Moviwa

Can I use generative AI with personal data?

7 min read · Reviewed in September 2026

In short

The GDPR does not ban using artificial intelligence with personal data, but it requires a legal basis for doing so, a processor agreement with the provider, and the ability to demonstrate both. The problem is not the AI: it is that every one of those requirements fails when an employee uses a tool the company never contracted.

What the GDPR is, in one useful sentence

Regulation (EU) 2016/679, in force since 25 May 2018, governs how organisations process data about natural persons. Its central idea is not prohibition but the accountability principle of Article 5(2): complying is not enough, you have to be able to demonstrate it. Everything else — legal bases, contracts, records, security measures — exists to make that demonstration possible.

That is precisely the part generative AI breaks. Not because the models are insecure, but because the usage happens outside any record.

What counts as personal data when we are talking about prompts

The GDPR defines personal data as any information about an identified or identifiable natural person, directly or indirectly. The definition is deliberately broad, and in the context of a prompt it tends to surprise people:

  • A first name and surname, obviously. Also a national ID number, a work email address or a phone number.
  • An indirect identifier: "the sales rep for the northern region who joined in March" identifies one specific person inside one specific organisation.
  • A long block of text pasted without reading it: a contract, a forwarded email, meeting minutes, a spreadsheet with a column of names nobody remembered was there.
  • Pseudonymised data that can be reversed. Replacing a name with "Client 4" anonymises nothing if the rest of the text lets you reconstruct who that is.

Genuine anonymisation — making re-identification impossible — does take the data outside the scope of the GDPR. It is the only clean way out, which is why it is the one Moviwa automates.

The four requirements that fail at once

When an employee pastes personal data into an AI tool the company has not contracted, it is not one article that is breached: it is four, simultaneously.

1. There is no legal basis for that disclosure

Article 6 requires a legal basis for every processing operation. A company may well have a basis for processing its customers' data in its CRM, but that does not cover disclosing it to a third party with no role in the relationship. The disclosure is a separate processing operation and needs its own justification.

2. There is no processor agreement

Article 28 requires a contract with any provider processing personal data on the controller's behalf, governing purpose, duration, security measures and what happens to the data at the end. Accepting the terms of a free tool from an employee's personal account is not a processor agreement, and it is not signed by anyone with the authority to sign it.

3. There may be an international transfer without safeguards

Many providers process data outside the European Economic Area. Chapter V requires specific safeguards — an adequacy decision, standard contractual clauses or similar — and an assessment of the destination country. None of that exists when the transfer is decided by an employee from their browser.

If your organisation provides services to the Spanish public sector, the same question reappears under a different name and different thresholds in the ENS, Spain's National Security Framework.

4. The processing appears in no record

Article 30 requires a record of processing activities. Invisible processing is not in the record, so the company states in writing, to its supervisory authority, something that is not true. Not in bad faith: because nobody knew it was happening.

On top of that sits Article 32, which requires security measures proportionate to the risk. It is hard to argue the measures are proportionate when there is not even visibility.

What happens if the tool trains on what you send it

This is the question that comes up most, and the honest answer has two parts.

The enterprise plans of the major providers generally undertake contractually not to use conversation content to train models. Free and consumer plans, in general, either make no such commitment or make it conditional on a setting the user has to turn on.

The distinction matters, but it is secondary. Even if the provider does not train on the data, the disclosure has already happened: a third party is processing personal data with no processor agreement in place. Training makes the problem worse; it does not create it.

And the real gap is not in the corporate plan the company contracted. It is in the personal accounts nobody contracted at all.

How does Moviwa help?

Moviwa acts at the only point where the problem is still solvable: before the prompt leaves the browser.

  • Detection at the moment of sending. Moviwa identifies personal data in the text an employee is about to send — names, tax identifiers, email addresses, phone numbers, account numbers — without depending on the destination tool to cooperate.

  • Block or anonymise, according to your policy. You can stop the message, or let it through with every identifying value replaced by a token. The employee carries on working with the tool and the personal data never reaches the provider. It is the route that turns unlawful processing into processing that simply does not happen.

  • A real inventory of tools. Moviwa shows which AI tools are genuinely in use across the organisation. That is the input that was missing to complete the Article 30 record with data rather than assumptions.

  • An exportable audit log. Every attempt, the policy applied and its outcome are recorded. It is the documentary evidence the Article 5(2) accountability principle demands, produced continuously rather than reconstructed when an inspection arrives.

  • Visibility without surveillance. The dashboard shows usage by team and by person, not the content of conversations. A control system that itself processes excessive personal data solves one problem by creating another.

See how the anonymiser works

Fines: what is at stake

The GDPR sets two tiers of administrative fine:

TierMaximumTypical infringements
Article 83(4)€10 million or 2% of total worldwide annual turnoverNo record of processing activities, no processor agreement, failure to implement security measures
Article 83(5)€20 million or 4% of total worldwide annual turnoverProcessing with no legal basis, breach of the Article 5 principles, international transfers without safeguards

In both cases the higher of the two figures applies, and the percentage is calculated on the group's worldwide turnover — not on the subsidiary's, and not on the affected business line's.

Worth adding what the table does not show: the fine is rarely the largest cost. An inspection consumes months of management time, and a breach notified to the people affected costs contracts.

Checklist: six steps to using AI without breaching the GDPR

  1. 1

    Find out what is actually being used. Before writing any policy, measure. An internal survey will not do it: nobody declares what they suspect is wrong.

  2. 2

    Decide which tools are authorised and contract the ones that will be used, with a signed processor agreement and a review of where the data is processed.

  3. 3

    Write a short, readable policy. What can be used, with what data, and what to do when somebody needs an exception. Two pages people read beat twenty they do not.

  4. 4

    Apply a technical control. A policy without a control is a statement of intent. The control has to act at the moment of sending, which is while the data has not left yet.

  5. 5

    Update your record of processing activities with the operations that involve AI, and assess whether any of them needs an Article 35 impact assessment.

  6. 6

    Train your staff and keep the evidence. Besides being good GDPR practice, it is a standalone obligation under Article 4 of the EU AI Act.

Frequently asked questions

Does the GDPR ban using ChatGPT at work?
No. It bans processing personal data with no legal basis, no contract with the provider and no way to demonstrate either. With a contracted tool, a signed processor agreement and a control that stops what must not leave, the use is perfectly lawful.
Is removing the name before pasting the text enough?
Not always. If the rest of the information still identifies the person, it is still personal data. Pseudonymisation reduces the risk but does not take the processing outside the scope of the regulation; only effective anonymisation does.
What if the employee uses their personal account on their own phone?
It is still the company's responsibility if company data is involved. It is also the hardest scenario to detect, and the reason the control has to be deployed at organisation level rather than depending on individual goodwill.
Do I need an impact assessment to use AI?
It depends on the processing, not on the technology. Article 35 requires one where the processing is likely to result in a high risk to people's rights: large-scale processing, special categories of data, or automated decisions with significant effects.
Does Moviwa certify my GDPR compliance?
No. Moviwa applies the controls and produces the evidence. Conformity is something your organisation sustains before its supervisory authority.

Official sources

Start by knowing what data is leaving

None of the six measures above can be planned without knowing what is happening in your organisation today.

No commitment · 15 minutes · No card

Related frameworks

Moviwa implements the technical and organisational controls these frameworks require, and produces the evidence to demonstrate them. Moviwa is not certified against these standards and does not certify your organisation: compliance remains your company's responsibility.

This content is informational and does not constitute legal advice. For decisions about your organisation's compliance, consult your legal adviser.