No AI tool is GDPR compliant on its own. GDPR compliance is a property of how your company uses a tool, not a label a vendor can print on its website: you are the controller, the vendor is your processor, and the question is whether the tool lets you meet your duties. So the useful question is not which AI is GDPR compliant, but which AI passes six checks you can run on any vendor in an afternoon.

This guide gives you that test, runs the common options through it, and shows how to use AI in a GDPR compliant way from the first user on. It builds on the GDPR itself and on the guidance of the German data protection authorities on AI, which was written for exactly this situation: a company that wants to select and use an AI application.

6checks decide whether you can use an AI tool compliantly, not the vendor label
4 %of worldwide annual turnover, or 20 million euros, is the upper fine for the most serious GDPR breaches
2 Feb 2025since then every company using AI must ensure AI literacy of its staff
10 Jul 2023EU-US Data Privacy Framework adopted: transfers only to participating US companies

Why no AI tool is GDPR compliant on its own

Because the GDPR puts the duties on the controller, which is you. Under Article 28 the vendor processes personal data on your behalf and has to sign a data processing agreement, but the legal basis, the purpose, the records of processing, the impact assessment and the proof that all of it works stay with your company; Article 5(2) calls that accountability.

A vendor can make this easy or impossible. Easy means: data stays in the EU or goes only to a country or company with an adequacy decision, the models behind the tool do not train on your inputs, the tool only sees what each user may see, and every access is logged. Impossible means: you cannot find out where a prompt went, which model answered it, or who asked about a customer last Tuesday. The German authorities list exactly these points in their guidance on AI and data protection, from the purpose of the use to the question whether the system is open or closed.

When a vendor writes GDPR compliant on its website, the most it can honestly mean is: this tool can be used in a GDPR compliant way, if you do your part. Ask for the data processing agreement, the list of sub-processors and the training exclusion before you believe the label.

The 6-point test for any AI vendor

Run these six checks on every tool before personal data goes in. The first two are about where data goes, the next two about what the AI can see, the last two about what it does and what is left behind. They follow the six components of an AI operating system for companies, because a tool that has none of those components usually fails the matching check.

CheckAsk the vendorGood answerWarning signLegal anchor
1. Where does it run?Data processing agreement, sub-processor list, data centre regionEU processing, sub-processors named with region, DPA signed before the trialEU region available on requestGDPR Art. 28, 44 ff.
2. Which models are behind it?Every model provider, its region, and the training clauseWritten training exclusion for every provider the tool callsExclusion only for the platform, not for the models behind itGDPR Art. 5(1)(b), 28(3)
3. How does it reach your data?Does it read live from your systems, or copy everything into its own index?Live access to the tools you already run, only what a request needsA full copy of your mailbox and drive, kept indefinitelyGDPR Art. 5(1)(c), 25
4. Who sees what?A live demo with a restricted test userThe restricted user gets no answer about restricted data, down to single recordsPermissions are on our roadmapGDPR Art. 25, 32
5. What may the AI do?Can agents write, send or decide without a person?Every write goes through an approval; no automated final decision about peopleFully autonomous agents as the defaultGDPR Art. 22
6. What is logged?A sample export of the audit logCSV or JSON per user and per tool call, kept at least six monthsA dashboard screenshot instead of a fileGDPR Art. 5(2), 30

Where does your own AI use stand?

The free AI governance assessment checks your policies, records, responsibilities and logs against the GDPR and the EU AI Act, and shows which of the six checks you can already pass. About 12 minutes, anonymous, EU-hosted.

Start the free governance check

Which AI tools are GDPR compliant? The common options through the test

None of them is compliant by default, and most business tiers can be used compliantly if you sign the data processing agreement and close the gaps below. Free consumer tiers are the exception: they are built for private use and are not the place for customer or employee data. The table names the weak spot to check first for each option and links our detailed reviews.

OptionCompany and hostingWeak spot to check firstDetailed review
ChatGPT Business / EnterpriseUS company, EU data residency optionConnectors per user; which data leaves your systems

ChatGPT Business and GDPR

Microsoft 365 CopilotUS company, EU Data BoundaryInherits every M365 permission, including oversharing

Copilot oversharing

Google Gemini for WorkspaceUS company, EU data regionsSees Workspace only; other systems stay outside the controls

Gemini for Workspace review

Claude Team / EnterpriseUS companyData region and which features route data outside the EU

Claude for Enterprise review

German and EU platformsEU company, hosting in the EUPermissions often only per workspace or folder; every model provider behind them needs its own terms

EU platform comparison

Self-hosted open sourceWherever you run itYou own logs, permissions and patches; nothing is there by default

Real self-hosting costs

Free consumer tiersMostly US companiesUsually no data processing agreement for business use: no personal data

EU ChatGPT alternatives

Two things the table cannot show. First, a US vendor with EU hosting still has a US parent, so ask how it handles access requests from US authorities; the European AI data sovereignty guide explains why. Second, the contract matters as much as the product: the DPA checklist for AI tools lists the 12 clauses to read before you sign.

Is there free GDPR compliant AI?

Not for company data. A free tier can be fine for texts without personal data, but as soon as names, customer details or anything about employees go in, you need a data processing agreement, and free consumer tiers usually do not offer one. The cheapest compliant route is a paid business tier or an EU platform without a seat minimum, or a free trial of one before you commit.

The European Data Protection Board made a second point relevant here in its Opinion 28/2024 of 18 December 2024: whether a model itself was trained lawfully can affect how it may be used. That is one more reason to know which models sit behind a tool, the second check in the test above.

How to use AI in a GDPR compliant way: 7 steps

Choosing a tool that passes the test is half the work. The other half is what your company documents and decides, and it takes days, not months.

1

Write down the purpose

Which tasks the AI does, with which data, for whom. A vague purpose like general productivity makes every later step harder.

2

Pick the legal basis

Usually the contract with the customer or a legitimate interest, documented per purpose. Consent from employees is rarely a stable basis.

3

Sign the data processing agreement

With the platform and, through its sub-processor list, covering every model provider. Check the clauses with the DPA checklist.

4

Add it to your records and check the DPIA

Enter the processing in your records under Article 30 and decide whether a data protection impact assessment is needed; our AI DPIA template walks you through it.

5

Set permissions before the pilot

Test with a restricted user that HR, finance and customer data stay where they belong. An AI that answers everyone with everything fails Article 32 on day one.

6

Write the policy and train people

One page on what may go in and what may not, plus role-based training records for the AI literacy duty in Article 4 of the EU AI Act. The AI policy template is a starting point.

7

Involve the works council early

In Germany an AI tool that could monitor staff triggers co-determination; showing the logs and permissions early avoids a stop later. See works council and AI.

Article 22 GDPR and the German guidance both draw the same line: AI may prepare a decision about a person, a person makes it. For hiring and staff evaluation the EU AI Act adds high-risk duties; the Annex III guide for HR covers them.

The questions people actually ask

How Teamo AI passes the six checks

Teamo AI was built around this test for companies with 5 to 200 employees. It runs in the EU with a data processing agreement, calls several model providers with a training exclusion for each, reads live from the tools you already use (Slack, Teams, Jira, Notion, HubSpot, Pipedrive, your calendar) instead of copying them, enforces permissions down to single records, lets agents write only after a person approves, and keeps three separate audit logs for six months that you can export.

It costs 9.97 euros per user and month plus usage-based AI credits, with no seat minimum, and a one-time setup of 500 to 2,000 euros that includes a personal setup with your team. You can run all six checks yourself in the 14-day trial, including the restricted test user.

Teamo AI: access control is not an extra

Run the six checks on Teamo AI yourself: EU hosting, training exclusion, live access, per-record permissions, approvals and exportable logs. 14 days free, no credit card, your team invited in minutes.

Start the free trial, no credit card

Key takeaway: test the tool, then document your part

The question which AI is GDPR compliant has no list as its answer, but it has a test. Six checks separate a tool you can use with company data from one you should keep away from it, and seven steps on your side turn a good tool into compliant use. Run the test before the pilot, not after the first complaint, and compare the results side by side with the compliance software comparison if you also need tooling for the documentation.

Which AI is GDPR compliant, in five sentences

No AI tool is GDPR compliant on its own; you are the controller and the vendor is your processor.

Six checks decide whether a tool can be used compliantly: where it runs, which models, how it reaches data, who sees what, what it may do, what is logged.

Business tiers can pass them with a data processing agreement; free consumer tiers are not for personal data.

EU hosting is necessary, not sufficient: permissions and logs matter as much.

Your part is purpose, legal basis, records, policy, training and the works council, and it takes days, not months.