Reading time: 5 min | Published: June 2026 | Category: Privacy, GDPR, Compliance
Everyone knows GDPR. Cookie banners, privacy policies, data processing agreements — companies have spent years and millions getting compliant.
Then they gave their employees access to ChatGPT.
And with that, years of compliance work developed a significant blind spot.
What GDPR actually requires
The General Data Protection Regulation is built on a few core principles. Two of them are directly relevant here.
Purpose limitation: personal data collected for one purpose cannot be used for another. If a client gave you their address to receive a contract, that address cannot be fed into an AI model without a separate legal basis.
Data minimization: you should only process the personal data that is strictly necessary for the purpose at hand. Not everything you have. Not everything in the file. Only what you need.
When a lawyer uploads a client contract to ChatGPT to get a summary, they are sending that client's full personal data — name, address, identification numbers, financial details — to a third-party AI provider. That provider processes the data on their servers, under their terms, in their jurisdiction.
This is a data transfer. It requires a legal basis. In most cases, there isn't one.
The "but they have a privacy policy" argument
AI providers do have privacy policies. Some offer enterprise agreements with stronger data protections. Some allow users to opt out of training.
None of this resolves the fundamental issue: the moment you send personal data to a third-party service without a valid legal basis, you are potentially in violation of GDPR — regardless of what that service promises to do with it.
The regulator doesn't ask "did the AI company have good intentions?" They ask "did you have a legal basis to share this data?"
The professional secrecy layer
For certain professions, the problem goes beyond GDPR.
Lawyers are bound by professional secrecy. Doctors are bound by medical confidentiality. Accountants, notaries, and financial advisors operate under similar obligations. These aren't just regulatory requirements — they are fundamental to the trust relationship with clients.
Sending a client's file to an AI model, even for a useful analytical purpose, may breach those obligations. The fact that the AI response is helpful doesn't make the transmission lawful.
What data minimization looks like in practice
The principle is simple: before processing personal data, ask whether you actually need it.
If you're using AI to summarize a contract, do you need the counterparty's home address in the text the AI receives? Probably not.
If you're using AI to flag risks in a financial report, does the AI need the account holder's IBAN and social security number? Almost certainly not.
The AI needs the content — the clauses, the figures, the structure — not the identity of the people those clauses and figures relate to.
This is the logic behind how ArcanAI works. Before your document reaches any AI model, the personal data is stripped and replaced with neutral tokens. The AI receives what it needs to do its job. The identity stays with you.
It's not just good privacy practice. It's what GDPR's data minimization principle actually requires.
What to do if your team uses AI with client data
If your organization uses AI tools — and most do, whether officially or not — the question isn't whether to act. It's how.
Start with an audit. Understand which AI tools your team is using and what data they're sending. Most organizations discover the answer is "more than we realized."
Then build a process. Either restrict what can be sent to AI tools, or implement a layer that anonymizes data before it reaches them. The second option is more practical — it doesn't block productivity, it just adds a privacy layer.
ArcanAI was built for exactly this use case. Free to try at arcanai.co.
