“I would like to use AI, but I am not sure the GDPR allows it.” The GDPR and data privacy are a barrier for SMEs looking to make more use of AI. The answer is rarely “no”, but there are a number of things you do need to think through. This post answers the underlying questions: 1) What does the GDPR say about personal data? 2) What does the GDPR mean for using AI? 3) What does this mean for your business?
1. What does the GDPR say again?
What the GDPR is. The GDPR is the European privacy law (in force since 2018) that sets the conditions under which organisations may process personal data. In the Netherlands the Dutch Data Protection Authority (AP) supervises compliance.
When is something personal data? Any information about an identified or identifiable person: a name, e-mail address, client file or photo. And “processing” covers almost anything you do with it — storing, sharing, and pasting it into a chatbot.1
What does that mean for you? If you process personal data, you must comply with the obligations of the GDPR. Those obligations are not specific to AI: they already applied to the personal data you are almost certainly processing already. Check the AP’s GDPR guidance tool for your own situation.2 The most important ones:
In any event:
- Legal basis: a valid reason, such as consent, a contract or a legitimate interest. “It is convenient” is not a legal basis (art. 6 GDPR).
- Data minimisation: use only the personal data you minimally need to achieve your purpose (art. 5(1)(c) GDPR).
- Accountability and rights: you must be able to justify your choices; individuals keep their rights of access, correction and erasure (art. 5(2) and art. 15–21 GDPR).
- Data processing agreement: the GDPR requires a written agreement whenever an external party — such as an AI provider — processes personal data on your behalf, and prescribes what it must contain (art. 28(3) GDPR).3
- Duty to inform: you must tell people which personal data you process about them, for what purpose and on what legal basis, who you share it with, how long you keep it and what rights they have. In practice you do this with a privacy statement (art. 12 to 14 GDPR).4
Only in special cases:
- Record of processing activities: if you meet certain conditions (for example if you have more than 250 employees) you must keep a record of what data you process (art. 30(5) GDPR).
- DPIA: processing that is likely to involve a high risk requires a prior risk assessment, the Data Protection Impact Assessment (art. 35 GDPR).
2. What does the GDPR mean for using AI?
If you want to start using AI, there are broadly two things to address: 1) you need a valid legal basis (or simply a reason) to use AI, and 2) you apply the GDPR basics to your AI use case.
What counts as a valid legal basis? The GDPR provides six (art. 6 GDPR), of which three are relevant for SMEs: consent from the individuals concerned, performance of a contract (for instance because you have an order to deliver) and legitimate interest (where you have an interest that outweighs the intrusion on privacy).5 Worth noting: consent sounds attractive, but it must be freely given, specific and informed, and the individual can withdraw it at any moment — after which you must stop.
On legitimate interest, the European counterpart of the AP (the EDPB) held on 17 December 2024 that AI applications can be justified, provided you complete the three-step test: name your interest, show your purpose cannot be achieved with less personal data, and weigh your interest against that of the individual.6 A commercial interest is expressly recognised.
Not sure whether this applies to you? In June 2026 the AP published guidance on generative AI and the GDPR that works this through for Dutch practice, with a separate tool for documenting the assessment.7
Applying the GDPR to your use of AI:
- Data processing agreements: choose a plan with an AI provider that includes a data processing agreement.
- Data minimisation: only use AI on personal data where the alternatives cost significantly more effort or money.
- A privacy statement that is accurate: check that what your website says still matches what you actually do.
- Update your privacy statement: name your AI provider as a recipient and state the transfer to the United States with the safeguard relied on. Never let AI take a decision with significant consequences for someone on its own; if you do, you must explain what the system does and what it means for the individual (art. 22 and art. 13(2)(f) GDPR).8
- A data breach procedure: record who you call if personal data ends up in the wrong tool — a client file in a free chatbot is a data breach. You have 72 hours to report it to the AP (art. 33 GDPR).
3. What does this mean for your business?
If you want to comply with the GDPR and use AI, there are four concrete steps you can take.
- Get a business AI subscription. This is the quickest win. With a business plan the data processing agreement is part of the terms and your data is not used for training by default. With free and consumer plans it is not — not even the paid ones. See the table below.
- Record your legal basis and write down the assessment. Name your interest, show the purpose cannot be achieved with less personal data, and weigh this (where you rely on legitimate interest) against the individual’s privacy.
- Keep personal data out of your prompts. What does not go in, you do not have to account for. Use pseudonyms (“client 1 to 30”) where you can. Health data is subject to a stricter regime: processing is prohibited unless an exception applies, in practice usually the explicit consent of the individual (art. 9 GDPR).
- Agree who is responsible for what. Which tools do we allow, what may go into them, who decides on new applications, and who checks the output before it leaves the building. One page of house rules does more than a thick policy nobody reads.
Plans from the three major AI providers that include a data processing agreement (position as at August 2026):
| Provider | Free | Paid consumer | Business |
|---|---|---|---|
| OpenAI (ChatGPT) | No9 | No — Plus and Pro10 | Yes — Business, Enterprise and the API11 |
| Anthropic (Claude) | No12 | No — Pro and Max13 | Yes — Team and Enterprise (Claude for Work) and the API14 |
| Google (Gemini) | No15 | No — not even with Google AI Pro or Ultra on a personal account16 | Yes — Gemini within Workspace Business and Enterprise17 |
So paying is not the same as business: an expensive consumer subscription does not give you a data processing agreement.
And if you do not comply? The AP can impose sanctions where the rules are not met (from a warning through to a fine of up to 4% of worldwide annual turnover). Practice is milder than that maximum suggests. Since 2018 the AP has published 49 sanctions, almost all against large organisations. Two of those concerned the use of algorithms, both at the Dutch Tax Administration, in 2021 and 2022.18 The chance of an SME being fined for using AI is therefore small. The real risk lies elsewhere: a data breach you have to report, a client asking where their data went, or reputational damage because you cannot explain yourself.
How Stokman Advisory can help
Stokman Advisory helps SMEs put this into practice. Think of AI governance — with the key questions: which tools do we allow, what may and may not go into them, who is responsible, how do we document legal bases and assessments, and how do we safeguard human oversight? We also test concrete use cases against the GDPR, carry out DPIAs and guide the transition to a business AI environment.
This article is general guidance, not legal advice.
Sources
- Dutch Data Protection Authority, Algorithms, AI and the GDPR. ↩
- Dutch DPA, GDPR guidance tool for businesses. ↩
- Art. 28(3) GDPR; see also Dutch DPA, Processing agreement. ↩
- Art. 12 to 14 GDPR; Dutch DPA, Right to information. Art. 13 applies where you collect the data from the person directly, art. 14 where you obtained it elsewhere. ↩
- Art. 6 GDPR; Dutch DPA, Legal bases from the GDPR explained. ↩
- EDPB, Opinion 28/2024 on AI models and the GDPR, adopted 17 December 2024, and Guidelines 1/2024 on legitimate interest. ↩
- Dutch DPA, Guidance on generative AI and the GDPR (June 2026) and the accompanying tool. ↩
- Art. 22 and art. 13(2)(f) GDPR. The art. 22 threshold concerns decisions based solely on automated processing that produce legal or similarly significant effects. ↩
- OpenAI, Enterprise privacy at OpenAI (updated 8 January 2026). The DPA is limited to Business, Enterprise and the API; the free tier falls outside it and is covered by the consumer privacy policy. ↩
- OpenAI, Enterprise privacy at OpenAI: Plus and Pro do not appear in the list of products for which a DPA can be executed, and OpenAI states it uses data "from versions of ChatGPT and other services for individuals" for model training. A DPA for ChatGPT Sites (9 July 2026) does exist for Plus and Pro users, but it covers only the data a published ChatGPT Site collects from end users and expressly not "your prompts, files or other content" in your conversations with ChatGPT. ↩
- OpenAI, Enterprise privacy at OpenAI: "we are able to execute a Data Processing Addendum (DPA) with customers for their use of ChatGPT Business, ChatGPT Enterprise, and the API". Note: the former ChatGPT Team is now ChatGPT Business. ↩
- Anthropic Privacy Center, consumer products: Claude Free, Pro and Max are consumer products. The DPA sits with the Commercial Terms and does not apply here. ↩
- Anthropic Privacy Center, consumer products: Pro and Max fall under the same consumer terms as the free tier. Paying does not change the legal status. ↩
- Anthropic, Data Processing Addendum (effective 24 February 2025), part of the Commercial Terms, art. B.1: "Customer is the controller and Anthropic is Customer’s processor". The commercial products are the API, Console and Claude for Work (Team and Enterprise). ↩
- Google, Gemini Apps Privacy Hub: applies to personal accounts, warning "Please don’t enter confidential information that you wouldn’t want a reviewer to see". Human-reviewed chats are retained for up to three years, even after you delete your activity. ↩
- Google, Gemini Apps Privacy Hub: this page expressly covers paid plans ("Subscription information: if you have a paid subscription to a Google AI plan"). A paid personal subscription therefore remains a consumer service. ↩
- Google, Generative AI in Google Workspace Privacy Hub: within Workspace, Gemini is a Core Service and is therefore covered by the Cloud Data Processing Addendum. ↩
- Dutch DPA, Fines and other sanctions (as at May 2026: 49 sanctions since 2018), and the childcare benefit fine of EUR 2.75m (December 2021) plus EUR 3.7m for the Fraud Signalling Facility (April 2022). ↩