A salesperson shows you a slide with the word “Enterprise” in caps, a padlock and three certification logos. You conclude your data is covered and you sign. That’s the exact moment most European companies take on a legal risk they never assessed. Because “enterprise” is a marketing label, not a contract clause —and GDPR isn’t met with a badge, it’s met with an architecture.
Generative AI and GDPR: why the “enterprise” badge doesn’t protect you
GDPR applies from minute one, and it applies to you, not to your vendor. You’re the data controller: if you feed your customers’ or your team’s personal data into a generative AI tool, the law expects you to know where that data ends up, who processes it and under what guarantees. The vendor is, at best, your data processor —and only truly so if there’s a contract that says as much. The “enterprise” label describes a pricing tier; it doesn’t describe what happens to your data once it leaves your organization.
The distinction matters because the fines aren’t theoretical. Article 83 of the GDPR provides for penalties of up to €20 million or 4% of global annual turnover, whichever is higher, for the most serious infringements. Nobody fines you for using AI; you can be fined for processing personal data with no legal basis, no processing agreement, or by transferring it outside the European Economic Area without safeguards. A padlock on a slide doesn’t cover that risk.
What your vendor won’t tell you (and you don’t ask either)
It’s not that they lie. It’s that the uncomfortable questions don’t come up in the demo, and you don’t ask them either because the word “enterprise” has already put you at ease. These are the ones that go unanswered:
- Where is my data physically stored and processed? In the EU, or in the United States with “equivalent measures”?
- Does the vendor train its models on what I send it? On exactly which plan does it stop, and how do I verify that?
- How long does it retain my data, and who can read it during that time (including human reviewers checking for “abuse”)?
- What sub-processors sit underneath? An AI vendor rarely processes alone: there’s hosting, logging, monitoring, and each one is another company touching your data.
- Is there a signed data processing agreement (DPA), or just terms of service I can accept with a click?
Where your data lives matters more than which model it uses
The public conversation about AI revolves around the model: which one is smarter, which hallucinates less. For GDPR, the model is almost irrelevant. What matters is the geography and the chain of custody of the data. If your vendor processes on US servers, you’re in international-transfer territory: you need a legal basis (an adequacy decision, standard contractual clauses) and, after years of legal turbulence on this exact issue, you’d better have that basis documented, not assumed.
This is where architecture beats the label. Two tools with the same underlying model can have opposite risk profiles depending on where they host the data, whether they encrypt it in transit and at rest, and whether they let you pick a region. The question isn’t “is your product secure?” —they always say yes to that. The question is “where, exactly, is this specific data processed, and will you put it in writing?”.
“We don’t train on your data”: read the fine print
It’s the star line of every demo. And it’s usually true —with conditions—. Many vendors don’t train on your data on their paid enterprise plans, but they do on the free or individual plans your team uses on their own without you knowing. The data leak rarely comes from the corporate contract; it comes from the sales rep who pastes the customer list into the free version to “draft an email faster”. The contract’s “we don’t train on your data” doesn’t cover the personal account someone opened on Tuesday.
GDPR isn’t the AI Act (and both apply to you)
It’s worth not mixing them up. GDPR governs personal data and applies to you today, with no grace period, whether you use AI or not. The AI Act governs AI systems by their level of risk and arrives in phases: the transparency obligations (telling users they’re talking to an AI, labelling generated content) start applying in August 2026, while much of the obligations for use-based high-risk systems have been pushed back —per the provisional agreement of May 2026— to December 2027. Practical translation: don’t wait for the AI Act to get your data in order. GDPR already binds you, and it’s the one that brings the big fines.
Security is decided by your architecture, not by your vendor
This is the heart of it. You can buy the most “enterprise” tool on the market and still be non-compliant, because compliance isn’t only in the product you buy: it’s in how you build it. Which data you let in, which fields you anonymize first, who has access, what gets logged, what gets retained, where you draw the line between what the system does on its own and what goes through a person. That’s architecture, and it’s yours. The vendor sells you an engine; you build the car, and you’re the one who answers if it runs off the road.
That’s why the boring part —data governance— is what actually protects you. Knowing what sensitive information you hold, where it lives, who touches it and under which contract isn’t paperwork: it’s the difference between using AI with a safety net and using it blind. If you don’t have that map, building it is the first job, before picking a model. We treat it as what it is —infrastructure— in our data governance service: knowing what data you have, where it lives and who touches it, and we harden it with security designed for AI systems, not just the classic network.
What to ask before you sign
You don’t need to be a lawyer to avoid signing blind. Before feeding personal data into any generative AI tool, demand written answers to this:
- Processing and storage region: EU yes or no, and do you let me pick it?
- A signed DPA that meets Article 28, sub-processor list included.
- Training and retention policy: what you do with my data, how long you keep it, how I delete it.
- International transfers: if it leaves the EEA, on what legal basis and with what documented safeguards.
- Human access: who, on your side, can read my conversations and under what circumstances.
And in parallel, sort out your own side: a clear usage policy so your team knows what they can and can’t paste into a chat. We lay it out in detail in the guide on how to set up a ChatGPT usage policy for your company, inside the pillar guide on using ChatGPT in the company without theatre or nasty surprises. The most expensive tool won’t save you from a policy that doesn’t exist.