Compliance8 min read

Is It Safe for French Civil Servants to Use AI?

Civil servants owe professional discretion, sometimes secrecy. Pasting citizens' data into a consumer AI exposes it to a third party.

By Pierre de ONYRI

The answer fits in one line. AI can help you draft, summarise or process a case. But never hand it a citizen's data. A name. An address. A social or medical detail. Pasted into a consumer AI, these details leave your department. That is a transfer to an outside third party. Yet a civil servant owes professional discretion, and sometimes professional secrecy. And your administration remains the data controller under the GDPR. There is a clean method: anonymise before any prompt, then restore the values locally.

The problem: citizens' data pasted into AI

The habit spreads across departments. You ask an AI to summarise a case file. You have it rewrite a letter to a citizen. You submit the draft of a decision. To save time, you paste the raw text. That text often holds the citizens' real data. The risk begins there, not in the tool itself.

An administrative file concentrates sensitive data. Here is what a poorly prepared prompt can expose.

  • The identity and contact details of citizens, and of third parties named.
  • Case data: social situation, income, housing, family.
  • Sometimes health data, a special category under the GDPR.
  • The internal file references and the attached documents.

The stake: discretion, secrecy and the GDPR

A civil servant is not an ordinary employee. They owe professional discretion. This duty sits in Article L121-7 of the General Civil Service Code (CGFP). It covers all facts, information and documents learned on duty. It binds every agent, tenured or on contract. Only the hierarchy can release the agent from it. Discretion protects the administration and its proper working.

Some agents also owe professional secrecy. Article L121-6 of the CGFP sets this and points to Articles 226-13 and 226-14 of the Criminal Code. This secrecy covers roles handling protected information: social work, health, tax, civil status. Unlike discretion, it protects the citizen and their data. The hierarchy cannot release the agent from it.

The sanction is not theoretical. Article 226-13 of the Criminal Code punishes disclosing secret information by a person entrusted with it. The penalty runs up to one year in prison and a 15,000-euro fine. That is the real text, not an estimate.

A consumer AI provider is an outside third party. Pasting citizens' data into an AI means transferring it to them. The content can be retained, reviewed or reused to train the model. This transfer clashes directly with discretion, and sometimes with secrecy. Exposure alone is enough to be a problem, even without a public leak.

The GDPR adds to these duties. Your administration is the data controller for citizens' data. It needs a legal basis, must minimise data and must secure processing. The GDPR also requires a data protection officer (DPO). Its Article 37 makes a DPO mandatory for any public authority or body, whatever its size. The CNIL has even served notice on towns that had not appointed one.

Is AI banned in public administration?

No. No rule forbids a civil servant from using AI. The tool can structure an argument, rewrite a letter or suggest an outline. What causes trouble is exposing the data, not using AI. So the question is not “should we give up AI?”. It is “how do we use it without exposing citizens' data?”. The answer is a framework: legal basis, minimisation, discretion and secrecy, and tools approved by IT.

AssumptionThe reality
“Summarising a file in AI stays internal”It is a transfer to an outside third party, while the agent owes discretion
“Every agent has the same secrecy”No: discretion binds every agent; secrecy binds those handling protected information
“AI escapes the GDPR”No: the administration stays the data controller, legal basis and minimisation included
“AI is banned in public administration”No: it is exposing the data that is the problem, not the tool
The risk isn't using AI — it's the citizens' data you leave behind in the prompt.

The fix: anonymise before the prompt

The fix follows the minimisation principle. When personal data is not needed, you strip it upstream. This is minimisation applied to AI. The agent keeps the tool and saves time. The AI never sees the file's real values. You stay in control of the data, on your own machine.

Two-part diagram: at top, an administrative folder carries a citizen data line in the clear (amber) that reaches an AI card past a columned-building glyph; at bottom, the same line is reduced to cobalt token chips followed by a checkmark, and the AI receives only these anonymized tokens.
After Service-Public.gouv.fr's civil-servant duties fact sheet and the CNIL's DPO and GDPR guidance.

In practice, you proceed step by step. You spot each identifying element. You replace it with a token before sending. The AI reasons about the shape of the file, without reading identities. You then restore the real values, locally. Here is the order to follow.

  1. 1Spot the citizens' data: identities, contact details, case elements, health.
  2. 2Replace them with reversible tokens, in the browser.
  3. 3Send only the anonymized text to the AI, through a tool approved by IT.
  4. 4Restore the real values in the reply, locally, then re-read the result.

That's what ONYRI Sanitize is for. The engine detects sensitive data — identities, contact details, case elements — and replaces it with reversible tokens before sending. Detection and the mapping stay in your browser. Only anonymized text reaches the model. The AI finds only tokens, never citizens' data. You get AI's help, while reducing the exposure that discretion, secrecy and the GDPR ask you to control.

Frequently asked questions

Can a civil servant use AI without breaching discretion or professional secrecy?
Yes, as long as citizens' data is not exposed. Every agent owes professional discretion (Article L121-7 of the CGFP). Some also owe professional secrecy (Article L121-6 of the CGFP, Article 226-13 of the Criminal Code). Pasting a name or a file into a consumer AI transfers that information to a third party. AI stays useful on anonymized text: strip the identifying data before any prompt.
Is AI banned in public administration?
No. No rule forbids AI for civil servants. It is exposing the data that is the problem, not the tool. Use requires a framework: legal basis, minimisation, discretion and secrecy, and tools approved by IT. The good practice is to anonymise citizens' data before any send.
Does anonymising before the prompt make me GDPR-compliant?
No, not on its own. Anonymising reduces risk and supports the minimisation principle. But it does not make the department “compliant” and lifts neither discretion nor professional secrecy. It is one useful control among others. Your duties of legal basis, security and appointing a DPO remain in full.

Sources & references

Keep your sensitive data in your browser

ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.

Anonymize my prompt

Read next