Monitoring – Take the principles of the AI Act and the GDPR seriously: document, evaluate, and refine. (EUR-Lex)




Sources




Data Protection Conference (DSK), Guidance Document „AI and Data Protection“ (as of May 6, 2024) – Criteria for the selection and use of AI applications in companies and government agencies. (Data Protection Conference)



European Data Protection Board (EDPB), „Report on the Work Undertaken by the ChatGPT Task Force“ (May 24, 2024) – First coordinated European assessment of ChatGPT’s data processing practices in light of the GDPR. (EDPB)



Fact Sheet „Use of Generative AI and Data Protection“ (University / Data Protection Officer, as of April 2024) – Practical guide to the use of generative AI, particularly ChatGPT, from a data protection perspective. (Data Protection Office, HWR Berlin)



eRecht24, „Can ChatGPT Be Used in Compliance with Data Protection Laws?“ (2025) – Analysis of data protection-friendly use of ChatGPT, including guidance on training use and settings. (eRecht24)



Regulation (EU) 2024/1689 – Artificial Intelligence Act (AI Act) – Official EU legal framework for AI, including a risk-based approach, governance obligations, and a timeline for implementation. (EUR-Lex)



EU AI Act Service Desk &amp; FPF Timeline – Overview of the phased implementation of the AI Act through 2026/2027. (AI Act Service Desk)



Reuters &amp; Le Monde (2025), reports on European Commission proposals to extend the timeline for high-risk obligations under the AI Act – indications of a planned delay of certain regulations until 2027. (Reuters)



Handelsblatt Live, “AI and Data Protection: How to Use AI Systems in Compliance with the GDPR” (2025) – Analysis of the interplay between the GDPR, the BDSG, and the AI Act in a corporate context. (Handelsblatt Live)



ASCOMP, sysbus.eu, Capterra – Information on InnoGPT as a GDPR-compliant AI platform with EU hosting and a zero-retention approach. (ASCOMP, sysbus.eu, Capterra)



arXiv – Technical articles on retrieval-based AI applications and knowledge management scenarios in a corporate context. (arXiv)



AKEuropa – Analyses and background reports on the practical implementation of the AI Act in Europe. (AKEuropa)




Note: This article provides technical guidance on the GDPR- and AI Act-compliant use of AI systems. It is not a substitute for legal advice. For binding assessments, you should consult legal experts.