Skip to content
Faylo
All articlesInsights

Can your organisation use ChatGPT under the GDPR/AVG?

By Team Faylo2 min read

Feeding a public chatbot sensitive data is a processing of personal data — often to a third country. What the AVG/GDPR requires, and how pseudonymisation before egress changes the calculus.

The short answer: it depends on what you put in the prompt. The moment a prompt contains identifiable personal data — a name, a BSN, a KvK number tied to a person — using a public AI service is a processing of personal data under the GDPR/AVG. And with most public chatbots, that data leaves the EU and reaches a processor you have no data processing agreement with.

What the AVG asks here

The AVG doesn’t name brands, but it does set principles. Three of them bear directly on AI use:

  • Lawfulness and purpose limitation: you need a basis and cannot simply repurpose data for a new goal.
  • Data minimisation: don’t process more personal data than the task requires.
  • Transfers: sending data outside the EEA requires additional safeguards, and you must know who the processor is.

Important: compliance is a property of your organisation and your processing. No vendor can tick that off for you — Faylo included. What a vendor can do is shape the architecture so those principles are easier to uphold.

Pseudonymisation changes the calculus

The AVG explicitly names pseudonymisation as an appropriate measure (Article 32). If identifiable identifiers are replaced by tokens before the prompt leaves your environment, the AI provider receives no data that can identify a person. The model’s reasoning power remains, but the risk is removed at the source.

This is exactly what Faylo is designed for: deterministic pseudonymisation before egress, with the mapping vault and keys inside your own tenant. Faylo is designed to support your AVG/GDPR obligations — it does not automatically make you “compliant”, but it takes the riskiest step (sending identifiable data to a third party) out of the equation.

A practical checklist

  • Know which data ends up in your prompts and whether it is identifiable.
  • Have a data processing agreement with every party that processes personal data.
  • Minimise transfers: don’t let identifiable identifiers leave the EEA in the clear.
  • Record what happens: an audit trail helps you demonstrate what was processed.

Want to see how this plays out on your own files? Book a pilot and assess the architecture together with your data protection officer.