Data minimization
Only pass along the information that is truly needed for the specific step.
Privacy is not added later. It has to be built into routing, permissions, storage locations, and logs.

Relevant both technically and organizationally.
Only pass along the information that is truly needed for the specific step.
Not every agent should be allowed to read every source or trigger every action.
Decisions, handoffs, and data movement need to stay visible.
Critical decisions remain with accountable people.
Every Saturday at 11:00 Europe/Berlin, the format gives a compact mix of market filtering, practical cases, questions, and clear next steps.
Next session: Saturday, August 8, 2026 at 11:00 · Europe/Berlin. The series then continues on a weekly rhythm.

We intentionally use wording such as GDPR-aware, privacy-conscious, and governance-ready instead of making unverified full-compliance promises.
Compliance only emerges from the combination of technology, contracts, processes, and real operational use.
What GDPR-compliant use of AI in the company concretely requires.
Assessment of common AI platforms by EU data residency, data processing agreement and training exclusion. Traffic light: Green = well suited, Yellow = possible with configuration/contract, Red = unsuitable for personal data. Sources: provider documentation, as of 07/2026.
| Platform / Model | EU data residency | DPA available | No training with data | Traffic light |
|---|---|---|---|---|
| Self-hosting (Mistral / Llama on-prem) | Yes — own EU infrastructure | Not needed (internal processing) | Yes — data does not leave the premises | 🟢 Green |
| Mistral (la Plateforme, EU cloud) | Yes — EU servers by default | Yes | Yes (Enterprise; non-EU flows can be disabled) | 🟢 Green |
| Azure OpenAI Service (EU region) | Yes — EU regions / data zones | Yes (Microsoft DPA) | Yes — no training with customer data | 🟢 Green |
| Google Gemini via Vertex AI (EU) | Yes — EU regions | Yes (Google Cloud DPA) | Yes — no training with Vertex data | 🟢 Green |
| OpenAI API (EU data residency region) | Yes — 'Europe' region with Zero Data Retention | Yes (OpenAI DPA) | Yes — no training with API data | 🟢 Green |
| Anthropic Claude (via Bedrock / Vertex EU) | Yes — via AWS / Google EU regions | Yes (DPA with SCCs; ZDR on request) | Yes — no training with API data | 🟢 Green |
| Anthropic Claude (first-party API) | Limited (no dedicated first-party EU region) | Yes (DPA with SCCs) | Yes — no training with API data | 🟡 Yellow |
| Free consumer chatbots (free tier) | Mostly US, no commitment | No / limited | No — inputs may be used for training | 🔴 Red |
The key facts on legally compliant use of AI.
GDPR compliance is not a property of a single tool, but of the right configuration. The safest are self-hosted open models (Mistral, Llama) on your own EU infrastructure. Among cloud providers, Azure OpenAI, Google Vertex AI, the OpenAI EU region and Anthropic Claude (via AWS Bedrock or Google Vertex) are GDPR-capable, provided a DPA is concluded and the EU region is chosen. Free consumer chatbots are unsuitable for personal data.
Yes. As soon as an AI service provider processes personal data on your behalf, a data processing agreement (DPA) under Art. 28 GDPR is mandatory. All major providers — Anthropic, OpenAI, Google and Mistral — provide a corresponding Data Processing Addendum. Culturetek ensures that the DPA is concluded and the processing is configured correctly.
In the free consumer version this is not advisable, because inputs can be used for training depending on the setting. Via the OpenAI API with an EU data residency region (Zero Data Retention) or via the Azure OpenAI Service with an EU region and Microsoft DPA, GDPR-compliant use is, however, possible. What is decisive are the DPA, the EU region and the exclusion of training with your data.
Yes, from a data protection perspective, self-hosting is the most controlled option. With a self-operated open model such as Mistral or Meta Llama on your own EU infrastructure, neither prompts nor outputs leave your own data center. The trade-off is higher operating and infrastructure costs as well as your own maintenance effort — Culturetek weighs this up per use case.
With the API and Enterprise plans of the leading providers (Anthropic, OpenAI, Google, Mistral), your inputs are by default not used for model training. With free consumer versions this may be different — there, inputs can flow into training depending on the plan and setting. For company data, API/Enterprise plans or self-hosting are therefore the right way.
Yes. The Data Protection Conference (DSK), the body of the independent German data protection supervisory authorities, has published the 'Orientierungshilfe Künstliche Intelligenz und Datenschutz' (first in May 2024) — a practical checklist for companies that deploy AI applications, supplemented by further guidance on technical and organizational measures and RAG systems. Culturetek aligns the implementation with this guidance (source: Datenschutzkonferenz, datenschutzkonferenz-online.de).
If you want to prioritize a real process, a few clear inputs are enough for a strong first assessment.