Blog · Compliance & AI · · 1 min read

Checklist: using AI without breaking the GDPR

AI on your work documents? Nothing forbidden there. It has even become routine. The real danger is not the tool itself, it is feeding it a raw file, with no filter at all, while assuming that no one will ever look at what sits inside. So here is a concrete checklist, built to keep you on the right side of the GDPR at every stage, before, during and after sending to the AI.

The checklist

  • Spot the documents at risk. Any file with names, addresses, IBAN, health or financial data.
  • Pseudonymize before the AI. Not just the name: dates, identifiers and amounts matter too.
  • Keep the key on your side. The mapping stays encrypted, separate from the document.
  • Review the masked document. Detection is never 100% perfect, a human check is still useful.
  • Handle scans too. An image holds text: OCR then mask, otherwise the leak goes through it.
  • Pick the right plan. DPA, rétention, region: match the subscription to professional use.
  • Re-identify locally. Restore the real values on your machine, never re-upload the key.
  • Train the teams. Without a simple alternative, AI usage continues in the shadows.

A checklist does not do everything. It will never replace a real internal policy, written down and shared across the team, yet it is enough to head off the most ordinary mistakes, the ones that cost dearly precisely because they look so harmless in the moment. The rule? Always the same. Never show the AI what identifies a person.

Safe-Doc handles the technical side of this checklist, end to end: detection of sensitive data, masking, layout kept exactly as it was, processing carried out in the European Union then purged, re-identification done locally. The rest is on your own processes. To go further, see the ChatGPT and GDPR at work guide.

Whole list checked, one single tool. Pseudonymize your documents before any send to the AI.

Part of the guide : Compliance & GDPR ↗