AI and GDPR: where your data actually ends up
Pasting an interview transcript into a generative AI looks harmless. Legally, it is processing of personal data, often combined with a transfer outside the European Union. This article sets out the obligations actually triggered, and why local execution changes the nature of the problem.

A prompt to an AI is processing
As soon as a prompt contains data that identifies a person, directly or indirectly, it constitutes processing under GDPR. A client name, a case number, an interview transcript, a CV, an email: all of it falls within scope.
As a result, you must be able to identify a legal basis, inform the people concerned, record the processing in your register, and guarantee their rights. That last point is often the most uncomfortable: can you answer an erasure request covering what was sent to a third-party service last year?
The question of transfers outside the European Union
Chapter V of GDPR governs transfers to third countries. Using an API whose servers sit outside the Union, or whose operator is subject to foreign law, constitutes such a transfer.
This ground has been unstable for a decade. The Court of Justice of the European Union struck down Safe Harbor in 2015, then Privacy Shield in 2020 in the ruling known as Schrems II. Each invalidation forced thousands of organisations to rewrite contracts under time pressure. Building a lasting dependency on a framework that has already collapsed twice is a bet.
Local execution removes the question. There is no transfer to justify if the data never leaves your premises.
Processors and real confidentiality
An AI vendor processing your data on your behalf is a processor under Article 28. That requires a precise contract, a list of sub-processors, and an obligation to inform you of changes.
Two points deserve close reading in those contracts. First, how long prompts are retained, often set at several weeks for stated security reasons. Second, whether data is used to improve models, sometimes disabled by default on enterprise plans and sometimes not.
For professions bound by a specific duty of secrecy, lawyers, healthcare professionals, banking, GDPR is not the only constraint. Professional secrecy applies independently, and it cannot be delegated by contract.
When an impact assessment becomes necessary
Article 35 requires a data protection impact assessment where processing is likely to result in a high risk. Several situations common in AI trigger that obligation.
- Large-scale processing of sensitive data, in particular health data.
- Systematic evaluation or scoring of individuals, including in a recruitment context.
- Combining datasets from different sources.
- Use of new technologies whose effects are poorly documented.
What on-premises execution simplifies
Hosting AI inside your walls exempts you from nothing: you remain the controller. But several topics disappear outright.
There is no longer a transfer outside the European Union to justify. There is no longer a processor to audit for the inference layer. Retention duration becomes yours. Answering an erasure request becomes an operation you control end to end.
That is the DIWY model. Devana OS runs Suite 366 and Devana entirely on the box, on your premises. Your teams' prompts do not leave the network, and permissions are enforced at platform level.
Key points
- A prompt containing identifying data is processing, with every obligation that follows.
- The transfer framework to the United States has been struck down twice by the CJEU. Depending on it is a known risk.
- Professional secrecy sits on top of GDPR and cannot be delegated by contract.
- On-premises execution does not remove your responsibility, but it removes the transfer and the inference processor.
Frequently asked questions
Is anonymising data before sending it enough?
Rarely. True anonymisation must make re-identification impossible, including by cross-referencing. Removing names from a detailed document usually leaves enough to identify people. That is pseudonymisation, which remains subject to GDPR.
Is a service hosted in Europe compliant?
It is progress, not a guarantee. What matters is the law governing the entity operating the service, not only where the data centre sits. A European subsidiary of a group subject to extraterritorial legislation remains exposed.
Does the AI Act replace GDPR?
No, the two texts stack. GDPR governs personal data, the AI Act governs AI systems by risk level. A single application can fall under both.
Do you still need a processing register with local AI?
Yes. You remain the controller. Local AI simplifies the processor chain and removes transfers, but the documentation obligation stands.
Your AI, inside your walls.
DIWY is available now, delivered within 72 hours, preconfigured with your applications.
Order a DIWY