When can AI be used in compliance with the GDPR?
Timo Wevelsiep•Updated: 15.08.2026Editorial note: Versions, commands and prices may change. Please verify critical steps independently before production use. This guide does not replace individual consulting.
Introduce local AI with controllable data paths? The AI Cube Pro is preconfigured with a local model, Open WebUI, hardening, and documented base setup. Custom data sources and integrations are assessed separately. Explore the AI Cube Pro
“GDPR-compliant AI” is not a single product feature. Compliance follows from a specific purpose, an appropriate legal basis, constrained data paths, and operations that actually enforce the agreed rules. This guide translates those requirements into technical and organisational questions. It is not legal advice. As of August 2026.
Short answer: AI can be used in compliance with the GDPR when the actual processing has a legal basis and is implemented so that data paths, access, retention, deletion, and involved providers remain controlled. A local server can make that control easier, but it does not replace the assessment.
Seven questions before using AI
1. What is the purpose?
“We want to use AI” is not a sufficiently specific purpose. Describe the workflow, such as making internal policies searchable, drafting from approved templates, or sorting documents. Only then can required data, users, and retention be defined.
2. Which data enters the system?
Do not record prompts alone. Uploaded files, knowledge bases, embeddings, chat history, logs, feedback, backups, and output are part of the processing. Special-category data under Article 9 GDPR and professional secrets require a stricter assessment.
3. What is the legal basis?
The legal basis depends on purpose and the relationship to the data subjects. Legitimate interests, contract, consent, and legal obligation are not interchangeable. Employee data may also require employment-law analysis and works-council involvement.
4. Who has technical access?
Assess users, administrators, manufacturers, hosting providers, subprocessors, and support. A local model can reduce the number of recipients if the interface, database, logs, backup, and administration also remain within the defined boundary.
5. Which connections leave the environment?
Model and container downloads, updates, telemetry, web search, external OCR or speech services, cloud models, monitoring, remote support, and off-site backups create common outbound paths. “On-premises” does not automatically mean “offline”. An egress inventory and firewall rules make the actual operating mode auditable.
6. How are rights and deletion implemented?
At minimum, define user roles, least privilege, retention, deletion, and procedures for access and correction. RAG systems must enforce source permissions before retrieval. A statement in the system prompt is not access control.
7. How are operations evidenced?
Document versions, configuration, data flows, responsibility, changes, and incidents. Logs should be useful but data-minimised. Updates, backup, recovery, and model changes are part of privacy by design because an unmanaged system cannot retain its promised properties.
What local AI improves
Local AI can move model inference, chat data, and retrieval into a controlled environment. This can reduce external transfers and place network and administrative access under direct control. German professional secrecy obligations are explained in the § 203 guide.
It does not automatically determine whether a purpose is lawful, whether every field is required, or how staff and data subjects must be informed. Technology provides a controllable foundation; the organisation must configure it for the actual operation.
Data protection is also only one part of approval. Roles, transparency, human oversight, and other duties under the EU AI Act must be assessed separately for the actual system.
Comparing three operating models
| Model | Advantage | Examine closely |
|---|---|---|
| Cloud workspace | quick start, little own operation | provider, plan, region, subprocessors, retention, and enabled features |
| Dedicated European platform | controllable region and administration | contract, keys, support, exports, and operating responsibility |
| Local platform | tight technical boundary and direct control | internal rights, updates, egress, backup, remote support, and availability |
No model is compliant merely because of its label. The actual data path decides.
AI Cube Pro as a technical foundation
The AI Cube Pro provides a local AI platform with 128 GB unified memory, Open WebUI, a local model, base setup, hardening, and functional testing. Staff can create personal or shared knowledge spaces in Open WebUI. The system costs EUR 5,999 excluding VAT and is usually ready within two weeks after configuration approval.
Automated knowledge sources, professional-software connections, custom RAG pipelines, VPN or NetBird access, and individual retention workflows are scoped separately. This makes clear which controls belong to the platform and which depend on the actual processing operation.
GDPR checklist for AI in an organisation
- constrain purpose and desired outcome in writing;
- inventory data categories, sources, output, logs, and backups;
- assess legal basis and transparency duties;
- document providers, subprocessors, and international transfers;
- define user, group, and administrative rights;
- test deletion, retention, and data-subject procedures;
- constrain outbound connections and remote support;
- define quality criteria, failure cases, and human review;
- establish update, restore, and incident processes;
- assess whether a data protection impact assessment is required.
Sources
Rather have it operated?
You'd rather not run Local AI for Business yourself? WZ-IT handles setup, operations and maintenance - privacy-focused from Germany.
Enquiry
Assess local AI for your use case
Start with the AI Cube Pro or have us assess a custom AI platform, knowledge connection, or integration.
Frequently Asked Questions
Answers to the most important questions
No. Local processing can reduce external data paths and improve technical control. Purpose, legal basis, minimisation, access, deletion, transparency, and potentially a data protection impact assessment still need to be addressed.
It can when a legal basis exists for the specific purpose and all other data-protection duties are met. The assessment concerns the complete operation, including input, output, knowledge sources, logs, and service providers, not only the model.
No. A local server may still connect externally for updates, telemetry, web search, cloud models, remote support, or backups. Those data paths must be defined, constrained, and documented.
When processing is likely to result in a high risk to the rights and freedoms of natural persons. This must be assessed from the actual purpose, data categories, scale, and controls.
The AI Cube Pro can be configured for controlled local operation and provides a technical basis for constrained data paths. Compliance of an actual use depends on the use case and the organisation's technical and organisational measures.
More on Local AI for Business
- The open-source LLM stack
- What is LiteLLM?
- What is Langfuse?
- What is vLLM?
- vLLM vs. Ollama
- What is RAG?
- Connect Open WebUI to Nextcloud (RAG with ACLs)
- What is local AI?
- Cloud AI vs. self-hosted
- AI sovereignty for companies
- Which LLM to self-host?
- Sizing GPU & VRAM
- Inference vs. Training
- Qdrant vs. pgvector
- The EU AI Act for companies
- Local AI for confidentiality professions
- Processing documents with AI
- AI agents & automation
- RAG with permissions
- Chatbot or knowledge navigator?
- AI agents: permissions and approvals
- AI assistants and the works council
- GDPR-compliant AI: assessment criteria
- What does a local AI server cost?
- Size a local AI server by users
- LLM models on 128 GB unified memory
- RAG with Nextcloud, SharePoint, and DMS
- Provide secure remote access to local AI
- Connect AI Cubes with ConnectX-7
- Run Open WebUI as a production appliance
- Configure ASUS Ascent GX10 for business
- Configure NVIDIA DGX Spark for business
- Configure Acer Veriton GN100 for business
- Configure Dell Pro Max with GB10 for business
- Configure Gigabyte AI TOP ATOM for business
- Configure HP ZGX Nano G1n for business
- Configure Lenovo ThinkStation PGX for business
- Configure MSI EdgeXpert for business





