Start by asking whether the input identifies a person
IMY states that GDPR applies when an organisation processes personal data in connection with developing or using AI. The organisation must follow the core principles, have a legal basis and inform people about how their data is handled. [1]
Names, email addresses, phone numbers, customer histories, employee notes and identifiable conversation excerpts can all change the risk of a seemingly simple prompt. Replacing a name does not necessarily make a record anonymous if the remaining details still identify the person.
Purpose and minimisation come before convenience
IMY’s guidance on AI and data minimisation emphasises thinking through which personal data—and how much—is genuinely needed for the purpose. “It may improve the answer” is not by itself a clear operating purpose. [2]
Write the purpose before opening the tool. A safer version of “analyse our customers” might be “group ten already-anonymised service questions so we can rewrite the FAQ”. The second formulation narrows both the data and the expected output.
Screen for high-risk processing before it starts
Not every AI use requires a data protection impact assessment. IMY says an assessment is mandatory when a type of processing is likely to create a high risk to people’s rights and freedoms, and it should generally happen before that processing begins. [3]
Escalate the review when the workflow scores or profiles people, uses sensitive or large-scale personal data, monitors behaviour, or supports decisions with significant effects. A small business can still begin safely with non-personal public information or bounded internal material that has been deliberately stripped of unnecessary personal details.
USE THIS
The decision record to keep
-
Purpose
What exact business outcome requires this information?
-
Data
Which fields identify a person, and which can be removed or aggregated?
-
Responsibility
Who is the controller, what does the provider do and who reviews output?
-
Access and retention
Where is input stored, for how long and who can retrieve it?
-
Decision boundary
What can AI prepare, and what must a person verify or approve?
-
Risk screen
Could this processing significantly affect, monitor, profile or expose someone?
-
Revisit date
Review the decision when the purpose, provider, data or automation changes.
PRIMARY SOURCES
Evidence used in this guide
-
Swedish Authority for Privacy Protection (IMY)GDPR and AI
Core GDPR responsibilities when personal data is used with AI.
-
Swedish Authority for Privacy Protection (IMY)Challenges with data minimisation and development of AI
Purpose limitation and using only the personal data that is needed.
-
Swedish Authority for Privacy Protection (IMY)When should a data protection impact assessment be conducted?
The high-risk threshold and timing of an assessment.