How safe is your use of AI in data protection terms?
Ten questions, about three minutes: we show where gaps typically sit when using AI tools — broken down into four areas, with a prioritised list of what to tackle first. No sign-up, no email address. An orientation, not legal advice.
Ten questions, about three minutes. No email address needed, the result appears immediately — and your answers never leave your device.
-
What kind of data do staff currently enter into AI tools?
- Only general or already public content
- Internal but uncritical text
- Customer data or trade secrets
- Also highly sensitive data (health, applications, personnel files)
-
Do you know which AI tools are actually being used in the company?
- Yes, there is a maintained overview
- Broadly speaking
- Only by hearsay
- No — everyone uses whatever they find
-
Are entries shortened or stripped of personal details beforehand?
- Yes, that is a binding rule
- Mostly, on the staff's own initiative
- Rarely
- No, it has never come up
-
Where do the providers you use process your data?
- Exclusively in the EU or EEA
- EU processing assured, but never verified
- Also outside the EU
- Unknown
-
Is it ruled out that your entries are used to train the models?
- Yes, contractually assured and switched off in the settings
- Switched off in the settings, but not assured in writing
- Not checked
- No — the entries feed into training
-
Do the tools run on business plans or on private accounts?
- Exclusively business plans on company accounts
- Mostly business
- Mixed
- Mostly private or free accounts
-
Is there a data processing agreement in place for the tools you use?
- Yes, for all of them — filed and findable
- For the most important ones
- Only for a few
- For none, or unknown
-
Are the AI tools listed in your record of processing activities?
- Yes, kept up to date
- Partly
- The record exists, but the AI tools are missing from it
- There is no record
-
Is there a written rule about what is allowed with AI and what isn't?
- Yes, known and acknowledged by everyone
- Yes, but hardly anyone knows it
- Only verbal agreements
- No
-
Who is responsible for AI matters in the company?
- A clearly named person with time allocated for it
- Named, but purely on the side
- Unclear
- Nobody
Important: This check is an orientation aid and not legal advice. It does not establish compliance; it shows typical gaps and sensible next steps. For binding statements, consult a data protection officer or a law firm specialising in data protection.