Important: This is practical information for Irish SMEs, not legal advice. Your obligations depend on the data, purpose, product settings and contracts involved.
Start with the information, not the tool
“Can we use ChatGPT?” is usually the wrong first question. The useful question is: “What information are we putting into it, for what purpose and under what controls?” A prompt that asks for a generic marketing outline may contain no personal data. A prompt that pastes a customer email, a CV or meeting notes often does.
The Irish Data Protection Commission (DPC) says organisations should understand what personal data an AI product uses, where it goes, whether the provider retains or reuses it, and how the product lets the organisation meet its GDPR obligations. The same thinking applies to ChatGPT, Copilot and other generative-AI tools.
Legal duties when personal data is involved
Where your business processes personal data through an AI tool, the GDPR still applies. The tool does not remove the usual responsibilities.
- Have a lawful, clear purpose. GDPR Articles 5 and 6 require processing to be lawful, fair and transparent, with a valid lawful basis. “It helps staff work faster” is not itself a lawful basis.
- Use only what is necessary. The data-minimisation and purpose-limitation principles mean you should not paste full customer files or staff records into a prompt when a redacted extract or non-AI route would do.
- Be open with people. If the AI use changes how you handle someone’s personal data, update the relevant privacy information and make sure your processing record reflects it. The exact information duty depends on how the data was obtained.
- Put the right vendor terms in place. If the provider processes personal data on your behalf, Article 28 requires a written controller–processor contract with specified terms. Check the actual service terms and data-processing addendum rather than assuming the provider is always only a processor.
- Protect the data and respect rights. Article 32 requires appropriate security. You must also be able to deal with relevant access, correction and deletion requests; the DPC specifically asks whether an organisation can do this for personal data held in an AI system.
- Check international transfers. If personal data is transferred outside the EEA, GDPR Chapter V rules apply. Record the data locations and transfer mechanism rather than relying on a vague statement that a product is “cloud based”.
When a DPIA may be required
A data protection impact assessment (DPIA) is not automatically required simply because a business uses ChatGPT. It is mandatory before processing that is likely to result in a high risk to people’s rights and freedoms. The DPC highlights examples such as extensive automated evaluation that significantly affects people, large-scale special-category data and large-scale monitoring.
AI use involving recruitment scoring, employee monitoring, health information, children’s data or decisions with serious effects deserves early specialist assessment. Where the threshold is unclear, a DPIA can still be sensible good practice and a useful record of the decision.
Good practice: make a safe path easier than a risky one
These steps are usually sensible controls, but they are not a substitute for deciding the legal position in your own context.
- Approve named tools, plans and account types; block or discourage personal accounts for business work.
- Give staff a short “do not paste” list: personal data, confidential client material, passwords, payroll, health data, legal advice and commercially sensitive information unless the use has been approved.
- Configure enterprise privacy, retention and training settings where available, then keep a dated record of what was chosen.
- Use dummy, aggregated or properly anonymised information for testing. Removing a name alone may not make a person unidentifiable.
- Require a competent person to check outputs before they are used for a decision, customer response or publication.
- Keep a simple register: tool, owner, purpose, data categories, vendor, contract, retention setting, transfer position, risks and review date.
A quick test before a prompt is sent
Ask four questions: Could this identify someone? Is this tool and account approved for that information? Do we know what the provider does with it? Could we explain and support the use if the person asked us about it? If any answer is “no” or “not sure”, stop and use a safer route or seek advice.
Plain-English takeaway
Do not treat the prompt box as a private notebook.
When personal data enters an AI tool, make sure the purpose, lawful basis, vendor arrangements, security and rights process are defensible before the prompt is sent.
What to do this week
- Find the AI tools staff already use, including free trials and AI features inside existing software.
- Identify which uses involve personal, confidential or special-category data.
- Review the provider’s terms, DPA, retention, training and transfer information for the approved use cases.
- Set a clear staff rule and an approval route for new tools or higher-risk uses.
- Link the use cases to your GDPR records and assess whether any require a DPIA.
For a broader starting point, use the AI compliance readiness checklist, then record the outcome in an evidence pack that connects systems, decisions and controls.
Official sources: GDPR, including Articles 5, 6, 28, 32, 35 and Chapter V ↗ · Irish DPC: AI, LLMs and data protection ↗ · Irish DPC: DPIAs ↗ · EDPB opinion on AI models ↗