# GDPR and generative AI: the questions to settle before deploying

> Generative AI does not create new data protection rules: it applies existing rules to flows nobody had anticipated. This guide lists the questions to settle before deployment, in the order they arise, with the texts and the positions of the CNIL, the French data protection authority, that answer them.

Source: https://smartagt.ai/en/ressources/rgpd-ia-generative/
Published: 2026-09-22
Publisher: SmartAGT (NERVIAL LABS)

---
## Start from the uses, not the tool {#uses}

The first question is not a legal one. What will you do with the tool? Draft letters, summarise files, answer customers, search a document base? Each use is a processing operation, with its own purpose, data and recipients. In its [questions and answers on using a generative AI system](https://www.cnil.fr/fr/les-questions-reponses-de-la-cnil-sur-lutilisation-dun-systeme-dia-generative), the CNIL recommends precisely that: start from an identified need rather than deploying a tool with no defined purpose.

A general-purpose assistant open to everyone with no framework makes the questions below impossible to answer. A list of permitted uses, even a short one, makes it possible.

| Question | Reference | What must come out of it |
| --- | --- | --- |
| Who is controller, who is processor? | GDPR, Art. 4, 26 and 28 | The role of each party and the matching contracts |
| On what lawful basis? | Art. 6, and Art. 9 for special-category data | One basis per use, documented |
| Is an impact assessment needed? | Art. 35 | The DPIA, or the reasoning for not doing one |
| Does data leave the EU? | Chapter V | The transfer tool used, or the architecture that avoids it |
| What is collected, and for how long? | Art. 5 and 25 | Minimisation and retention rules enforced by the tool |

## Who is responsible for what {#roles}

The organisation making the tool available to its teams is the controller. The platform vendor and the model provider normally act as processors, under a contract that meets Article 28: processing on documented instructions, confidentiality, security, authorised sub-processors, deletion or return of data at the end of the contract.

The analysis gets harder when a provider reuses data for its own purposes, for instance to train its models. It is no longer simply carrying out your instructions. The CNIL asks organisations to look closely at this point, in particular where data may be reused by the provider under its terms of use. Get a written commitment that data will not be reused, or choose another provider.

> **Watch out** The terms of a consumer offering and of a business offering from the same provider often differ on data retention and reuse. Check the contract you actually signed, not the marketing page.

## Lawful basis and purposes {#lawful-basis}

Each use must rest on one of the bases in Article 6. For an internal productivity tool, legitimate interest is often considered; it requires a documented balancing test against the rights of the people concerned, employees as well as third parties mentioned in documents. Consent is rarely appropriate in an employment relationship, because of the imbalance between employer and employee.

Three situations call for particular scrutiny:

- **Special-category data** under Article 9 (health, opinions, trade union membership): processing it is prohibited unless an exception applies. A use that handles it must be identified as such, not discovered afterwards in the prompts.
- **Automated decisions**: Article 22 governs decisions based solely on automated processing that produce legal effects or similarly significantly affect a person. A model that proposes and a person who genuinely decides changes the nature of the processing.
- **The model itself**: in its [Opinion 28/2024](https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-282024-on-certain-data-protection-aspects-related-to_en), the European Data Protection Board states that the deployer of a model should ascertain, to an appropriate extent, that it was not developed by unlawfully processing personal data.

## The data protection impact assessment (DPIA) {#dpia}

Article 35 requires an impact assessment where processing is likely to result in a high risk to people's rights and freedoms. The European guidelines set out nine criteria; processing that meets at least two is presumed to require one. Innovative use of technology is one of them, and the CNIL lists the DPIA among the measures to plan before deploying generative AI.

In its recommendations on impact assessments for AI systems, the CNIL points to risks specific to these systems, including erroneous content, users' automation bias and data extraction. In practice:

- **Describe the uses** Purposes, data categories, data subjects, flows to each party.
- **Assess necessity** Can the same purpose be achieved with less data, or without personal data?
- **Analyse the risks** Disclosure through a prompt, a wrong answer about a person, excessive retention, provider access, transfer outside the EU.
- **Set the measures** A local model for sensitive uses, pseudonymisation before sending, retention periods, human oversight, training.
- **Involve the DPO** Article 35 requires seeking their advice where one has been designated, and they will follow up the measures over time.

*A generative AI DPIA is structured use by use, not for the tool as a whole.*

If a use is also high-risk under the AI Act, the two assessments are best run together: see the guide [AI Act obligations for businesses](~/ressources/ai-act-entreprise/).

## Transfers and choice of deployment model {#transfers}

Any personal data sent to a provider established outside the EU, or accessible from abroad, is a transfer governed by [Chapter V of the GDPR](https://eur-lex.europa.eu/eli/reg/2016/679/oj): adequacy decision, the Commission's standard contractual clauses, or another appropriate safeguard. A lawful transfer does not, however, settle exposure to foreign laws, which is covered in the guide [The Cloud Act and AI](~/ressources/cloud-act-ia/).

The deployment model largely decides the answer. The CNIL considers that it generally seems more appropriate and more secure to favour on-premise deployment; conversely, with a system used through an API, control lies almost exclusively in the provider's hands.

## Minimisation, retention and rights {#minimisation}

Data minimisation (Article 5) and data protection by design (Article 25) translate into concrete choices:

- **Do not store what is not needed**: a raw prompt kept indefinitely is a personal data file nobody declared.
- **Remove identifiers before sending** where the use allows it: that is the subject of the guide [Anonymise or pseudonymise before an LLM](~/ressources/anonymiser-donnees-llm/).
- **Set retention periods** for conversations, logs and document indexes.
- **Plan for data subject rights**: a person can ask for access to, or erasure of, data about them, including in conversation histories.
- **Frame uses in a policy** listing what is permitted and what is not, as the CNIL recommends, and turn it into configuration.

The overall framework, linking these choices to location and applicable law, is in the guide [Data sovereignty and generative AI](~/ressources/souverainete-donnees-ia/).

## Frequently asked questions {#faq}

### Is a DPIA mandatory to deploy generative AI?

It is whenever the processing meets the conditions of Article 35, which is common: innovative use, employee data, volume. The CNIL lists it among the measures to plan before deployment. If you do not carry one out, document why it is not required.

### Is the model provider our processor?

In principle yes, if it processes the data only on your behalf and on your instructions. If it reuses the data for its own purposes, such as training, the analysis changes and the contract must address it explicitly.

### Can employees enter personal data into the tool?

That depends on the use and the deployment model. The rule must be written in a policy and, ideally, enforced by the tool: a local model for sensitive data, detection and pseudonymisation before anything is sent outside.

### Where SmartAGT fits
SmartAGT is deployed on-premise and acts as a processor within the meaning of the GDPR. The model can be 100% local, or supplied by a cloud provider you contract with directly. In hybrid mode, a privacy vault, once enabled, detects and reversibly pseudonymises direct identifiers (email, phone, IBAN, payment card, IP address, French NIR, SIREN, SIRET, licence plate, and the terms you add) before any outbound call, and no raw prompt reaches the audit log.
Logging relies on a SHA-256 hash-chained audit trail and AES-256 encryption. The platform is not yet certified by a third party. Details are on the [Security](~/security/) page.
