Which AI is GDPR compliant? An Irish guide
· Updated · Written and maintained by Joaquín Trapero, Nonimo
None of them, and that answer is more useful than any list would be. The GDPR regulates processing, not products. There is no register of approved tools, no Irish certification scheme for them, and no statement from the Data Protection Commission that any assistant on the market is or is not lawful to use.
What the law asks about is your use of the thing. Who is the controller, what contract you hold, whether the provider trains on your text, where the data goes, how long it is kept, who can read it, and what you typed in the first place. Only the last of those is entirely yours, and it is the one most firms never write down.
This guide takes those questions in turn and answers them for ChatGPT, Claude, Gemini and Copilot, from each company’s own documents and from the DPC’s own words. It is not a ranking, and it does not end with a recommendation to buy anything. Two of the four providers sit on a European Commission list that the other two do not, and that difference changes your paperwork rather than your safety.
Why no AI tool is compliant on its own
Compliance is a property of an organisation and of a processing operation, not of a piece of software. The same product can be lawful in one office and unlawful in the next, with identical settings, because the two offices put different documents into it under different contracts.
That is the structure of the Regulation, not a technicality invented to sell something. The obligations in Articles 5, 6, 24, 28, 30, 32 and 35 attach to the controller, which in this scenario is your firm, not to the supplier of the tool.
The two things a supplier can promise, and the rest, which is yours
One is what it will do with your data once it has it, and the other is what it will sign. Training, retention, access, location and subprocessors live in the first. The processing agreement and its schedules live in the second.
Everything else is yours, and a vendor page cannot carry any of it.
| The supplier decides | You decide |
|---|---|
| Whether it trains on your content | Whether you have a lawful basis |
| Where it processes and stores | Whether the transfer is documented |
| How long it retains | Which account your staff sign in with |
| Who inside the company can read | What goes in, and what never does |
| Which subprocessors it uses | Whether you can answer an access request |
| What contract it will sign | Whether you wrote any of it down |
That split is why a page listing approved tools would be dishonest even if somebody published one. Not one row on the right changes with the product you buy, and the rule that governs the last of them is the single page our AI policy template is written to produce.
What the DPC tells you to check before you start
The Data Protection Commission put this in a single sentence in its guidance of 18 July 2024, and it is the most useful sentence written by an Irish regulator on the subject.
Data Protection Commission, AI, Large Language Models and Data Protection, 18 July 2024
Before you start using an AI system, you should first understand what personal data it uses, how it uses it, where the personal data goes in situations where a third-party is involved in the processing, whether it is retained by the provider of the AI product or re-used in any way, and how the product allows you to meet your GDPR obligations.
Read the last clause again. The DPC does not ask whether the product is compliant. It asks whether the product lets you comply, which is a different question with a different answer for every firm. The same guidance adds that the provider’s documentation should tell you all of this in an understandable and accessible form, which is a quiet standard to hold a vendor to.
The seven criteria that decide whether your use is lawful
The DPC’s sentence unpacks into seven checks. They are the spine of this guide and of the tables below, and each has an article of the Regulation behind it rather than an opinion.
| Criterion | Where it comes from | Where you find the answer |
|---|---|---|
| Who is controller, who is processor | Articles 4(7), 4(8), 28 | The terms that apply to your plan |
| A written processing contract | Article 28(3) | The provider’s DPA or addendum |
| Whether the provider trains on your text | Articles 5(1)(b), 6 | The privacy policy and plan terms |
| Where the data is processed and stored | Articles 44 to 49 | Residency pages and subprocessor lists |
| How long it is kept | Article 5(1)(e) | The retention schedule, not the FAQ |
| Who inside the provider can read it | Article 32 | The enterprise privacy page |
| What your staff put in | Article 5(1)(c) | Nobody but you |
Six of those seven are answered by reading. The seventh is answered by writing a rule and collecting acknowledgements, and it is the only one where no amount of vendor diligence helps.
Controller, processor and the contract in between
On a consumer account you are usually not in a processor relationship at all. The provider is a controller in its own right, deciding purposes of its own, and you have no contract that limits them beyond the consumer terms everybody clicks.
On a business or enterprise plan the shape changes. The provider takes the role of processor for your content, your organisation is the controller, and a written contract under Article 28(3) sets out the subject matter, duration, nature and purpose, the types of data, the categories of data subject, and the provider’s obligations. That is the single biggest difference in this guide, and it is a procurement decision rather than a settings decision.
Training, and why it is a separate question from sending
There are two distinct events when someone puts a client letter into an assistant, and only one of them has a switch. The first is disclosure: the text leaves your office and arrives at a company outside it, the moment the request is sent. The second is use of that text for model training, which the provider decides afterwards about text it already holds.
Turning training off removes the second. It does not reverse the first, shorten retention, or stop an administrator reading the conversation. Our guide to whether that first event is a breach works through the test and the first hour, because the answer matters inside 72 hours rather than at leisure.
Location, retention, access and what you typed
The remaining four are matters of record keeping more than of engineering. You need to be able to say where the data goes, under which transfer tool, for how long it is held, and who at the provider can see it. The answers exist in published documents for all four products, which is more than can be said for a good deal of business software. They also fill the brackets in the data paragraph of an engagement letter.
The seventh is the only one where the tool is irrelevant. A document that should never have left the office is a problem on every plan, under every contract, in every jurisdiction.
Who answers for these four tools in Ireland
On this point Ireland is genuinely different from the rest of Europe, and it is worth checking rather than assuming. All four providers have put an Irish company between the European user and the parent.
| Product | Controller for the EEA | Registered in | Names the DPC as lead? |
|---|---|---|---|
| ChatGPT | OpenAI Ireland Limited | Sheriff Street Upper, Dublin 1 | Yes, in writing |
| Claude | Anthropic Ireland, Limited | Barrow Street, Dublin 4 | No, points to your local authority |
| Gemini | Google Ireland Limited | Provider for the EEA and Switzerland | Not in the Gemini notice |
| Copilot | Microsoft Ireland Operations Limited | Leopardstown, Dublin 18 | Not in the Privacy Statement |
Sources: each company’s own privacy documentation, consulted 19 and 20 September 2026.
Only one of the four says it in writing
OpenAI’s Europe privacy policy of 24 August 2026 names the Data Protection Commission as its lead supervisory authority in terms. The other three do not, in the documents a user reads, and the difference is worth keeping straight when you tell a client where a complaint would go.
The practical position is that the one-stop-shop mechanism of Article 56 is the normal route for a company whose main establishment is in Ireland, and the DPC has described itself in those terms in its own published statements, quoted later on this page. What you can accurately tell a client is that you would raise it with the DPC and ask, not that Dublin formally decides for every one of the four.
What the one-stop-shop actually gets you
Less than people assume, and more than nothing. It means one authority runs the cross-border inquiry rather than 27, which is why Irish decisions about global products carry weight far beyond Ireland.
It does not mean the DPC has reviewed these products, and it does not give you a defence. Your obligations as controller are unaffected by who supervises your supplier, a point the same regulator makes at every opportunity.
It is also worth knowing the size of the office on the other end. In 2025 the Commission took in 16,160 new cases from individuals, a rise of 45 per cent, concluded 11,734 of them, and received 6,521 valid breach notifications.
None of that caseload is about artificial intelligence, and that is the point of quoting it. The authority that would look at your use of an assistant is an office with a queue, and the great majority of what lands on its desk arrives as a complaint from one individual rather than as a thematic review.
The four assistants, criterion by criterion
What follows is two short paragraphs for each, against the seven checks, with the detail in the guide behind each name. The purpose here is comparison rather than depth, and the four guides exist so that this page does not have to repeat them.
ChatGPT
OpenAI Ireland Limited is controller for the EEA. A Data Processing Addendum is available for ChatGPT Business, Enterprise and the API, and business content is not used for training by default. On consumer plans it trains until you turn it off, and deleted data leaves OpenAI’s systems within thirty days with named exceptions.
European data residency exists only for eligible API customers and new Enterprise or Edu workspaces, so no consumer plan qualifies. On Business, workspace admins can view, export and delete conversations, and named outside contractors review content for abuse. The detail, including what the training switch leaves untouched, is in our ChatGPT guide.
Claude
Anthropic Ireland, Limited is controller for the EEA. The commercial terms say Anthropic may not train models on Customer Content, which is a promise about use rather than about receipt, retention or disclosure. Consumer accounts train unless you opt out, under the privacy policy of 10 September 2026.
Traffic can be routed to selected regions, and Anthropic’s own help article adds the sentence its competitors have no equivalent for: data is stored in the United States. Retention runs on more than one clock, the longest of which is seven years for trust and safety scores, and our Claude guide sets out all of them.
Gemini
Google Ireland Limited is the provider for the EEA and Switzerland. On personal accounts, turning Keep Activity off does not stop Google using chats to respond and to protect the service. Trained reviewers read a sample, and reviewed conversations are kept for up to three years and are not removed when you delete your activity.
On Workspace the picture is a processor commitment under the Cloud Data Processing Addendum, qualified by the words “outside your domain”. Data regions are an edition feature rather than a setting, and Gemini Notebook sits outside them. Our Gemini guide quotes the human review sentence in full rather than summarising it.
Copilot
Microsoft Ireland Operations Limited is controller for consumer use, and Microsoft is processor under the Data Protection Addendum for work accounts. Microsoft states plainly that prompts, responses and Graph data are not used to train foundation models, and it repeats that commitment across the commercial products.
The gap is elsewhere. Generated web search queries leave both the Data Protection Addendum and the EU Data Boundary, and models provided by Anthropic as a subprocessor are, in Microsoft’s own words, currently excluded from that boundary. Our Copilot guide works out which of the four Copilot products you are actually in.
Free accounts and business accounts: where everything changes
If there is one decision on this page that changes more than any other, it is which account a member of staff signs in with. It decides which contract governs the text, which is upstream of every other question here.
| What changes | Consumer account | Business or enterprise plan |
|---|---|---|
| The provider’s role | Controller in its own right | Processor for your content |
| Article 28 contract | Not generally available | Published and signable |
| Training on your text | On by default in three of the four | Off by default across the four |
| Admin visibility | None, it is a personal account | Admins can view, export, delete |
| Audit and retention controls | Minimal | Available, and configurable |
| What a client can be told | Little that is verifiable | The contract, by name |
Sources: the four providers’ consumer and enterprise privacy documentation, consulted 19 and 20 September 2026.
The Law Society of Ireland reached the same place from the professional duty side. Its generative AI guidance of December 2025 says that by default, free and paid consumer versions of GenAI systems are not suitable for securely handling personal data or client confidential data, and it names Copilot, ChatGPT, Claude and Gemini while saying it.
The same guidance carries a warning in the other direction, and it is the sentence to remember on a procurement call: solicitors “should never assume that using an enterprise-grade tool guarantees compliance”. Buying the higher tier answers the contract question. It does not answer the other six. For a firm of solicitors the last of them is what the pasted affidavit carries, and an Irish solicitor can act on that before anything is sent.
That is also the moment the cost question arrives, because moving a whole office onto business plans is a real line in a budget and the saving of not doing it is illusory. A consumer account with no contract behind it is the thing your insurer asks about, as our guide to the AI questions on cyber proposal forms sets out.
The processing agreement: what to look for in each one
Article 28(3) tells you what a processor contract must contain, so reading one is a checklist exercise rather than a legal opinion. All four providers publish theirs, and all four scope it to the business products rather than to the consumer app.
| Product | The document | Covers | Training on that content |
|---|---|---|---|
| ChatGPT | Data Processing Addendum | Business, Enterprise, the API | Not by default |
| Claude | Anthropic DPA, with the commercial terms | Commercial plans | “May not train models on Customer Content” |
| Gemini | Cloud Data Processing Addendum | Workspace editions, or bought separately | Not outside your domain |
| Copilot | Microsoft Data Protection Addendum | Work and school accounts | Not for foundation models |
Sources: each provider’s published contractual documentation, consulted 19 and 20 September 2026.
The column that matters most on that table is the third. A processing agreement you have not signed, for a plan you are not on, protects nobody, and the commonest failure in a small Irish office is a firm that has read the enterprise documentation and is using the consumer app. What each of these documents says, product by product, is set out in our other guides.
The three clauses worth reading before you sign
- Purpose limitation. The contract should say the processor acts only on documented instructions, and nothing in the surrounding terms should quietly restore a use of its own. A promise not to train is worth reading against the retention and abuse monitoring clauses in the same document.
- Subprocessors. You need the list, the locations and the notice period for changes. Microsoft’s own documentation is the reason this matters: it discloses a model provider from another company inside Copilot whose processing sits outside the EU Data Boundary, and that disclosure is only useful if somebody reads it.
- Assistance and audit. Article 28(3)(h) does not require the processor to demonstrate your compliance. It requires it to make available the information necessary for you to demonstrate it, and to allow audits. Those are different obligations, and the second is the one that gets negotiated away.
Five questions get you through a supplier call without a lawyer in the room, and every one of them has a documentary answer.
| The question | What a usable answer looks like |
|---|---|
| Which plans does your addendum cover | Named plans, not “our business products” |
| Where is the current subprocessor list | A URL, with a change notification period |
| What is your transfer tool for the United States | A certification, or the clauses and their version |
| What is the retention period, and what survives deletion | Two numbers, not one |
| Who inside your company can read our content | A role and a purpose, not a reassurance |
The answers belong in a file with the date you got them. Every document cited in this guide carries a date, and several of them changed during 2026 alone.
The exception that is easiest to miss
An exception of this kind is not a scandal, and every large contract has them. What matters is whether you know where yours are before a client asks.
The clearest published example among these four is Microsoft’s: the Data Protection Addendum does not apply to generated web search queries, and neither does the EU Data Boundary, with Microsoft acting as controller for those queries under the Product Terms. That is a documented boundary of a contract, written down by the provider, and it belongs in your record rather than in a surprise.
Transfers to the United States, and the list that decides
This is where the four products genuinely separate, and it is the part that almost every comparison article gets wrong by treating the EU-US Data Privacy Framework as something a company either broadly supports or does not.
The adequacy decision is narrower than that. Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 says, in Article 1, that the United States ensures an adequate level of protection for personal data transferred from the Union to organisations in the United States that are included in the Data Privacy Framework List maintained by the US Department of Commerce.
So the question to ask is whether the provider’s US entity is on the list. We checked all four on 20 September 2026 against the Department of Commerce register, in both the active and the inactive views, and confirmed with a control search that the instrument returns results when there is something to return.
| Provider | On the DPF List, 20 Sep 2026 | Stated transfer tool | What goes in your record |
|---|---|---|---|
| Google LLC | Yes, active, all three frameworks | Adequacy where it applies | The certification, and its scope |
| Microsoft Corporation | Yes, recertification under review | Adequacy where it applies | The certification and the review status |
| OpenAI | Not listed, active or inactive | Adequacy decisions, and SCCs | The SCCs and your transfer assessment |
| Anthropic | Not listed, active or inactive | Adequacy decisions, and SCCs | The SCCs and your transfer assessment |
Source: Data Privacy Framework List, US Department of Commerce, searched 20 September 2026 in both the active and inactive registers.
The register held 3,664 participants that day. Two of these four providers were on it and two were not, which splits the group down the middle on the one criterion where a search takes thirty seconds and an assumption takes years to surface.
What this does not mean
It does not mean OpenAI and Anthropic transfer data unlawfully. Standard contractual clauses under Article 46(2)(c) are a valid transfer tool and both companies say in their own policies that they use them. OpenAI’s Europe privacy policy of 24 August 2026 relies on adequacy decisions where they apply and on the clauses for other jurisdictions, and Anthropic’s policy of 10 September 2026 says the same in different words.
What it does mean is that your paperwork differs. A transfer under adequacy is documented by pointing at the certification. A transfer under standard contractual clauses carries an assessment of the destination country’s law and, where needed, supplementary measures, and it is your assessment rather than the provider’s.
The assessment nobody has done
In most Irish firms of the size this guide is written for, the transfer record either does not exist or says the word “cloud” and stops. That is the gap a client’s data protection officer finds in ten minutes, and it is cheaper to close than to explain.
The document you want is short: who the importer is, what categories go, on which transfer tool, what you assessed, and when you last looked. Where each assistant sends the data is set out in our other guides, and the record can be filled in from them.
How long each of them may keep it
Retention is where published answers are most specific and where summaries are most misleading, because every provider has a headline number and at least one longer one behind it.
| Product | Deleted content | The longer clock | What deletion does not reach |
|---|---|---|---|
| ChatGPT | Within 30 days | Legal holds, banned accounts, financial records | Content already stripped of identifiers for training |
| Claude | 30 days from backend storage | Up to 5 years in training pipelines, 7 for safety scores | Flagged conversations, on their own clock |
| Gemini | With your activity | Up to 3 years for reviewed conversations | Anything a human reviewer has read |
| Copilot | Per tenant configuration | 18 months in the personal app of 18 August 2026 | Web search queries, outside the addendum |
Sources: each provider’s retention documentation, consulted 19 September 2026 and cited in full in the four product guides.
The spread runs from 30 days at one end to 7 years at the other, with 18 months sitting in the middle as the default in the personal Copilot app. A firm quoting the headline figure to a client is quoting the shortest of several numbers.
Deletion is a request, not a switch
All four work the same way: the provider has already received the document, and your deletion runs against a clock that other parties can stop. That is not sinister and every large provider does it, but it changes what you can accurately tell a client.
The answer a client deserves is the longest applicable number rather than the shortest published one. Deciding which number applies to a given conversation means reading the retention schedule rather than the marketing page, and our Claude guide has the clearest worked example, because Anthropic publishes four clocks and says that one conversation can sit in more than one of them.
What the DPC has said about generative AI, and what it has not
The Irish regulator has been more active on this subject than its public profile suggests, and none of what it has said amounts to approving or condemning a product.
The guidance of July 2024
The AI, LLMs and Data Protection blog of 18 July 2024 is the closest thing to an Irish checklist, and it is short enough to read in a coffee break.
Besides the sentence quoted at the top of this guide, it lists risks that map onto the criteria above: unwanted processing of inputs, the difficulty of answering an access or erasure request once data is inside a system, memorisation causing training data to be regurgitated, filters that can be circumvented, the risk of automated decisions where outputs are used without human analysis, and storage limitation failures where no retention schedule exists.
None of that is specific to a vendor, which is the point. It is a list of things a controller must be able to answer, and it is the closest an Irish organisation gets to an official structure for this decision.
The opinion Dublin asked Europe for
Data protection authorities across Europe now work from it when they assess an AI model, and Ireland’s request for it came out of a court case.
On 8 August 2024 the DPC brought urgent proceedings in the Irish High Court over X’s processing of its EU and EEA users’ public posts to train Grok. It was the first time the office had taken such an action as lead supervisory authority, using section 134 of the Data Protection Act 2018.
The proceedings were struck out on 4 September 2024, when X agreed to make its undertaking permanent. The DPC asked the Board for its Article 64(2) opinion the same day, and the Board announced the result on 18 December 2024.
The opinion covers three things: when an AI model can be considered anonymous, whether legitimate interest can be a basis for developing or deploying one, and what happens if a model was built with unlawfully processed personal data.
On anonymity it sets a demanding bar. It must be very unlikely both that individuals can be identified directly or indirectly from the model, and that their personal data can be extracted from it through queries. On the third question it says that unlawful development can affect the lawfulness of deployment, unless the model has been duly anonymised.
| When | What the DPC did |
|---|---|
| 8 August 2024 | Urgent High Court proceedings over Grok training data, a first for the office |
| 4 September 2024 | Proceedings struck out, and the Article 64(2) request sent to the Board |
| 12 September 2024 | Statutory inquiry opened into Google Ireland over the PaLM 2 assessment |
| 7 November 2025 | Statement on LinkedIn AI training, after five changes were secured |
| 17 February 2026 | Statutory inquiry opened into X over images generated with Grok |
Source: Data Protection Commission press releases and statements, as cited below.
Two inquiries, and the articles the DPC named
Both are open under section 110 of the Data Protection Act 2018, both touch generative AI, and both are worth knowing about because of which articles they name.
- Google Ireland Limited, opened 12 September 2024. A cross-border inquiry into whether a data protection impact assessment was required before developing the PaLM 2 foundational model. There was no published decision as at 20 September 2026.
- X Internet Unlimited Company, opened 17 February 2026. An inquiry on a large scale into the creation and publication of sexualised images made without consent, using the generative AI functionality associated with the Grok model, examining compliance with Article 5, Article 6, Article 25 and Article 35.
That list of four articles is the most useful thing on this page for a firm that wants to know what the regulator actually measures. Principles, lawful basis, data protection by design, and the impact assessment. It is the same spine as the criteria above, written by the authority rather than by a vendor.
Neither inquiry is a finding, and writing about them as though they were is the mistake that gets a vendor page quoted back at it. An open inquiry is a question, and both of these are questions about how a model was built rather than about how you use one.
They belong here for the vocabulary. These are the articles Dublin reaches for, and they are the same ones our guide to the public sector side works through for bodies carrying a statutory duty on top.
The sentence that answers the title of this guide
In November 2025 the DPC published a statement about LinkedIn’s plan to train generative AI models on the personal data of its EU and EEA members. The office had reviewed the documentation, raised concerns and secured five categories of change, from better transparency notices to filters that keep trade union content out of the training set, plus a report due within five months of the processing starting.
Then it wrote the sentence that should end every conversation about compliant AI tools, in its statement on LinkedIn AI training of 7 November 2025.
The DPC has not approved, or found compliant, LinkedIn’s use of users’ personal data for generative AI model training.
That is the Irish regulator, having spent months on a single product with the company’s full cooperation, declining to certify it. No vendor page can offer you what the DPC has declined to give, and any page that does is describing something the regulator has not said.
The same statement describes the office as “the Lead Supervisory Authority for many large global technology companies with their main establishment in Ireland”, which is the clearest published support for the point made earlier about where a complaint goes.
What the regulator actually fined in 2026
Enforcement in Ireland this year has been about where records sit and how long they are kept rather than about chatbots, and that is the same question in older clothing. The Commission fined the Health Service Executive €645,000 on 2 September 2026, with a reprimand and corrective orders alongside it.
The HSE decision followed two breach notifications in late 2023, an inquiry opened in May 2024 and twelve site inspections nationwide, and it turned on the physical conditions of storage facilities and the integrity of the documents in them. An AI tool is a storage facility with a contract attached. The questions the DPC asked there are the questions it would ask about a chat history.
What should never go in, even on a business account
A signed processing agreement changes who is accountable for what. It does not make a disclosure appropriate, and it does not satisfy Article 5(1)(c), which asks that personal data be adequate, relevant and limited to what is necessary for the purpose. Applied to an employment or legal file, that test often lets the sensitive fact through and almost never the employee’s name beside it.
| What goes in | Why it is different | What the Irish frame adds |
|---|---|---|
| Whole client files, to summarise one point | Everything else in the file is unnecessary | Minimisation applies per purpose, not per session |
| Special category data | Article 9 needs a condition of its own | The DPC’s DPIA list treats it at scale as high risk |
| Other people’s identifiers, PPS numbers included | The person never chose your supplier | A State identifier, and the question rarely needs it |
| Privileged material | The duty is separate from data protection | The Law Society warns privilege can be lost by intentional release |
| Another person’s correspondence | You are not that person’s controller for this | Their reasonable expectations were formed elsewhere |
Sources: GDPR Articles 5 and 9; Data Protection Commission Article 35(4) list; Law Society of Ireland generative AI guidance, December 2025.
The practical rule is smaller than the table suggests. Ask what the assistant actually needs to do the job, send that, and keep the rest in the file. A question about a clause needs the clause, not the parties. A summary of a medical report needs the findings, not the name and the date of birth above them. In a GP practice the same rule governs what comes out of a referral letter first.
This is also the one place on this page where a tool can help with the mechanics rather than the judgment, and where our guide to the breach question is worth reading before rather than after.
How to document it: the record, the policy and the assessment
Three documents carry this, and none of them is long. Firms rarely go wrong on the drafting; they go wrong because nobody is responsible for them. The middle one is the only one that has to be written from scratch, and our AI policy template is a model of it that a firm can adopt and sign.
| Document | Where it comes from | What it has to say here |
|---|---|---|
| Record of processing | Article 30 | The tool, its purpose, the categories, the retention, the transfer tool |
| Internal AI rule | Article 24, and good sense | Which accounts, which documents never, who to tell if it goes wrong |
| Impact assessment | Article 35, and the DPC’s own list | The risk, the mitigations, and the residual risk you accepted |
The Article 30 line most firms are missing
A record of processing that lists your case management system and your accounts package, and does not list the assistant your staff use every day, is a record that describes a firm that no longer exists. Adding the row takes an afternoon.
The row needs a transfer column, and this is where the check in the previous section pays for itself. Two of these four providers are documented by naming a certification, and two by naming standard contractual clauses and the assessment you carried out. Writing “cloud” in that cell is what a visiting data protection officer looks for first.
When the DPC’s own list makes an assessment mandatory
Beyond the three mandatory cases in Article 35(3), the DPC has adopted a national list under Article 35(4). It names ten processing types for which an assessment becomes mandatory where a documented screening or preliminary risk assessment indicates likely high risk.
Four of the ten are the ones a firm adopting an assistant should read closely.
| The listed item | Why it bites here |
|---|---|
| Personal data used on a large scale for a purpose other than the one it was collected for | Existing client files put into a new tool, under Article 6(4) |
| Profiling or algorithmic means used to determine access to services or with significant effects | Triage, scoring or eligibility decisions taken with model output |
| Combining or linking separate datasets where that contributes to profiling | Connectors that join a mailbox, a drive and a case system |
| Processing on a large scale where the Data Protection Act 2018 requires suitable and specific measures | Special category and criminal offence data under the Irish Act |
Source: Data Protection Commission, List of Types of Data Processing Operations which require a Data Protection Impact Assessment, Article 35(4) GDPR.
The word doing the work is “documented”. The screening that decides you do not need an assessment is itself a record, and the list’s own factors put “uses of new or novel technologies” first among the things that make high risk likely. A firm that decided it did not need one, and wrote down why, is in a far better position than one that never asked.
The AI Act is a different law, and it stacks on top
Nothing in this guide is affected by the EU AI Act, and nothing in the AI Act replaces any of it. They are separate instruments with separate regulators, separate definitions and separate penalties, and a firm using an assistant at work generally has duties under both.
Put simply, the GDPR asks about personal data, and the AI Act asks about the system, its risk class and what you tell the people in front of it.
For Ireland, the deployer duties, the dates after the July 2026 omnibus and the question of which Irish body enforces what are set out in our guide to the AI Act in Ireland, and the extraterritorial question in our guide on whether it applies outside the EU. This page does not repeat either of them.
| The question | Under the GDPR | Under the AI Act |
|---|---|---|
| Who is it about | Identified or identifiable people | The system and its risk class |
| Who enforces it in Ireland | The Data Protection Commission | Fourteen sectoral bodies, coordinated by Oifig IS na hÉireann |
| What you owe before you start | Lawful basis, contract, record, assessment | Literacy, transparency, duties that depend on the risk class |
| Does compliance with one satisfy the other | No | No |
What no tool fixes on its own, including ours
Software of this category masks identifiers in text before it is sent, and that is not compliance, which is a property of an organisation rather than of a product. Ours performs pseudonymisation: the mapping back to the person is kept, encrypted, on the machine, and Article 4(5) is explicit that pseudonymised data remains personal data, so every one of the seven criteria above still applies.
It is a Mac and Windows app. A payment card with a valid check digit is cleaned silently before the text is sent, while a matched PPS number is shown to you rather than removed, and who is entitled to use one is set out in statute.
Among the seven criteria, it fits exactly one: what your staff put in. What the app keeps is on our security page. Moving everyone to a business account, signing the addendum, adding a row to the record and writing one page of rules is a complete and legitimate answer, and it costs an afternoon rather than a licence fee.
Our organisations page is written for the firms that do all of that first and then want the input side controlled anyway, and our partners page for the external providers who usually end up configuring it. The insurance side of the same conversation is in our Irish cyber cover guide.
Sources
- Regulation (EU) 2016/679, General Data Protection Regulation. Articles 4(5), 4(7), 4(8), 5, 6, 9, 24, 28(3), 30, 32, 35, 44 to 49 and 56, as cited throughout for controller and processor roles, minimisation, the contents of a processing contract, records, security, impact assessments, transfers and the one-stop-shop mechanism. Source
- Data Protection Act 2018 (Ireland). The Irish implementing Act, including section 110, the power under which the Data Protection Commission commences a statutory inquiry. Source
- Commission Implementing Decision (EU) 2023/1795 of 10 July 2023. Article 1 limits the finding of adequacy to transfers to organisations in the United States “that are included in the ‘Data Privacy Framework List’” maintained by the US Department of Commerce. Source
- Data Privacy Framework List, US Department of Commerce, searched 20 September 2026. Google LLC active on all three frameworks; Microsoft Corporation active with recertification under review; no entry for OpenAI or Anthropic in either the active or the inactive register; 3,664 participants in total on the day of the search. Source
- Data Protection Commission, AI, Large Language Models and Data Protection, 18 July 2024. What to understand before starting to use an AI system; the risks listed for an organisation using an AI product, including memorisation, filter circumvention, automated decision making and storage limitation. Source
- Data Protection Commission, List of Types of Data Processing Operations which require a Data Protection Impact Assessment. The Irish Article 35(4) list: ten processing types mandatory where a documented screening indicates likely high risk, and the factors influencing that assessment, beginning with uses of new or novel technologies. Source
- Data Protection Commission, Data Protection Impact Assessments guidance. The obligation to assess, decide and document whether an assessment is necessary for each proposed processing operation, and to consult the Commission where residual high risk remains. Source
- Data Protection Commission, inquiry into Google Ireland Limited, 12 September 2024. A cross-border statutory inquiry under section 110 of the Data Protection Act 2018 into whether an impact assessment was required before developing the PaLM 2 foundational model. Source
- Data Protection Commission, inquiry into X Internet Unlimited Company, 17 February 2026. An inquiry on a large scale under section 110, concerning generative AI functionality associated with the Grok model, examining compliance with Articles 5, 6, 25 and 35 GDPR, with the DPC acting as lead supervisory authority. Source
- Data Protection Commission, final decision following inquiry into the HSE, announced 2 September 2026. A fine of €645,000, a reprimand and corrective orders over the storage and retention of paper records in external facilities, following two 2023 breach notifications, an inquiry opened in May 2024 and twelve site inspections. Source
- Data Protection Commission, Annual Report 2025, published 30 June 2026. 16,160 new cases from individuals, up 45 per cent on the previous year; 6,521 valid breach notifications; 208 cross-border complaints concluded as lead supervisory authority. Source
- European Data Protection Board, opinion on AI models, announced 18 December 2024. Requested by the Irish supervisory authority under Article 64(2); when an AI model may be considered anonymous, the three step test for legitimate interest, the criteria for reasonable expectations, and the effect of unlawful development on lawful deployment. Source
- Data Protection Commission, DPC statement on LinkedIn AI Training, 7 November 2025. The five categories of change secured, the report due within five months of commencement, the sentence “The DPC has not approved, or found compliant, LinkedIn’s use of users’ personal data for generative AI model training”, and the description of the office as “the Lead Supervisory Authority for many large global technology companies with their main establishment in Ireland”. Source
- Data Protection Commission, conclusion of proceedings relating to X’s AI tool Grok, 4 September 2024. Urgent High Court proceedings brought on 8 August 2024 over the training of Grok on EU and EEA users’ public posts; the first such action by the DPC as lead supervisory authority, under section 134 of the Data Protection Act 2018; proceedings struck out on X’s permanent undertaking, and the Article 64(2) request made to the EDPB the same day. Source
- Law Society of Ireland, guidance on the use of generative artificial intelligence, December 2025. Names Copilot, ChatGPT, Claude and Gemini; by default, free and paid consumer versions are not suitable for securely handling personal data or client confidential data; never assume an enterprise tool guarantees compliance; privilege may be lost by intentional release to a third party. Source
- OpenAI, Europe privacy policy, updated 24 August 2026. OpenAI Ireland Limited as controller for the EEA and Switzerland; the Data Protection Commission named as lead supervisory authority; section 10 on transfers, relying on adequacy decisions under Article 45(1) and on the standard contractual clauses under Article 46(2)(c) for other jurisdictions. Source
- OpenAI, Enterprise privacy at OpenAI, updated 8 January 2026. No training on business data by default; the Data Processing Addendum for Business, Enterprise and the API; who inside OpenAI can view conversations, and the outside contractors who review Business conversations for abuse. Source
- Anthropic, Privacy Policy, effective 10 September 2026. Anthropic Ireland, Limited; section 5 on data transfers to servers in the United States, relying on adequacy decisions and on standard contractual clauses under Article 46 for countries without an adequacy decision. Source
- Google, Gemini Apps Privacy Hub, consulted 19 September 2026. Google Ireland Limited as provider for the EEA and Switzerland; the legal bases for the EU and UK; trained reviewers and the retention of reviewed conversations for up to three years, disconnected from the account and not deleted with your activity. Source
- Google, Generative AI in Google Workspace Privacy Hub, updated 14 August 2026. The processor commitments under the Cloud Data Processing Addendum; content not human reviewed or used for model training outside your domain without permission; the retention table, and data region settings not applying to Gemini Notebook. Source
- Microsoft Learn, Data, privacy and security for Microsoft Copilot, and for web search in Copilot. No training of foundation models on prompts, responses or Graph data; the EU Data Boundary; “Models provided by Anthropic as a subprocessor are currently excluded from the EU Data Boundary”; the Data Protection Addendum and the EU Data Boundary do not apply to generated web search queries. Source
Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT . No account, and your client's details never leave your machine.
Common questions
Which AI is GDPR compliant?
None on its own. The GDPR regulates processing, not products, so there is no register of approved tools. What decides it is your use: the contract you hold, whether the provider trains on your text, where the data goes, how long it is kept and what you put in.
Is ChatGPT GDPR compliant?
That question has no yes or no answer. OpenAI Ireland Limited offers a Data Processing Addendum for Business, Enterprise and the API, and names the Irish Data Protection Commission as its lead supervisory authority. Whether your use is lawful depends on your contract and your inputs.
Who regulates ChatGPT, Claude, Gemini and Copilot in Ireland?
The Data Protection Commission, at 6 Pembroke Row, Dublin 2. All four products have an Irish company as controller for the European Economic Area, although only OpenAI names the DPC as its lead supervisory authority in its own privacy policy.
Do I need a data processing agreement to use AI at work?
Yes, where the provider processes personal data on your behalf. Article 28 GDPR requires a written contract with specified content. OpenAI, Anthropic, Google and Microsoft each publish one for business plans. Consumer plans are generally outside those documents.
Can I send personal data to OpenAI or Anthropic under the GDPR?
Yes, with a Chapter V transfer tool in place. Neither company appeared on the EU-US Data Privacy Framework List when we checked it on 20 September 2026, so both rely on standard contractual clauses. Google LLC and Microsoft Corporation are on that list.
Do I need a DPIA before using an AI tool in Ireland?
Sometimes. The DPC's Article 35(4) list names ten processing types where an assessment becomes mandatory once a documented screening shows likely high risk. The first is using personal data on a large scale for a purpose other than the one it was collected for.
What has the Irish DPC said about generative AI?
It went to the High Court in August 2024 over Grok's training data, requested the European opinion on AI models delivered that December, and stated in November 2025 that it has not approved or found compliant LinkedIn's use of personal data for generative AI training.
Is a free ChatGPT account enough for client work in Ireland?
The Law Society of Ireland says that by default, free and paid consumer versions of GenAI systems are not suitable for securely handling personal data or client confidential data. Its guidance of December 2025 points firms towards enterprise versions instead.
Does masking data before you send it make the use lawful?
No. Pseudonymised data is still personal data under Article 4(5) GDPR, so the obligations continue to apply. Reducing what a third party receives is a genuine reduction in risk, but it does not replace the contract, the record or the lawful basis.