SME note · privacy
GDPR basics for AI projects
GDPR is not a 60-page PDF to scare the committee. In an AI pilot it is a short list: which data you touch, on what legal basis, who the processor is, where it lives, and what never goes into a public model.
SMEs who skip this are not evil. They skip it because “it is only a test”. Tests stay. Prompts get logged. The customer Excel ends up in a history you do not control.
This does not replace a lawyer. It is the minimum we require before a flow is switched on. If it cannot fit on one page, the scope is too big.
Inventory before the prompt
Name the flow (supplier invoices, support tickets, internal FAQ). List fields: name, tax ID, amount, email, health, children, credentials. Mark which are personal and which are special. If there are special categories or children, stop: this is not a two-week pilot.
The inventory is boring and it is what saves you when someone asks “what did you put in the model?”. Without it the answer is a shrug. That is not a defence.
A legal basis, not a checkbox
Contract (fulfil an order, invoice), legal obligation (keep invoices), legitimate interest (improve an internal process with safeguards), consent (rare in back-office AI and easy to break). Pick one and write it. “Because it is handy” is not a basis.
Legitimate interest needs a balance: what you gain, what risk for the person, what less invasive alternative. If you cannot explain it in five lines, do not use it as a drawer.
Processors and sub-processors
Whoever hosts the model, stores logs, transcribes, or backups: processors. Ask for the contract, the sub-processor list, residency, whether they train on your inputs, and how they delete. “We are GDPR compliant” on a homepage is not a contract.
If the vendor does not answer in writing within a week, they are not a vendor for a pilot with real data. Use synthetic data or an internal corpus with no personal data until they answer.
What never gets pasted
- Credentials, tokens, passwords, seeds.
- Health, politics, union membership, biometrics.
- Full payrolls, scanned IDs, children’s data.
- Customer secrets covered by contract.
- Entire databases “so the model gets an idea”. Minimise: the field you need, not the spreadsheet.
Inform the team and the people
The team needs a yes / no / ask poster, not a manual. Customers and staff need to know if a new processing affects them. Sometimes updating a clause is enough; sometimes you must say it specifically. Do not decide that in the corridor on go-live day.
Document the flow: one page with inventory, basis, processor, retention and the kill switch. That is the embryo of the records of processing for this treatment.
Pilot and programme fit
The legal perimeter runs in parallel with the flow design, not after. Kit Consulting fits inventory, risk and vendor criteria. Implementation does not start on real data until that page exists.
If the voucher squeezes the calendar, cut the pilot, not the inventory. A fast deliverable with a leak is not a deliverable.
Retention and deletion, practically
Invoices are kept under commercial and tax law; the pilot does not delete them at day 30. Test prompts with personal data do get deleted when the test ends — and the test has a date. Vendor logs: ask the period and ask that it not exceed what you need to debug.
When a customer exercises a right, you must know which queues hold their data. That is why the one-page inventory is not bureaucracy: it is the map for the answer. If the answer is “we do not know”, the pilot ran ahead of the record.
Document deletion once (steps, screens, who does it). You do not need a 15-page procedure. You need to be able to repeat it.
What is not “legitimate interest” here
“We want to improve productivity” is not enough. Neither is “the vendor does it this way” nor “it is a test”. Legitimate interest holds if the flow is internal, the data is the minimum, worse alternatives exist (retyping 80 invoices by hand with more errors) and people are not harmed out of proportion.
If the flow touches end customers in a public chat, it is almost never legitimate interest. Then you either have a clear contract, or real consent, or no pilot. Do not invent a fourth way in the memo.
Frequently asked questions
Do we need a DPO?
It depends on volume and data type. Many SMEs are not required to have one. That does not exempt them from a legal basis, contracts and an inventory.
Can we just anonymise?
Pseudonymisation is not anonymisation. If you can still get back to the person, it is still personal. Doing anonymisation well is harder than it looks in a spreadsheet.
What about local models?
They reduce processors; they do not remove the legal basis or the team perimeter. The risk of pasting too much is still on the table.
Next: data and privacy and EU suppliers. Write to us with the flow and data type.
Studio in Barcelona. Part of Clutch Developer. Oriented to Spain’s SME digitalisation programmes. Request an assessment.