ChatGPT has long since arrived in everyday working life. In almost every company, there are employees using AI tools: for email drafts, research, summaries, or programming tasks. That is fundamentally a good thing. The problem: in most cases, this happens without clear rules, without coordination with IT, and without regard for data protection.
Experts call this "shadow AI": the uncontrolled use of AI tools within a company. And it is one of the biggest data protection risks that many managing directors don't even have on their radar yet. Not because the technology is dangerous, but because nobody has defined what is allowed and what isn't.
We see this regularly with our customers in Brandenburg and Schleswig-Holstein. The willingness to use AI is there; uncertainty about data protection is what slows things down. This article explains where the actual risks lie, what the GDPR really requires, and why a ban is the worst of all solutions.
Why companies use ChatGPT (and why many get it wrong)
The benefits of AI tools in everyday work are obvious. A sales employee has a quote drafted and saves 30 minutes. A project manager condenses a 20-page set of minutes into three paragraphs. A developer generates boilerplate code and focuses on the architecture. All of this works. And that is exactly why more and more people are doing it, often on their own initiative.
This is where the problem begins. When an employee uses their private ChatGPT account and pastes customer data into the input, the following happens: personal data leaves the company, ends up on servers in the US, and may be used to train future models. Without a data processing agreement. Without the consent of the people affected. Without management knowing about it.
This is not a hypothetical scenario. Samsung experienced exactly this case in 2023: engineers had entered confidential source code into ChatGPT. The consequence was a company-wide ban. Other companies, from banks to law firms, had similar incidents.
But the solution is not to ban AI. The solution is to establish clear rules.
What the GDPR actually says about AI tools
First, the good news: the GDPR does not prohibit the use of AI tools. It governs the handling of personal data, regardless of whether that data is processed in an Excel spreadsheet, a CRM system, or an AI chatbot. If you use ChatGPT without entering personal data, there is little to object to from a data protection perspective.
But as soon as personal data comes into play (names, email addresses, customer numbers, health data), several GDPR requirements apply at once: data processing agreements, privacy by design, and possibly a data protection impact assessment. That sounds like a lot, but in practice it is manageable if you set it up correctly from the start.
The core is simple: it is not about whether you use AI. It is about whether and how personal data is processed in the process. Separate these two questions cleanly, and data protection becomes solvable.
The most common mistakes we see at companies
In our workshops and consulting projects, we encounter the same patterns again and again:
Free accounts used for business purposes. The private ChatGPT account has no data processing agreement. Yet employees use it daily for customer communication. Many companies don't even know this.
No rules about what may be entered. Without a clear policy, employees copy customer lists, contract data, or HR data into AI tools in good faith. Not out of malice, but because nobody told them not to.
Training options not reviewed. Even with paid plans, inputs may be used for model training. The relevant setting must be actively checked and documented.
No internal AI policy. Most companies have a social media policy and a privacy statement, but no AI policy. Yet the need for one is now just as great.
Using AI output unchecked. ChatGPT can invent facts and cite sources that don't exist. If an AI-generated text contains false information about a person and goes out unchecked, that quickly becomes a legal problem.
The biggest data protection mistake is not the technology. It is the absence of clear rules. The good news: those rules can be set up in a single day.
Alternatives to ChatGPT
ChatGPT is the best-known AI tool, but far from the only one. There is now a range of alternatives that can be interesting for companies with data protection requirements: providers with European data processing, models that can be run on your own infrastructure, and API services that by default do not use customer inputs as training data.
The landscape is more diverse than many think. But choosing the right tool depends heavily on the use case: which data is processed? How sensitive is it? Which integrations do you need? How many employees will work with it?
Recommending "the best tool" across the board would be disingenuous. In our workshops, we go through the options with you and evaluate them against your specific requirements. That way, you find not only the safest tool, but also the most useful one for your team.
Why an AI ban is the worst solution
Many companies respond to the uncertainty with a total ban. Understandable, but counterproductive. Shadow AI cannot be prevented if the alternative is a ban. Employees will simply use their private accounts instead, and the risk grows rather than shrinks.
The companies that ban AI are not protecting themselves. They are falling behind. While the competition speeds up processes and cuts costs, their own team loses time on tasks an AI would have completed in minutes.
The better way: introduce AI officially, create safe conditions, and capture the productivity gains. What this requires is not a months-long transformation. It is a structured process that starts with a workshop and ends with a clear policy and the right tools.
Conclusion: it's easier than you think
ChatGPT and other AI tools can be used in a GDPR-compliant way within a company. The technical and legal solutions exist. What is missing in most companies is not the awareness that something should be done, but a concrete plan for how to set it up correctly.
That is exactly what we do in our workshops: in one day, we jointly develop the ground rules for AI in your company. Which tools fit your requirements, which data may be processed where, and what a practical AI policy for your team looks like. At the end, you have not just clarity, but a finished set of rules your employees can apply the very next day.
Whoever sets the rules today has the head start tomorrow.