Nova
Log inGet started
AI and personal data

AI and GDPR at work the right habits, from regulator guidance

Updated October 5, 2026 · 5 min read

In brief

Using AI at work is compatible with GDPR, provided you know what you enter and where it goes. The basic rule, as the French data protection authority (CNIL) puts it: submit to an assistant only information you are authorized to share, and no personal or confidential data in a tool whose vendor may reuse the content. The company, for its part, chooses a suitable tool, writes the rules, and trains its teams.

What a regulator recommends: the CNIL’s guidance

GDPR is the same regulation across the European Union, and each country has its own data protection authority. France’s authority, the CNIL, published its answers on the use of generative AI systems on July 18, 2024. It does not ban these tools. It asks organizations to:

  • write the rules: an internal policy that states which uses are allowed and which are forbidden;
  • choose a suitable tool: check what the vendor does with the data entered, and turn off its reuse where possible;
  • train the users: on how the tool works, on its limits, on the rules;
  • involve the data protection officer (DPO) and, depending on the case, carry out a data protection impact assessment.

It points out that the organization is the one that is liable if its staff misuse AI. If you operate in another country, check the guidance of your own data protection authority: the European Data Protection Board lists them all.

What GDPR requires as soon as personal data is involved

Personal data is any information relating to an identified or identifiable person: a name, an email address, a résumé, a pay slip. Pasting it into an assistant means processing it under GDPR. The usual rules apply:

  • A purpose and a legal basis (Articles 5 and 6): know why you are processing this data, and on what grounds.
  • Data minimization (Article 5): provide only the data that is needed. Often, the task works just as well without the names.
  • Security and confidentiality (Articles 5 and 32).
  • A contract with the vendor when it processes data on your behalf (Article 28), and safeguards for transfers outside the European Union.
  • No fully automated decision about a person when it significantly affects them (Article 22).
  • Stronger protection for sensitive data (health, political opinions, trade union membership, and so on), whose processing is prohibited except in specific cases (Article 9).

The right habits, for every employee

  1. Use the tool and the account your company approves, not a personal account.
  2. Before you paste a text, remove the names, contact details, and amounts that the task does not need.
  3. Do not enter health data, disciplinary records, passwords, or confidential documents into a consumer tool.
  4. Set the privacy options on your account (table below).
  5. Review and check. The CNIL advises never reusing an answer as is.
  6. Do not let AI decide alone about a person: a hire, a disciplinary measure, a performance review.

What the assistants do with your data

ToolYour conversations, with a personal accountWith a business plan
ChatGPTThey can be used for training, unless you turn off “Improve the model for everyone.”Business, Enterprise, Edu: no training on your content by default.
ClaudeThey are used for training only if you agree.Team, Enterprise: no training on your content by default.
Microsoft CopilotKept for 18 months by default; they can be used for training, unless you opt out in the settings.Work account: your prompts, the responses, and your work data are not used to train the AI.
GeminiKept for 18 months by default, with possible review by people, unless you turn off “Keep Activity.”Google Workspace: content is not reviewed by people and not used for training without permission.

According to the vendors’ official pages, reviewed in early October 2026. Not being used for training is not enough to be compliant: the contract, the place of processing, and the access rights matter too.

For the company: six points to settle

  1. Take stock of how AI is really used, including through personal accounts.
  2. Choose a business plan and read the contract: the vendor’s role, the place of processing, the reuse of data.
  3. Write the policy: approved tools, off-limits data, cases where human approval is required.
  4. Involve your DPO, and carry out a data protection impact assessment when the processing presents a high risk to individuals (Article 35).
  5. Update your record of processing activities, if you keep one (Article 30).
  6. Train the teams, and do it again when the tools change.

For the most serious infringements, GDPR provides for fines of up to €20 million or 4% of worldwide annual turnover (Article 83). This page explains the rules and is not legal advice: for a specific situation, see your data protection officer or a lawyer.

What Nova brings

Nova is subscription software that trains your teams on AI, job by job. The guided use cases recall the precautions: which account to use, which data to remove, what to check. Each tool page says what the vendor does with your data, with its source and its check date. On the company side, you keep a catalog of approved tools. See the use cases for a data protection officer or an HR manager, among the 140 jobs on AI training by job.

In Nova, the company never sees one person’s activity or questions. Nova does not give legal advice. From €19 per month: see pricing or try the interactive demo.

Frequently asked questions

Can you put personal data into ChatGPT?

Not in a consumer personal account. The CNIL recommends submitting only information you are authorized to share. With a business plan, it is up to your organization to decide case by case, with its data protection officer.

Does GDPR forbid using AI at work?

No. It governs what you do with personal data, with AI as with any other tool. Rephrasing a general text involves no personal data; your company’s confidentiality rules still apply.

Do we need an AI usage policy?

The CNIL recommends one: an internal policy that clearly defines which uses are allowed and which are forbidden, along with training for users.

Do we need a data protection impact assessment (DPIA)?

It is mandatory when processing is likely to result in a high risk to individuals (Article 35 of GDPR). For generative AI, the CNIL recommends involving the DPO and, where appropriate, carrying one out.

Who is liable if an employee misuses AI?

The organization. The CNIL points out that the organization is the one that is liable when its staff misuse AI.

Sources

Go further

Get started

Create your workspace. Solo, or as a team.

Nova shows each person what AI can do in their job, guides them to the result, and keeps them up to date.

Interactive demo

€0

Free, no account needed. You try the real product yourself, as a preview: it is not a sales call.

Try the interactive demo

Solo

€19 per month

For one person: employee, freelancer, business owner. Or €190 per year.

Get started

Teams

from €129 per month

Team, Business, or Company, for up to 50 people. Beyond that, custom, quote on request.

See pricing

No commitment · Cancel anytime · Nova is subscription software, not an accredited training provider