Back to home // RESOURCES · SECURITY AND REGULATION

AI and GDPR: what changes when the model runs inside the company

Which data protection obligations arise when using AI with documents containing personal data, and which ones go away — and which do not — when the system is on-premise.

Polaris AI Team ·

AI and GDPR

Using artificial intelligence with documents that contain personal data is processing subject to the GDPR. If the AI is a cloud service, the provider normally acts as a data processor, and the requirements of Article 28 apply — plus those on international transfers if the servers are outside the European Economic Area. If the AI runs on the company’s own servers, that third party disappears, but the company remains the data controller and keeps all its other obligations.

First: this is not legal advice

This article explains the concepts involved when a business uses AI with personal data. Each specific processing activity needs its own analysis, which is what the company’s data protection officer or a specialist lawyer is for. The official sources are linked at the end.

Obligations that arise when using cloud AI

Special categories and professional secrecy

Article 9 of the GDPR gives enhanced protection to certain categories of data: health, genetic and biometric data, political opinions, sexual orientation, among others. A clinic using AI with medical records is processing health data, which raises the bar for everything above.

Professional secrecy — for lawyers, healthcare professionals, advisors — is an obligation separate from the GDPR that adds to it. Sending documentation covered by secrecy to a third party, even a contracted technology provider, is something each professional must weigh against the rules of their profession and its governing body.

What changes with on-premise AI

And the EU Artificial Intelligence Act

Regulation (EU) 2024/1689, known as the AI Act, regulates AI systems according to their level of risk and applies in phases. It does not replace the GDPR: both apply at the same time when an AI system processes personal data.

For most administrative uses in a small business — classifying documents, extracting invoice data, answering questions about the internal archive — the bulk of the most demanding obligations, designed for high-risk systems, does not usually apply. But it is worth checking case by case and following the timeline at the official source, because it has been under review.

How Polaris AI handles it

Polaris AI runs on the company’s own servers or a private virtual machine. The container network where the models run has no internet access, and the only outbound connections are to services the company already uses — its own Google Workspace and WhatsApp. Outbound traffic can be audited.

That removes the AI provider as a recipient of the documents. It does not remove the company’s obligations as data controller, and we say so in every conversation.

Official sources and related reading

Official texts: General Data Protection Regulation (EU) 2016/679 · Artificial Intelligence Act (EU) 2024/1689 · Spanish Data Protection Agency (AEPD).

Frequently asked questions

Yes, with conditions. If the AI is an external service, the GDPR requirements on processors and transfers apply, and you need to consider whether professional secrecy allows sending that documentation to a third party. If the AI runs inside the company and documents do not leave its network, that part goes away, although the company keeps its other obligations.
The content the model processes does not. There may be other connections — for instance, to the email or messaging the company already uses — and it is important to know what they are and be able to audit them.
No. No system is GDPR-compliant on its own: compliance depends on how the company uses it. On-premise AI removes the risks of sending data to an external provider, but the company still needs a legal basis, security measures, records of processing, and all its other obligations.

Want to know which of your processes could be automated without documents leaving the company? We look at it in the assessment.

Request a Polaris AI Assessment

Do you work with sensitive data?

We will explain how Polaris is installed, what connections it has, and how it is audited. No commitment.

Talk to Polaris AI on WhatsApp