Compliance

GDPR and Generative AI

Can you put customer data into ChatGPT or Copilot? Yes, under three conditions, all of them at once.

SJ.CO

Three conditions, not just one

A valid legal basis, a signed data processing agreement with the provider, and minimisation of the data sent.

SJ.CO
The mandatory contract

What is a DPA?

What it is

The data processing agreement required by Article 28 GDPR whenever a third party processes your data.

Who signs it

You and the provider. OpenAI, Microsoft, and Google offer it directly from the customer portal.

SJ.CO

A server in Europe is not enough

The 2018 US CLOUD Act lets the United States compel data hosted in Europe. Location alone does not replace a provider governed exclusively by EU law.

SJ.CO
Four actions

Where to start, concretely

Map the AI tools in use and check their DPAs
Sign the missing DPAs (a few clicks with each provider)
Minimise by default: send only what the task requires
Log sensitive uses: who, which tool, what purpose, what date
SJ.CO
Framework in place

Sign the contracts before you use the tools

We map your tools, sign the contracts, and set up the logging. An hour covers the essentials.

saint-jean.co · bringing your AI use into compliance.

SJ.CO