Free instant check

How safe is your use of AI in data protection terms?

Ten questions, about three minutes: we show where gaps typically sit when using AI tools — broken down into four areas, with a prioritised list of what to tackle first. No sign-up, no email address. An orientation, not legal advice.

Ten questions, about three minutes. No email address needed, the result appears immediately — and your answers never leave your device.

  1. What kind of data do staff currently enter into AI tools?

    • Only general or already public content
    • Internal but uncritical text
    • Customer data or trade secrets
    • Also highly sensitive data (health, applications, personnel files)
  2. Do you know which AI tools are actually being used in the company?

    • Yes, there is a maintained overview
    • Broadly speaking
    • Only by hearsay
    • No — everyone uses whatever they find
  3. Are entries shortened or stripped of personal details beforehand?

    • Yes, that is a binding rule
    • Mostly, on the staff's own initiative
    • Rarely
    • No, it has never come up
  4. Where do the providers you use process your data?

    • Exclusively in the EU or EEA
    • EU processing assured, but never verified
    • Also outside the EU
    • Unknown
  5. Is it ruled out that your entries are used to train the models?

    • Yes, contractually assured and switched off in the settings
    • Switched off in the settings, but not assured in writing
    • Not checked
    • No — the entries feed into training
  6. Do the tools run on business plans or on private accounts?

    • Exclusively business plans on company accounts
    • Mostly business
    • Mixed
    • Mostly private or free accounts
  7. Is there a data processing agreement in place for the tools you use?

    • Yes, for all of them — filed and findable
    • For the most important ones
    • Only for a few
    • For none, or unknown
  8. Are the AI tools listed in your record of processing activities?

    • Yes, kept up to date
    • Partly
    • The record exists, but the AI tools are missing from it
    • There is no record
  9. Is there a written rule about what is allowed with AI and what isn't?

    • Yes, known and acknowledged by everyone
    • Yes, but hardly anyone knows it
    • Only verbal agreements
    • No
  10. Who is responsible for AI matters in the company?

    • A clearly named person with time allocated for it
    • Named, but purely on the side
    • Unclear
    • Nobody

Prefer to talk directly? Free initial call

Important: This check is an orientation aid and not legal advice. It does not establish compliance; it shows typical gaps and sensible next steps. For binding statements, consult a data protection officer or a law firm specialising in data protection.

What the check examines

It goes through the four areas where most problems arise when businesses use AI — weighted by how heavily they count when it matters. What weighs most is which data reaches the tools at all: get that right and you are halfway there, even if paperwork is still missing elsewhere.

Data & content

32%

What actually gets typed into the tools — the point where nearly every problem is decided.

Share of the overall result

Provider & processing location

28%

Where the data ends up, who processes it and whether it feeds into model training.

Share of the overall result

Contracts & records

24%

Data processing agreements and the record of processing activities — the first thing a supervisory authority asks for.

Share of the overall result

Rules & responsibility

16%

Whether anyone in the business is responsible and whether staff know what is allowed.

Share of the overall result

What does my score mean?

Risk levels of the GDPR quick check
Grade Points Assessment
75–100 Urgent action needed. The basics are missing in several areas. As long as that is the case, personal data and trade secrets should not reach AI tools at all. The good news: the first steps are legwork, not litigation — taking stock and writing a do-not list gets you out of the red zone within days.
50–74 Clear gaps. Some things are in order, but the safeguards are missing at decisive points. Typically that means missing agreements or unchecked training settings. This can usually be closed within a few weeks without pausing your use of AI.
25–49 Broadly sound. The foundations are in place. What's missing are records and binding rules — the things nobody misses day to day but that count when it matters. Half a day of tidying up gets you into the green.
0–24 Solidly set up. You have the usual pitfalls under control: you know which tools are in use and where the data is processed, and there are contracts and responsibilities. Keep it current — the market moves fast, and a change of provider resets the assessment to the start.

Why high is bad here

Our other tools measure potential — there a high value is a good thing, because there is a lot to gain. This check measures risk. A high value here means safeguards are missing in several places. So that nobody confuses the two, the scale is coloured the other way round and the result explicitly calls the number a “risk score”.

The most common situation in mid-sized businesses is not the risky flagship project but quiet sprawl: individuals working with free accounts and real customer data, without anyone knowing. The check makes exactly that visible — and gives you an order in which to work through it.

Frequently asked questions

Is this legal advice?

No, explicitly not. The check is an orientation: it shows where gaps typically sit when using AI tools and what can be closed first. It replaces neither a review by a lawyer or data protection officer nor a data protection impact assessment. We are an automation agency, not a law firm.

Do I get a “GDPR-compliant” seal at the end?

No — and you should avoid anyone offering you one. Compliance is not a state a questionnaire can establish; it depends on your specific processing, contracts and records. The check therefore names risks and measures, not a clean bill of health.

Why is a high value bad here?

Because this check measures risk, not potential. In the AI potential check a high value means a lot of untapped room — here it means a lot of open issues. That is also why the scale is coloured the other way round: green is good, red means act.

Are my answers stored?

No. The evaluation runs entirely in your browser; your answers never leave your device. We can see neither that you took the check nor what came out of it — unless you tell us in conversation.

We only use AI “on the side” so far — is the check still worth it?

Especially then. The most common situation in small businesses is not the big AI project but quiet sprawl: individuals using free accounts with real customer data, without anyone knowing. That is legally trickier than a properly set-up project — and visible in three minutes.

What does it cost to close the gaps?

Most of it costs time, not money: taking stock, obtaining agreements, checking settings, writing one page of rules. It only gets expensive when a data protection impact assessment or legal review is needed — which is the exception for everyday use cases in mid-sized businesses.

How we support you in clearing this up

You do not have to commission any of this from us — much of it can be done in-house. If you would like support, this is what we actually do.

In a free intro call we will tell you plainly which of these will do something for you — and which will not. Including when the honest answer is “none”.

You've seen the gaps — what now?

In a free 30-minute call we go through your points and separate what you can handle yourself within days from what genuinely needs legal advice. No sales pressure.

Get started

Ready to really put AI to work?

Tell us about your project in a few minutes — you’ll get an honest initial assessment, with no sales pressure.

  • Free & no obligation
  • Reply usually within 1 business day
  • GDPR-compliant