GDPR and generative AI: what your firm can (and can’t) do
The three conditions for using generative AI without breaching GDPR or professional confidentiality: your data is never used for training, it stays in the EU, and a data-processing agreement is in place. Plus pseudonymization.
The problem
Uploading confidential documents to a public AI cloud means handing them to a third party, often outside the EU, with the risk that they are kept or used to train the model. For a law firm or a regulated business, that is both a GDPR problem and a professional-confidentiality problem.
The three conditions
For generative AI use to be compatible with GDPR and confidentiality, three things are required:
- No training on your data: it is never used to train the model.
- Data in the EU: processed and stored within the Union.
- A signed data-processing agreement with the provider, setting out roles and safeguards.
A setup hosted on your own servers (on your premises or on a dedicated EU server) meets all three from the outset.
Pseudonymization
The GDPR (Articles 4(5) and 32) recognizes pseudonymization as a security measure: names, tax IDs, and IBANs are replaced with placeholders before the model ever sees them. Mind the limits: it reduces risk, but it is not anonymization, and it does not protect the content (a defense strategy remains readable). For that, you need a private space of your own: the data never leaves it, nothing is logged, and no one can read it.
Where regulation is heading
In Italy, Law 132/2025 put AI on the statute books, aligning with the EU AI Act. It adds few new obligations beyond the European Regulation, but it points the way: keeping your data under your control is the prudent posture.
The bottom line
You can use generative AI in a compliant way — provided you choose a setup that never lets your data leave. If you want to understand what is possible in your case, start with 3 hours.
Informational guide, not legal advice. For your specific case, consult a privacy attorney.