Deployed worldwide
WZ-IT Logo

When can AI be used in compliance with the GDPR?

Timo WevelsiepTimo WevelsiepUpdated: 15.08.2026

Editorial note: Versions, commands and prices may change. Please verify critical steps independently before production use. This guide does not replace individual consulting.

Introduce local AI with controllable data paths? The AI Cube Pro is preconfigured with a local model, Open WebUI, hardening, and documented base setup. Custom data sources and integrations are assessed separately. Explore the AI Cube Pro

“GDPR-compliant AI” is not a single product feature. Compliance follows from a specific purpose, an appropriate legal basis, constrained data paths, and operations that actually enforce the agreed rules. This guide translates those requirements into technical and organisational questions. It is not legal advice. As of August 2026.

Short answer: AI can be used in compliance with the GDPR when the actual processing has a legal basis and is implemented so that data paths, access, retention, deletion, and involved providers remain controlled. A local server can make that control easier, but it does not replace the assessment.

Seven questions before using AI

1. What is the purpose?

“We want to use AI” is not a sufficiently specific purpose. Describe the workflow, such as making internal policies searchable, drafting from approved templates, or sorting documents. Only then can required data, users, and retention be defined.

2. Which data enters the system?

Do not record prompts alone. Uploaded files, knowledge bases, embeddings, chat history, logs, feedback, backups, and output are part of the processing. Special-category data under Article 9 GDPR and professional secrets require a stricter assessment.

The legal basis depends on purpose and the relationship to the data subjects. Legitimate interests, contract, consent, and legal obligation are not interchangeable. Employee data may also require employment-law analysis and works-council involvement.

4. Who has technical access?

Assess users, administrators, manufacturers, hosting providers, subprocessors, and support. A local model can reduce the number of recipients if the interface, database, logs, backup, and administration also remain within the defined boundary.

5. Which connections leave the environment?

Model and container downloads, updates, telemetry, web search, external OCR or speech services, cloud models, monitoring, remote support, and off-site backups create common outbound paths. “On-premises” does not automatically mean “offline”. An egress inventory and firewall rules make the actual operating mode auditable.

6. How are rights and deletion implemented?

At minimum, define user roles, least privilege, retention, deletion, and procedures for access and correction. RAG systems must enforce source permissions before retrieval. A statement in the system prompt is not access control.

7. How are operations evidenced?

Document versions, configuration, data flows, responsibility, changes, and incidents. Logs should be useful but data-minimised. Updates, backup, recovery, and model changes are part of privacy by design because an unmanaged system cannot retain its promised properties.

What local AI improves

Local AI can move model inference, chat data, and retrieval into a controlled environment. This can reduce external transfers and place network and administrative access under direct control. German professional secrecy obligations are explained in the § 203 guide.

It does not automatically determine whether a purpose is lawful, whether every field is required, or how staff and data subjects must be informed. Technology provides a controllable foundation; the organisation must configure it for the actual operation.

Data protection is also only one part of approval. Roles, transparency, human oversight, and other duties under the EU AI Act must be assessed separately for the actual system.

Comparing three operating models

Model Advantage Examine closely
Cloud workspace quick start, little own operation provider, plan, region, subprocessors, retention, and enabled features
Dedicated European platform controllable region and administration contract, keys, support, exports, and operating responsibility
Local platform tight technical boundary and direct control internal rights, updates, egress, backup, remote support, and availability

No model is compliant merely because of its label. The actual data path decides.

AI Cube Pro as a technical foundation

The AI Cube Pro provides a local AI platform with 128 GB unified memory, Open WebUI, a local model, base setup, hardening, and functional testing. Staff can create personal or shared knowledge spaces in Open WebUI. The system costs EUR 5,999 excluding VAT and is usually ready within two weeks after configuration approval.

Automated knowledge sources, professional-software connections, custom RAG pipelines, VPN or NetBird access, and individual retention workflows are scoped separately. This makes clear which controls belong to the platform and which depend on the actual processing operation.

GDPR checklist for AI in an organisation

  • constrain purpose and desired outcome in writing;
  • inventory data categories, sources, output, logs, and backups;
  • assess legal basis and transparency duties;
  • document providers, subprocessors, and international transfers;
  • define user, group, and administrative rights;
  • test deletion, retention, and data-subject procedures;
  • constrain outbound connections and remote support;
  • define quality criteria, failure cases, and human review;
  • establish update, restore, and incident processes;
  • assess whether a data protection impact assessment is required.

Sources

Rather have it operated?

You'd rather not run Local AI for Business yourself? WZ-IT handles setup, operations and maintenance - privacy-focused from Germany.

Enquiry

Assess local AI for your use case

Start with the AI Cube Pro or have us assess a custom AI platform, knowledge connection, or integration.

How should we get back to you?

Frequently Asked Questions

Answers to the most important questions

No. Local processing can reduce external data paths and improve technical control. Purpose, legal basis, minimisation, access, deletion, transparency, and potentially a data protection impact assessment still need to be addressed.

It can when a legal basis exists for the specific purpose and all other data-protection duties are met. The assessment concerns the complete operation, including input, output, knowledge sources, logs, and service providers, not only the model.

No. A local server may still connect externally for updates, telemetry, web search, cloud models, remote support, or backups. Those data paths must be defined, constrained, and documented.

When processing is likely to result in a high risk to the rights and freedoms of natural persons. This must be assessed from the actual purpose, data categories, scale, and controls.

The AI Cube Pro can be configured for controlled local operation and provides a technical basis for constrained data paths. Compliance of an actual use depends on the use case and the organisation's technical and organisational measures.

Contact

Let's Talk About Your Idea

Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.

Email
[email protected]
Arrange a callback

Callback

Arrange a callback

Leave your number and we will call back — at the latest on the next business day.

For a longer conversation you can book an appointment instead.

Companies worldwide trust WZ-IT

  • ml&s
  • Rekorder
  • Keymate
  • Führerscheinmacher
  • SolidProof
  • ARGE
  • Boese VA
  • nextGYM
  • Maho Management
  • Golem.de
  • Millenium
  • Paritel
  • Yonju
  • EVADXB
  • Mr. Clipart
  • Aphy AG
  • Negosh
  • ABCO Water Systems
1/2 - Topic Selection50%

What is your inquiry about?

Select one or more areas where we can support you.