It happens. An employee pastes a client contract into ChatGPT to save five minutes, never suspecting the file held a name, an address and a client's bank details, and the realization only lands once the answer is on screen. The first instinct is panic. Wrong move. A data leak through an AI can be handled, as long as you act fast and in the right order. Here is the playbook.
Assess
Identify what left, when, and to which tool.
Contain
Cut access, delete the conversation, rotate what can be rotated.
Notify
Notify the authority within 72h if there is a risk, and the people if high risk.
Prevent
Anonymize at the source so it does not happen again.
Note: this is a général approach, not legal advice. Depending on the context, have the breach qualification and the notification duty validated by your DPO or counsel.
The reflex that changes everything: prevent
Almost always, the incident starts with a harmless move. No malice. Just someone trying to go faster. Banning AI fixes nothing, because teams will reach for it anyway, on a personal account, somewhere you can no longer see what leaves. The real fix sits elsewhere. It makes sure the identifying data never leaves your walls. Pseudonymize the document before pasting it, and the leak is gone. Nothing to notify. Nothing to contain.
The cost of a leak
The fine is only the visible part. A leak also costs the hours spent patching the hole, the trust damaged with the client involved, and a reputation that takes months to rebuild after collapsing in a single afternoon. We put numbers on all of it in the cost of a data leak via AI.
Safe-Doc works upstream. It masks the identifying data before it ever reaches the AI, processes everything in the European Union, then purges without keeping a trace, which closes the gap instead of chasing a leak already gone. For the details, see the ChatGPT and GDPR at work guide.
The best incident is the one that never happens. Pseudonymize before the AI. Make it a habit, and the problem fades.