Skip to content
How GDPRWise Works calendar_today Updated: 8 October 2026 schedule 6 min read

Review Your AI Use and Set Your AI Permissible Use Policy in GDPRWise

verified Last reviewed 8 October 2026 · GDPRWise legal team

A step-by-step guide for the GDPR coordinator: inventory the AI tools your staff use, add them as systems, link the vendor and the processes, set a rule per tool and generate your AI Permissible Use Policy in the GDPRWise app.

summarize Key Takeaways
  • check_circle Your staff already use AI, both in standalone tools such as ChatGPT and in AI features inside the software you own; the first step is a list of both
  • check_circle Every AI tool becomes a system in your customer and/or staff dossier, with its account type, its vendor linked and its processes linked
  • check_circle The policy can only allow personal data in a tool whose vendor has a data sharing agreement with you; without one the app flags the rule as a risk
  • check_circle On the GDPR Documents page you set a rule per tool (allowed or not, which data) and generate the AI Permissible Use Policy; a tool without a rule is listed as not allowed

Your staff already use AI: in ChatGPT, and inside the tools you already own. An AI Permissible Use Policy says which tools are allowed and with which data. This guide takes you from “no idea” to a generated policy in six steps, with the GDPRWise app open next to you.

1. Inventory your AI use

Make two lists. Walk through them with the people who know what the team actually uses: an office manager, a team lead, whoever runs IT.

Standalone AI tools that people open in a browser or app:

  • ChatGPT
  • Claude
  • Gemini (the app)
  • Mistral Le Chat
  • Microsoft Copilot (the chat)

AI features inside tools you already use:

  • Microsoft 365 Copilot (Word, Excel, Outlook, Teams)
  • Gemini in Google Workspace (Docs, Gmail, Meet)
  • Meeting recaps and transcripts in Teams or Meet
  • Canva
  • Notion AI
  • Zoom AI Companion
  • The assistant in your CRM, accounting tool, help desk or HR software

Ask one question per tool: do people paste customer or staff data into it? Names, email addresses, a candidate’s CV, a complaint, an invoice, a meeting transcript. If the answer is yes or probably, the tool belongs in the policy. If nobody can say, assume yes.

Do not stop at the tools you pay for. The free ChatGPT account someone opened on their own is exactly the one that needs a rule.

2. Add them as systems

Every AI tool becomes a system in your dossier. Which dossier depends on whose data goes in:

  • Customer data goes in: My Customer Dossier, tab Systems (Customer related systems).
  • Staff data goes in: My Staff Dossier, tab Systems (Staff related systems).
  • Both, as with a suite such as Microsoft 365 or Google Workspace: add it in the customer dossier and tick Also add this system to the staff dossier while adding. It then appears in both.

Pick the tool from the library, or use Add another system and create your own if it is not listed. In the system modal, tab General:

  • Tick AI features if the tool has them for your company, even when the library entry does not say so. A CRM with a new AI assistant counts.
  • Set the Account type: consumer, business or enterprise. The advice the app gives you for this system depends on it. A consumer account is the one someone created with a personal email and no company contract.

Screenshot: the system modal, General tab, with AI features ticked and the account type selected.

Still in the system modal, open the tab Third parties and tick the entry of the tool’s vendor: OpenAI for ChatGPT, Microsoft for Copilot, Google for Gemini, Anthropic for Claude.

Is the vendor not in the list yet? Close the modal, go to My Third Party Dossier and add the vendor there first. Then send the data sharing agreement request from the app, or record that you already have a processing agreement with that vendor (business and enterprise accounts usually include one in the contract). Come back to the system and tick the vendor.

Why this step matters: the policy can only allow personal data in a tool whose vendor has a processing agreement with you. That is the GDPR’s Article 28 requirement for every processor that handles personal data on your behalf. GDPRWise flags a rule that allows personal data without such an agreement as a risk, so sort this out before step 5.

Screenshot: the Third parties tab of the system modal, with the guidance callout.

Open the tab Processes on the system and tick the activities the tool is used in: drafting customer emails, screening CVs, summarising meetings, bookkeeping. This puts the system in the right place in your records of processing, next to the data and the purpose it serves.

If an activity is missing, add it first under the Processes tab of the same dossier, then come back.

5. Set the rules

Go to GDPR Documents, find the AI Permissible Use Policy card and click Set the AI tool rules. The AI tools dialog lists one row per system with AI features. For each tool, set:

  • Status: allowed or not allowed.
  • Data allowed: Public information only, No personal data, Personal data, or Personal data incl. special categories (health, religion and the like).
  • Allowed use (optional): a short description of what the tool may be used for, such as “drafting and translating, no customer data”.

Below each choice the app lists issues to look at: a consumer account, a missing data sharing agreement, data transfers outside the EU, special categories without a specific legal basis. Read them. A red issue can only be confirmed knowingly: the app records who confirmed it and when, so the decision is traceable later.

A sensible default for a tool with a consumer account and no agreement: allowed, public information only. For a business account with the agreement in place: allowed, no personal data or personal data, depending on what the tool is used for. Reserve “including special categories” for a tool that was specifically assessed for it.

Screenshot: the rule modal, with the numbered list of issues under the data choice.

6. Generate the policy and hand it to staff

Back on the AI Permissible Use Policy card, generate the document. It lists every AI tool with its status, the data allowed and the agreed use, and names the tools that are not allowed. Share it with your staff the way you share your other policies, and ask them to confirm they have read it.

Telling staff is a step of its own. The next compliance item, Implement AI staff training, covers it: the EU AI Act asks businesses that use AI to take measures that support AI literacy among the staff who work with it, and a short session on this policy is the practical way to do that.

What good looks like

  • Every AI tool your staff use is a system in the right dossier: customer, staff or both.
  • Every system with AI features has its vendor linked, with a data sharing agreement in place or recorded.
  • Every such system has its processes linked.
  • Every tool has a rule: status, data allowed and, where useful, the allowed use.
  • Any red issue was confirmed knowingly, and you can say why.
  • The generated policy is current and has been handed to staff. A tool without a rule is listed in it as not allowed, which is the right default until you assess it.

Repeat the inventory when a new tool shows up or a vendor changes its terms, and regenerate the policy; the app marks it as needing an update when the underlying systems change.

description

How to create an AI acceptable use policy for your business

What such a policy should contain and why, if you want the background to the rules you set here.

Read more arrow_forward
description

AI and privacy: what every small business should know and do

The GDPR and AI Act duties behind this guide: processing agreements, AI literacy and transparency.

Read more arrow_forward
auto_awesome Not using GDPRWise yet?

The free scan shows where your business stands on the GDPR. In the app you build your dossiers step by step and generate your AI Permissible Use Policy from them.

Share share LinkedIn mail Email
GW
GDPRWise Editorial

This article was written by the GDPRWise team and reviewed by our privacy experts. We regularly review our content for accuracy and legal correctness.