Control over AI
Blog
GDPR and workplace AI 7 min read

GDPR and employee use of AI tools: a practical rollout guide

How to frame controller responsibility, DPIA work, employee guidance, data minimisation, and technical controls for workplace AI.

ChatGPT5
Summarise my notes from this performance review into a short write-up.
Paste the notes below and I'll turn them into a concise summary.
ChatGPT can make mistakes. Check important info.

The example above is interactive. Click a highlighted value to see your action options.

GDPR-ready workplace AI rollouts need purpose limits, data minimisation, a DPIA for higher-risk use cases, clear employee guidance, and controls that reduce personal data before it is submitted to AI tools.

Controller responsibility in practice

When your employees use an AI tool for work purposes, your organization is the controller for the personal data they put into prompts. That means the familiar obligations apply: lawful basis, purpose limitation, data minimisation, and the rest.

The challenge is that AI tools have made it much easier to accidentally process personal data at scale. A single support team member can run hundreds of prompts per day, each potentially containing customer names, contact details, or account information.

Treat AI usage as a risk in daily work, not only a procurement risk. The vendor's terms matter, but so does what employees actually do with the tool.

DPIA: when do you need one?

A DPIA is most relevant when the use case is likely to create high risk for individuals. Practical triggers include:

  • Systematic processing of special category data (health, religion, political views)
  • Processing at scale that would not otherwise be subject to oversight
  • Combining datasets in ways that create new risks

Not every use of ChatGPT requires a DPIA, but using it to process customer health records or employee performance data very likely does. Document which categories of data should never enter public AI tools as a starting point for your risk assessment.

Data minimisation: the practical approach

The GDPR principle of data minimisation means using only the personal data necessary for the purpose. In prompt terms, this means:

Employees cannot do this automatically. They need a tool that shows them what is sensitive in their prompt before they submit it, so they can make the right choice in the moment.

ChatGPT5
Summarise my notes from this performance review into a short write-up.
Paste the notes below and I'll turn them into a concise summary.
ChatGPT can make mistakes. Check important info.
Hover or tap a highlighted value to replace, mask, or delete it - before the draft reaches anyone.

Minimisation is not only about the prompt text. A case file, a personnel file, a client report: the same names, dates of birth, and account numbers turn up in documents that get pasted or attached, not just typed. A tool that opens the document, marks what is sensitive, and lets someone redact it before sharing covers that path too.

PreviewAnonymise (4)
The desktop app marks sensitive fields in a document for you to redact before you share it or paste it into AI.

Keep evidence of training, controls, and review without turning the rollout into surveillance.

What employees need to know

They should know:

  • Which tools are approved for which use cases
  • What categories of data are out of scope for AI tools (special categories, confidential client data, credentials)
  • How to anonymise or mask prompts when working with sensitive content
  • Where to escalate if they are unsure

The first bullet assumes you can actually answer it. Most organisations cannot, until they can see which AI tools people have opened, not just the two or three that were formally rolled out:

Search tool, vendor or categoryโ€ฆ
700+ tools
ChatGPT๐Ÿ‡บ๐Ÿ‡ธ
HighAllowed
Claude๐Ÿ‡บ๐Ÿ‡ธ
MediumAllowed
DeepSeek๐Ÿ‡จ๐Ÿ‡ณnew
CriticalNot allowed
Perplexity๐Ÿ‡บ๐Ÿ‡ธnew
MediumNo decision yet
Mistral๐Ÿ‡ซ๐Ÿ‡ท
LowNo decision yet
Midjourney๐Ÿ‡บ๐Ÿ‡ธ
MediumNo decision yet

Every tool, scored for risk

700+ AI tools, each scored Low to Critical, with nothing pre-approved or pre-blocked until someone decides.

More about AI Tools

Each tool lands with a risk score already attached, so "which tools are approved" stops being a guess and becomes a decision you can point to.

A good policy is short, specific, and tied to real tasks. Write rules employees can remember during real work, not a 20-page document they sign once and never read again.

Frequently asked questions

Do all AI tools require a DPIA? Not always. A DPIA is most relevant when the use case is likely to create high risk for individuals.

What should employees know? They should know which tools are approved, what data is out of scope, and how to anonymise or mask prompts.