"You can't use AI — GDPR forbids it." We hear that at least once a week. It's almost always wrong. But there are real things you need to know — and a few mistakes your SME is probably already making, long before AI even enters the picture.
"GDPR and AI": why everyone is scared (often for no good reason)
GDPR dates from 2018. Consumer-facing generative AI, from 2022. The two have been lumped together in many decision-makers' minds, creating a vague fear: "if we use AI, we'll have data problems."
That fear isn't completely unfounded — there are real risks, and we'll come back to them. But it's often disproportionate, and it holds back businesses that could automate without any legal issue whatsoever.
Here is the real framework: GDPR governs the processing of personal data. Personal data is any information that directly or indirectly identifies a natural person: a name, an email address, a phone number, an IP address, a purchase history.
AI as such is neither permitted nor prohibited by GDPR. What matters is what you do with the data you feed it.
Ask yourself: am I giving personal data to this tool? If not, GDPR does not apply to that specific use. If yes, the usual GDPR rules apply — no more, no less.
What GDPR actually says about AI — 4 simple points
1. It's not the tool that's regulated — it's the processing. Using Claude to write an internal newsletter about company strategy? Zero GDPR issues. Using Claude to analyse your clients' complaints by pasting their names and emails into the prompt? That's personal data processing, and the rules apply.
2. You must have a legal basis to process personal data. The three most common bases for SMEs: the contract (you process a client's data as part of an order), consent (newsletter), and legitimate interest (limited B2B prospecting). If you use AI to process this data, the legal basis must already exist — AI does not create a new legal basis.
3. Minimise the data you share. The principle of data minimisation is one of the cornerstones of GDPR: only process what is strictly necessary for your purpose. In practice for AI: do you really need to include the client's name and address in the prompt, or would the problem work just as well with anonymised data?
4. The EU AI Act (2024) adds to GDPR but does not replace it. The AI Act, progressively applicable since 2024–2025, classifies AI systems by risk level. For an SME using consumer tools (ChatGPT, Claude, Copilot) for internal tasks, you are generally far from the "high-risk systems" targeted by the law. The regulation primarily targets systems that make decisions with a significant impact on individuals.
What your SME is probably already doing wrong — before AI even comes along
Here is what we observe in the majority of Belgian SMEs with fewer than 50 employees. These are not judgements — they are findings we make during every diagnostic session.
No up-to-date privacy policy on the website. Or a copy-pasted version from the internet that doesn't reflect your actual practices. This is a basic GDPR requirement — completely independent of AI.
Newsletters sent without valid consent. Double opt-in is not mandatory in Belgium, but consent must be freely given, informed, specific, and documented. "You left me your business card at the trade fair" is not enough.
Unsecured Excel files containing client data. Shared by email, stored on USB drives, without encryption or access control. That's unsecured personal data processing — GDPR-applicable since 2018.
SaaS tool access shared without a DPA in place. Do you use Google Workspace, Mailchimp, HubSpot, Calendly? These tools process personal data on your behalf. Without a signed DPA, you're not compliant — and again, this has nothing to do with AI.
The real risks when you use ChatGPT or Claude at the office
Let's be concrete. Here are the situations that actually create a risk, and those that don't.
| Situation | Risk level | What to do |
|---|---|---|
| Writing a generic email, a quote, or a product description | None | Go ahead — no personal data involved |
| Summarising a news article or a public document | None | Go ahead — content already public |
| Brainstorming a marketing campaign without client data | None | Go ahead — stay at the concept level |
| Generating creative content, presentations, internal texts | None | Go ahead — no personal data in output |
| Sharing pseudonymised data (Client A, Client B) | Moderate | Verify that the pseudonymisation is genuine |
| Processing data with a legal basis + signed DPA | Moderate | OK if DPA in place and purpose respected |
| Automations that read/write in the CRM | Moderate | Require a DPA from each supplier |
| Pasting identifiable client data into a consumer tool without a DPA | Real | Avoid — concrete risk |
| Processing sensitive data (health, beliefs, detailed financial data) | Real | Reinforced framework — seek legal advice |
| Automated decision system affecting clients/employees | Real | GDPR Article 22 — strict requirements |
| Using client data to train your own model | Real | Explicit consent required in most cases |
How to use AI and stay fully compliant
You don't need a law firm to get started. Here is a 5-step progression any SME can follow.
5 steps to using AI in GDPR compliance
1. Classify your data (1 hour). Separate what is personal (names, emails, client contracts, HR data) from what is not (anonymous internal data, public texts, aggregated statistics). Non-personal data can go into any tool without GDPR constraints.
2. Sign a DPA with your AI providers (30 min per tool). OpenAI, Anthropic, and Google all offer data processing agreements (DPAs) for professional accounts. These agreements define how your data is processed and protected. Check the "Privacy" or "Legal" pages of each tool — the DPA can often be signed in a few clicks.
3. Anonymise before sharing (daily habit). Before pasting a document into a prompt, replace names, emails, and identifiers with codes ("Client A", "Supplier 1"). In 80% of cases, the AI can do its job without needing the real identities.
4. Train your team on simple rules (30-min session). Three rules cover 95% of situations: no identifiable client data in unconfigured consumer tools, no HR data without a DPA, no automated decision without human validation. A 30-minute session is enough.
5. Update your privacy policy (1 hour + legal review). If you use AI to process personal data, mention it in your privacy policy. One sentence is enough: state that you use AI tools as part of your processing activities, with the names of the main providers. It's good practice — and some authorities are starting to require it.
Our approach at LTC Group
AI should not be a barrier — it should be a lever. LTC Group configures AI solutions hosted in Europe, with DPAs in place and compliance measures built in from the start. You use it, we handle the framework. To implement AI without GDPR risk, start with our AI diagnostic.
- Solutions hosted in Belgium or Europe.
- DPA and documentation delivered at handover.
- GDPR × AI team training included.