Your staff already use AI: in ChatGPT, and inside the tools you already own. An AI Permissible Use Policy says which tools are allowed and with which data. This guide takes you from “no idea” to a generated policy in six steps, with the GDPRWise app open next to you.
1. Inventory your AI use
Make two lists. Walk through them with the people who know what the team actually uses: an office manager, a team lead, whoever runs IT.
Standalone AI tools that people open in a browser or app:
- ChatGPT
- Claude
- Gemini (the app)
- Mistral Le Chat
- Microsoft Copilot (the chat)
AI features inside tools you already use:
- Microsoft 365 Copilot (Word, Excel, Outlook, Teams)
- Gemini in Google Workspace (Docs, Gmail, Meet)
- Meeting recaps and transcripts in Teams or Meet
- Canva
- Notion AI
- Zoom AI Companion
- The assistant in your CRM, accounting tool, help desk or HR software
Ask one question per tool: do people paste customer or staff data into it? Names, email addresses, a candidate’s CV, a complaint, an invoice, a meeting transcript. If the answer is yes or probably, the tool belongs in the policy. If nobody can say, assume yes.
Do not stop at the tools you pay for. The free ChatGPT account someone opened on their own is exactly the one that needs a rule.
2. Add them as systems
Every AI tool becomes a system in your dossier. Which dossier depends on whose data goes in:
- Customer data goes in: My Customer Dossier, tab Systems (Customer related systems).
- Staff data goes in: My Staff Dossier, tab Systems (Staff related systems).
- Both, as with a suite such as Microsoft 365 or Google Workspace: add it in the customer dossier and tick Also add this system to the staff dossier while adding. It then appears in both.
Pick the tool from the library, or use Add another system and create your own if it is not listed. In the system modal, tab General:
- Tick AI features if the tool has them for your company, even when the library entry does not say so. A CRM with a new AI assistant counts.
- Set the Account type: consumer, business or enterprise. The advice the app gives you for this system depends on it. A consumer account is the one someone created with a personal email and no company contract.
Screenshot: the system modal, General tab, with AI features ticked and the account type selected.
3. Link the vendor
Still in the system modal, open the tab Third parties and tick the entry of the tool’s vendor: OpenAI for ChatGPT, Microsoft for Copilot, Google for Gemini, Anthropic for Claude.
Is the vendor not in the list yet? Close the modal, go to My Third Party Dossier and add the vendor there first. Then send the data sharing agreement request from the app, or record that you already have a processing agreement with that vendor (business and enterprise accounts usually include one in the contract). Come back to the system and tick the vendor.
Why this step matters: the policy can only allow personal data in a tool whose vendor has a processing agreement with you. That is the GDPR’s Article 28 requirement for every processor that handles personal data on your behalf. GDPRWise flags a rule that allows personal data without such an agreement as a risk, so sort this out before step 5.
Screenshot: the Third parties tab of the system modal, with the guidance callout.
4. Link the processes
Open the tab Processes on the system and tick the activities the tool is used in: drafting customer emails, screening CVs, summarising meetings, bookkeeping. This puts the system in the right place in your records of processing, next to the data and the purpose it serves.
If an activity is missing, add it first under the Processes tab of the same dossier, then come back.
5. Set the rules
Go to GDPR Documents, find the AI Permissible Use Policy card and click Set the AI tool rules. The AI tools dialog lists one row per system with AI features. For each tool, set:
- Status: allowed or not allowed.
- Data allowed: Public information only, No personal data, Personal data, or Personal data incl. special categories (health, religion and the like).
- Allowed use (optional): a short description of what the tool may be used for, such as “drafting and translating, no customer data”.
Below each choice the app lists issues to look at: a consumer account, a missing data sharing agreement, data transfers outside the EU, special categories without a specific legal basis. Read them. A red issue can only be confirmed knowingly: the app records who confirmed it and when, so the decision is traceable later.
A sensible default for a tool with a consumer account and no agreement: allowed, public information only. For a business account with the agreement in place: allowed, no personal data or personal data, depending on what the tool is used for. Reserve “including special categories” for a tool that was specifically assessed for it.
Screenshot: the rule modal, with the numbered list of issues under the data choice.
6. Generate the policy and hand it to staff
Back on the AI Permissible Use Policy card, generate the document. It lists every AI tool with its status, the data allowed and the agreed use, and names the tools that are not allowed. Share it with your staff the way you share your other policies, and ask them to confirm they have read it.
Telling staff is a step of its own. The next compliance item, Implement AI staff training, covers it: the EU AI Act asks businesses that use AI to take measures that support AI literacy among the staff who work with it, and a short session on this policy is the practical way to do that.
What good looks like
- Every AI tool your staff use is a system in the right dossier: customer, staff or both.
- Every system with AI features has its vendor linked, with a data sharing agreement in place or recorded.
- Every such system has its processes linked.
- Every tool has a rule: status, data allowed and, where useful, the allowed use.
- Any red issue was confirmed knowingly, and you can say why.
- The generated policy is current and has been handed to staff. A tool without a rule is listed in it as not allowed, which is the right default until you assess it.
Repeat the inventory when a new tool shows up or a vendor changes its terms, and regenerate the policy; the app marks it as needing an update when the underlying systems change.
How to create an AI acceptable use policy for your business
What such a policy should contain and why, if you want the background to the rules you set here.
Read more arrow_forwardAI and privacy: what every small business should know and do
The GDPR and AI Act duties behind this guide: processing agreements, AI literacy and transparency.
Read more arrow_forwardThe free scan shows where your business stands on the GDPR. In the app you build your dossiers step by step and generate your AI Permissible Use Policy from them.