Generative AI in the Enterprise: What to Review from a Data Protection Perspective Before Using a Third-Party Tool
The use of generative artificial intelligence tools has rapidly integrated into the daily operations of many companies. Solutions such as ChatGPT, Claude, Copilot, or Gemini are already being used to draft texts, summarize documents, prepare presentations, analyze information, generate ideas, translate content, or automate certain internal tasks.
Their utility is evident. They save time, automate processes, and facilitate the work of different departments. However, from a data protection standpoint, their use should not be deployed in an improvised manner nor left to the individual initiative of each employee.
When a company uses a generative AI provided by a third party, it is not merely incorporating one more tool. It is allowing specific corporate information to be entered into an external technological environment, managed by a provider that may be located outside the European Economic Area, utilize international sub-processors, and apply different terms depending on the contracted version.
The relevant question is not only what the tool can do, but what data will be entered, who will process it, for what purpose, for how long, where it is hosted, and what control the company retains over that information.
The Version Used is Not a Minor Matter
One of the first aspects that must be reviewed is the specific version of the tool. Using a free or personal account is not the same as using a business or enterprise version.
In consumer versions, the user accepts general terms and conditions designed for individual use. In many cases, these conditions are not tailored to meet the needs of an organization nor to offer a solid framework for data protection compliance. There may be insufficient administrative controls, or the information entered may be subject to retention and use rules that are largely incompatible with a corporate environment.
Enterprise versions usually offer greater guarantees: centralized user management, security controls, permission configuration, exclusion of data use for training purposes, data processing agreements, information about sub-processors, and clearer retention or deletion options.
For this reason, before permitting the use of a generative AI, the company should define which tool can be used, with which version, and under what conditions. Allowing each employee to use their own personal account generates a risk that is difficult to control.
The Data Processing Agreement
The use of a generative AI tool by a company will, as a general rule, involve the processing of personal data. Even if the organization establishes internal instructions not to enter personal data into prompts or uploaded documents, the provider will normally process, at least, the identification and professional data of the users who access the tool, information linked to account management, activity logs, technical data, usage logs, or information necessary to provide support and ensure the security of the service.
Therefore, one of the first issues to be analyzed is the role assumed by the provider. In most cases, when the tool is provided as a service to the company, the provider will act as a data processor, which entails having a data processing agreement in place pursuant to Article 28 of the GDPR.
This contract, commonly known as a DPA (Data Processing Agreement), must clearly regulate the subject matter of the processing, its duration, the nature of the operations performed, the categories of personal data processed, the categories of data subjects affected, the applicable security measures, and the obligations of the provider. It must also specify how security breaches, data subject rights requests, the return or deletion of information, and the potential involvement of third parties are managed.
At this point, it is particularly relevant to review which sub-processors participate in the provision of the service. Many AI solutions rely on infrastructure providers, cloud services, security tools, technical support, or entities within their own corporate group. The company must know this service delivery chain, especially when any of those third parties may access personal data or process information outside the European Economic Area.
The DPA should not be reviewed in isolation. It must be connected with the terms of service, security documentation, the list of sub-processors, and the specific conditions of the contracted version. Only then can it be verified whether the contractual framework truly reflects how the tool operates and what guarantees the provider offers.
Model Training: A Critical Issue
One of the main questions to analyze is whether the information entered into the tool can be used to train or improve artificial intelligence models.
In a business environment, workers may enter internal information, customer data, financial documentation, or even content subject to confidentiality. Allowing this information to be used to train the provider’s models poses significant risks from both a data protection perspective and the protection of business secrets and confidentiality.
Therefore, the company must verify whether prompts, uploaded documents, generated outputs, and employee feedback can be used to improve the service or train models. This review must be conducted on the specific version to be contracted, as conditions can vary significantly between free, professional, and enterprise modalities.
It is recommended to opt for solutions that exclude the use of corporate data for training by default or, otherwise, choose to disable this functionality. It is also advisable to review the processing of feedback that users may send to the tool, as in some services it may have a different regime than the ordinary content of conversations.
International Data Transfers
Many generative AI tools are provided by vendors located in the United States or by corporate groups with infrastructure, support, or sub-processors outside the European Economic Area. This requires a review of international data transfers.
The company must know where the data is hosted, from which countries it can be accessed, which group entities intervene, and which sub-processors participate in the provision of the service. If international transfers exist, it will be necessary to identify the applicable legal mechanism. In practice, this may involve reviewing Standard Contractual Clauses (SCCs), adequacy decisions when applicable, or specific transfer frameworks recognized by the European Union.
In many cases, it may also be necessary to conduct a Transfer Impact Assessment (TIA). This assessment allows evaluating whether the destination country offers a level of protection essentially equivalent to the European one and whether the contractual, organizational, and technical measures applied are sufficient.
In generative AI tools, technical measures are of particular importance. Encryption, access limitation, data segregation, hosting location, log management, and the ability to restrict processing can be decisive elements in assessing risk.
Data Retention
Another essential aspect is the period for which the provider retains the information. Some tools save conversations so that the user can consult them later. Others retain technical records, activity logs, usage data, or backup copies for certain periods.
The company must know these timeframes and assess whether they are compatible with its own internal retention policies. Not all uses present the same risk. A generic query about writing style is not comparable to uploading a contract containing personal data, a customer complaint, labor documentation, or financial information.
It is also convenient to check whether the organization can delete conversations, disable histories, limit file uploads, configure retention periods, or prevent certain users from using more sensitive functions. If the tool does not offer sufficient control over the information, it may not be suitable for certain processing operations.
Internal Use Policy
Contracting an enterprise version is not enough if users do not receive clear instructions. The company should approve an internal use policy for generative AI tools indicating which tools are authorized, what type of information can be entered, what data must be avoided, and what anonymization or pseudonymization measures must be applied.
This policy must be practical. Employees need understandable criteria to know when they can use AI and when they cannot. They must also understand that AI can generate incorrect, incomplete, or outdated answers, so the results must be reviewed before being used in a professional context.
Registry, Security, and Accountability
The incorporation of a generative AI tool must be reflected in the organization’s compliance system. The company should include it in its inventory of technology providers and, where appropriate, in its record of processing activities or in the internal documentation linked to the corresponding processing.
If the intended use could imply a high risk to the rights and freedoms of individuals, it will be necessary to assess whether a Data Protection Impact Assessment (DPIA) is required. This will depend on the type of data, the volume processed, the purpose, the affected groups, and the role that the AI plays in the process.
Conclusion
Generative AI can bring significant value to a company, but its implementation must be done with sound judgment. It is not about banning its use, but about establishing a clear framework that allows exploiting its advantages without compromising personal data, confidential information, or strategic assets of the organization.
The key lies in incorporating these tools with a sufficient prior evaluation, clear rules of use, and adequate control over the information that is entered into them.

