How to Use AI in Your Company Without Breaking GDPR
Yes, you can use AI under the GDPR. The key is minimisation: anonymise personal data before the prompt. A practical guide for company leaders.
The answer fits in one line. Yes, you can use AI in your company without breaking the GDPR. The CNIL does not ban it. It asks you to respect a few clear principles. The most effective of them is minimisation. Send the AI only what is strictly necessary. And anonymise personal data before the prompt. Data that never reaches the model cannot leak. This guide gives you the concrete rules, the objection to answer, and the simplest fix.
The problem: your teams already use AI
Look at what happens across your teams. A salesperson asks ChatGPT to summarise a client exchange. An assistant pastes a contract into Copilot to rephrase it. A support agent types a whole complaint into Le Chat. Each time, personal data leaves the machine. A name. An email. A phone number. Sometimes far more.
These uses are helpful. They save time. But they often happen with no framework and no instruction. That is where the risk begins, for the company and for the people concerned.
The stakes: you are the data controller
One point of law changes everything. The company that decides the purposes and means of a processing operation is the “data controller” under the GDPR. It carries the responsibility for compliance. Including when an employee types personal data into an external AI. The act comes from a staff member. The responsibility flows back to the company.
So the GDPR applies to these uses. The CNIL, the French data protection authority, can investigate and sanction. The regulation provides for graduated administrative fines. Article 83 sets ceilings. They reach up to 10 million euros or 2 % of worldwide annual turnover for some breaches. And up to 20 million or 4 % for breaches of the core principles. These are theoretical ceilings, not an automatic sum. The CNIL adjusts heavily for severity and cooperation.
The rule that protects most: minimisation
Among all the obligations, one acts at the root of the risk. It is data minimisation, set out in Article 5 of the GDPR. The data processed must be adequate, relevant and limited to what is strictly necessary. The CNIL recommends favouring the technique that reaches the result with the least personal data possible. That includes anonymising or pseudonymising upfront, when the person’s identity is not needed.
The reasoning is simple. If the AI does not need your client’s real name to rephrase an email, do not give it. You get the same result, without exposing the person. Minimisation is not a brake. It is the most economical and honest control there is.
Here are the concrete rules to hold, as the data controller.
- Legal basis (Article 6): identify from the start why you process this data — consent, contract, legitimate interest — and document the purpose.
- Minimisation (Article 5): send the AI only what is strictly necessary, and anonymise personal data when the identity is not useful.
- DPIA (Article 35): run a data protection impact assessment if the processing presents a high risk to people.
- Informing people: tell your clients and staff clearly that their data may be processed through AI tools.
- Tool choice: prefer a provider with a data processing agreement (DPA) and a “no training” clause on your data.
- Human in the loop: keep a human review before any decision that affects a person.
Two points deserve rigour, because they are often misunderstood.
| Common belief | The reality |
|---|---|
| “Using AI means you must appoint a DPO” | No. The DPO (data protection officer) is mandatory only in the 3 cases of Article 37 — not from AI alone. |
| “Any AI requires a DPIA” | No. A DPIA is required only for high-risk processing (at least 2 of the CNIL’s 9 criteria). |
| “The GDPR bans AI” | No. The CNIL supports compliant use; it does not ban it. |
| “Anonymised data stays risky” | Data that never reaches the model cannot leak through that model. |
Should you ban AI? The objection to answer
Many leaders settle this with a ban. It is tempting, but counter-productive. Banning AI does not remove the need. Your teams then switch to consumer tools, on their personal accounts, beyond any control. That is “shadow AI”: hidden use, with no framework, where you no longer see anything pass through.
The safe path is the opposite. Frame the use, then equip it. Give your teams a simple way to use AI without exposing personal data. You keep the productivity, and you regain control.
The fix: anonymise before the prompt
Let us turn minimisation into a concrete gesture. Before sending text to the AI, replace each piece of personal data with a token. The client’s name becomes a token. The email becomes a token. The AI reasons about the shape of your request, without ever seeing the real values. You restore the real values afterwards, locally.
That is exactly what ONYRI Sanitize does. The engine detects sensitive data and replaces it with reversible tokens, before sending. The method fits in four steps.
- 1Spot the personal data in your text: names, emails, phone numbers, addresses, amounts.
- 2Replace them with reversible tokens, in the browser.
- 3Send only the anonymised text to the AI of your choice.
- 4Restore the real values in the reply, locally.
ONYRI Sanitize is one minimisation control among your obligations, not turnkey GDPR compliance. But it is the control that acts where the risk begins. Detection and the mapping stay in the browser. Only anonymised text reaches the model. The real values never leave the machine. You apply, in practice, the minimisation the CNIL recommends, and your teams keep the AI that moves them forward.
Frequently asked questions
- Can you use AI in your company without breaking the GDPR?
- Yes. The CNIL confirms AI stays usable in compliance, provided you respect the core principles: legal basis (Article 6), minimisation (Article 5), informing people and security. The most effective control is minimisation: send the AI only what is strictly necessary and anonymise personal data before the prompt. As the data controller, you carry that responsibility, even when an employee types the data.
- Do you need a DPO to use AI in your company?
- Not necessarily. The DPO (data protection officer) is mandatory only in three cases (Article 37 of the GDPR). One: public bodies. Two: organisations whose core activities involve large-scale, regular and systematic monitoring of individuals. Three: those whose core activities involve large-scale processing of special-category or criminal data. Using an AI tool does not, on its own, make a DPO mandatory. One may still be useful, but it is not an automatic requirement.
- Is a data protection impact assessment (DPIA) required for AI?
- Only in case of high risk. A DPIA (data protection impact assessment, Article 35) becomes mandatory when the processing may create a high risk to people’s rights. The CNIL provides a list of nine criteria; meeting at least two of them triggers a DPIA in principle. So not every AI use automatically requires an impact assessment.
Sources & references
Keep your sensitive data in your browser
ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.
Anonymize my prompt