Is Your AI Use GDPR-Compliant? A Self-Assessment
Answer 8 questions to see whether your AI use meets the GDPR. Each “no” reveals a gap — and the most common one is the quickest to fix.
You want a simple answer. Is your AI use GDPR-compliant (General Data Protection Regulation)? No one can settle that for you in one line. You can — in eight questions. Answer yes or no to each. Every “no” is a potential gap. France’s CNIL (the national data protection authority) is clear: AI gets no exemption. As soon as an AI system processes personal data, the GDPR applies. Pasting a client file into a consumer ChatGPT is therefore data processing. Let’s run the diagnosis.
The self-assessment: eight questions, eight “yes” to aim for
Take thirty seconds. Answer each question honestly. A “yes” means a point under control. A “no” means a gap to close. Count your “no” answers at the end.
- 1Do you paste personal or client data into an AI tool? A name, an email, an HR file, a contract all count.
- 2Have you identified a lawful basis for this processing? Article 6 of the GDPR sets out six, including consent and legitimate interest.
- 3Do you anonymise the data before writing the prompt? Article 5 requires sending only what is strictly necessary.
- 4Does your AI tool offer a DPA (data processing agreement) with an anti-training clause?
- 5If the processing is high-risk, have you carried out a DPIA (data protection impact assessment)?
- 6Have you informed the people concerned that their data may pass through an AI? Articles 12 to 14 require it.
- 7Do you frame transfers of data outside the European Union, if your provider hosts elsewhere?
- 8Are your teams aware of what they can, and cannot, paste into a chatbot?
How to read your score
Add up your “no” answers. The result is not an official grade. It is a warning signal, for your own use. Here are three simple profiles.
- Zero “no”: your framework is solid. Document it and keep it current with every new tool.
- One to three “no”: targeted gaps to close. Fix the anonymisation one first — it is the quickest.
- Four “no” or more: the risk is real. Set an AI-use policy before you continue, and get support.
One point deserves to be clear. This diagnosis lights up your exposure. It replaces neither legal advice nor your DPO (data protection officer) if you have one.
“Should we just ban AI?” No.
Many directors draw the wrong conclusion. They want to ban AI. That is a mistake. The problem is not the tool. The problem is the personal data pasted into it without care. AI stays useful to reason, write, structure. It simply does not need to see your real values.
Another myth. “We have no mandatory DPO, so no obligation.” Wrong. A DPO is mandatory in only three specific cases, set out in Article 37 of the GDPR. Using AI is not automatically one of them. But the GDPR itself applies in every case. Lawful basis, minimisation, information: these duties hold, DPO or not.
The most common gap — and the quickest to fix
Of the eight questions, one comes back as “no” again and again. Anonymisation. Most teams paste raw personal data into AI, without masking it. It is also the fastest gap to fix. And it touches a central GDPR principle.
Article 5 of the GDPR requires data minimisation. You process only data that is adequate, relevant and limited to what is strictly necessary. Sending a full file to an AI, when a few fields would do, breaches that principle. Anonymising before the prompt applies minimisation to the letter.
| Self-assessment question | GDPR principle | A “no” means |
|---|---|---|
| Do you have a lawful basis? | Article 6 — lawfulness | The processing stays unlawful until one of the six bases is identified |
| Do you anonymise before the prompt? | Article 5 — minimisation | You send more personal data than necessary |
| If high-risk, a DPIA? | Article 35 — impact assessment | A high-risk processing proceeds with no prior study |
| Have you informed the people? | Articles 12 to 14 — transparency | People are unaware their data passes through an AI |
So how do you close this gap? You keep the AI. You only strip the personal data from the prompt. Here is the sequence.
- 1Spot the personal data in your text: names, emails, numbers, amounts, contact details.
- 2Replace each item with a reversible token, in the browser.
- 3Send only the anonymized text to the AI.
- 4Restore the real values in the reply, locally, on your machine.
This step alone does not make your whole use compliant. It does, however, address the most common gap. It directly serves the minimisation of Article 5. And it reduces your reliance on your provider’s anti-training clause, since the AI never sees the real values.
That is what ONYRI Sanitize is for. The engine detects sensitive data — names, emails, numbers, amounts — and replaces it with reversible tokens before sending. Detection and the mapping stay in your browser. The real values never leave your machine. Only anonymized text reaches the model. You keep the power of AI, while applying the minimisation the GDPR and the CNIL expect of you.
Frequently asked questions
- Is your AI use GDPR-compliant?
- It comes down to eight points. Do you paste personal data into AI? Do you have a lawful basis (Article 6)? Do you anonymise before the prompt (Article 5)? Does your tool offer a DPA with an anti-training clause? Have you run a DPIA if the risk is high (Article 35)? Have you informed the people (Articles 12 to 14)? Do you frame transfers outside the EU? Are your teams aware? Every “no” is a gap. The CNIL reminds us that AI gets no exemption.
- Does AI make a DPO or a DPIA mandatory?
- Not automatically. A DPO (data protection officer) is mandatory only in three cases set out in Article 37 of the GDPR. Using AI is not one of them. A DPIA (impact assessment) is required only where the processing is high-risk: on the CNIL’s dedicated list, or meeting at least two of the nine European criteria. But the GDPR applies in every case, DPO or not.
- Is anonymising before the prompt enough to be compliant?
- No, not on its own. GDPR compliance covers the lawful basis, informing people, transfers and security. But anonymising before the prompt fixes the most common gap: pasting raw personal data into AI. This step directly serves the minimisation of Article 5 and cuts your exposure. It is the first “no” to turn into a “yes”.
Sources & references
Keep your sensitive data in your browser
ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.
Anonymize my prompt