Important: This is practical information for Irish SMEs, not legal advice. Your obligations depend on the data, purpose, product settings and contracts involved.

Start with the information, not the tool

“Can we use ChatGPT?” is usually the wrong first question. The useful question is: “What information are we putting into it, for what purpose and under what controls?” A prompt that asks for a generic marketing outline may contain no personal data. A prompt that pastes a customer email, a CV or meeting notes often does.

The Irish Data Protection Commission (DPC) says organisations should understand what personal data an AI product uses, where it goes, whether the provider retains or reuses it, and how the product lets the organisation meet its GDPR obligations. The same thinking applies to ChatGPT, Copilot and other generative-AI tools.

Legal duties when personal data is involved

Where your business processes personal data through an AI tool, the GDPR still applies. The tool does not remove the usual responsibilities.

When a DPIA may be required

A data protection impact assessment (DPIA) is not automatically required simply because a business uses ChatGPT. It is mandatory before processing that is likely to result in a high risk to people’s rights and freedoms. The DPC highlights examples such as extensive automated evaluation that significantly affects people, large-scale special-category data and large-scale monitoring.

AI use involving recruitment scoring, employee monitoring, health information, children’s data or decisions with serious effects deserves early specialist assessment. Where the threshold is unclear, a DPIA can still be sensible good practice and a useful record of the decision.

Good practice: make a safe path easier than a risky one

These steps are usually sensible controls, but they are not a substitute for deciding the legal position in your own context.

A quick test before a prompt is sent

Ask four questions: Could this identify someone? Is this tool and account approved for that information? Do we know what the provider does with it? Could we explain and support the use if the person asked us about it? If any answer is “no” or “not sure”, stop and use a safer route or seek advice.

Plain-English takeaway

Do not treat the prompt box as a private notebook.

When personal data enters an AI tool, make sure the purpose, lawful basis, vendor arrangements, security and rights process are defensible before the prompt is sent.

What to do this week

  1. Find the AI tools staff already use, including free trials and AI features inside existing software.
  2. Identify which uses involve personal, confidential or special-category data.
  3. Review the provider’s terms, DPA, retention, training and transfer information for the approved use cases.
  4. Set a clear staff rule and an approval route for new tools or higher-risk uses.
  5. Link the use cases to your GDPR records and assess whether any require a DPIA.

For a broader starting point, use the AI compliance readiness checklist, then record the outcome in an evidence pack that connects systems, decisions and controls.

Official sources: GDPR, including Articles 5, 6, 28, 32, 35 and Chapter V ↗ · Irish DPC: AI, LLMs and data protection ↗ · Irish DPC: DPIAs ↗ · EDPB opinion on AI models ↗