Tool · runs in your browser As of 26 August 2026
The data traffic light: may this go into an AI tool?
The most common question in daily work, and the one where most goes wrong. Two answers are enough. The traffic light is deliberately strict: when in doubt, better to leave out one item too many.
All twelve combinations at a glance
| Kind of data | Tool | Assessment | Why | Instead |
|---|---|---|---|---|
| Public content | Private account | Green: No data problem. | Public content is unproblematic in itself; the question here is the quality of the answer, not data protection. | For work purposes, set up a company account all the same. A private account runs on one person, so what builds up at the provider is a usage profile of that person, not of the business. |
| Public content | Approved for company use | Green: No data problem. | Public content in an approved tool: the normal case, and how it should be. | Check the result all the same before it goes out. Approved data does not mean correct answers. |
| Public content | Locally run AI | Green: No data problem. | Public content, a local tool: in data protection terms the simplest combination. | Two questions remain: is the local model good enough for the task, and is the installation exposed on the network? These programs usually ship without password protection. |
| Internal data without personal reference | Private account | Amber: Better not through a private account. | No personal data, but trade secrets. Training can often be switched off in a private account too; what is missing is the contract. Without a data processing agreement there is no duty to follow your instructions and no company control over what happens to the inputs. | If it has to be quick: round the figures and leave out names and customers. The lasting solution is a company-approved tool. |
| Internal data without personal reference | Approved for company use | Green: Fine – with a sense of proportion. | With a data processing agreement and training switched off, this is the intended route for internal data. | Stay frugal: enter only what the task really needs. The best input is the one you can leave out. |
| Internal data without personal reference | Locally run AI | Green: Fine. | Run locally, your inputs do not go to an AI provider. For internal documents that is the most frugal solution. | Check two things: whether the answer quality is enough for the task, and what the program itself reports outwards. Models are downloaded, and update checks carry device and version data with them. |
| Personal data | Private account | Red: Stop. | Names, contacts or contracts of customers and staff in a private AI account are a data protection problem, not a minor offence, however urgent the job. | Placeholders instead of names (“Customer A”, “Employee B”) hide the link to a person, they do not remove it. The placeholder usually does the job; the tool is still the wrong one. The route runs through an approved company tool. |
| Personal data | Approved for company use | Amber: Possible – under conditions. | With a data processing agreement, training switched off and data minimisation, this can be permissible. Whether it is in your case depends on tool and purpose. Your AI policy settles that, and legal advice if in doubt. | Rule of thumb: if a placeholder does the job, use the placeholder. The insight is the same, the amount of data is not. It does not make the input anonymous, only leaner. |
| Personal data | Locally run AI | Amber: Technically the cleanest route – with homework. | Your inputs do not go to an AI provider, so the transmission problem disappears. That alone does not make the processing itself lawful – the GDPR applies unchanged, so legal basis, purpose, access and deletion have to be settled. On top, the programs report device and version data when they check for updates, and few ship with password protection. | Set down in writing who may use the system for what, secure access to it, and settle the legal basis as for any other processing. Then this is a good solution. |
| Particularly sensitive data | Private account | Red: Stop, no exceptions. | Health data, job applications, salaries: the touchiest group in a business. A private account is off limits, and placeholders help little here. With rare characteristics the inference back to the person remains possible, and then the input is not anonymous at all. | For now this data belongs in no AI tool at all. If the need is real: data protection officer or legal advice first, the tool question second. |
| Particularly sensitive data | Approved for company use | Red: Settle it first, then type. | Even with a data processing agreement this is not an everyday decision. This category of data needs an explicit clarification beforehand, often with the answer: no. | Before any use: data protection officer or legal advice. Until then: keep it out. |
| Particularly sensitive data | Locally run AI | Amber: Only with clear rules. | Running locally solves the transmission problem, not the protection question: access, purpose and deletion have to be settled before such data goes into any system. | First the written rule: who, for what, for how long. Then the tool. In that order it is defensible. |
The traffic light is orientation, not legal advice. Whether an entry is permissible in a specific case depends on tool, settings and purpose. The fourth data type gathers what counts as particularly sensitive inside a business. In law, only “health” is a special category under Art. 9 GDPR; salaries and financial data are not. Job applications are not a special category either, but often contain such data. All of it is confidential regardless. Your selection stays in your browser; nothing is transmitted or stored. What is to apply generally in your business belongs in an AI policy.
May I enter customer data into ChatGPT?
Through a private account without a data processing agreement: as a rule, no. Through a company-approved tool with such an agreement: under conditions. A placeholder instead of the real name is almost always leaner, but it does not make the input anonymous. Which conditions apply in a specific case is for your AI policy to settle, and legal advice if in doubt. The AI literacy check shows whether rules, briefings and a record are already in place in your business.
What is a data processing agreement?
The contract recording that a provider processes your data only on your behalf and on your documented instructions. Art. 28 of the GDPR sets out what has to be in it. Subject matter and duration, nature and purpose of the processing, the types of data, the categories of data subjects, and your rights and obligations. As a rule, the contract comes only with the business offerings. What decides it is not whether you pay but which contract you signed. A paid consumer plan runs without one too.
What placeholders do, and what they do not
Replacing names with placeholders and rounding amounts is pseudonymisation, not anonymisation. The difference is in the GDPR itself. Under Art. 4(5), data is pseudonymised if it can be reattributed using additional information. Recital 26 still counts such data as personal. An input is anonymous only once nobody can infer a person from the context either. In small businesses and with rare characteristics that inference is easier than people think. For most tasks the placeholder changes nothing about the result, and less data is better than more all the same. The prompt workshop shows how placeholders sit in a clean instruction.
Frequently asked questions about the data traffic light
How do I know whether training is switched off?
Why is the traffic light stricter than the provider?
Does the traffic light also apply to image and translation tools?
What belongs in an AI policy?
Sources and status. The assessments rest on Regulation (EU) 2016/679, the General Data Protection Regulation. Drawn on here are Art. 4(5) and Recital 26 on the line between pseudonymisation and anonymity. Also Art. 9 on special categories of data, Art. 28 on processing on behalf of a controller and Art. 33 on notification. The governing text is the consolidated version of 4 May 2016. The Regulation has not been amended since, only corrected three times, most recently in Official Journal L 74 of 4 March 2021. The AI Act is not relevant here: it governs the labelling of AI and AI literacy, not which data may go into a tool. Source: EUR-Lex, Regulation (EU) 2016/679 (opens in a new tab). As of 26 August 2026.
Terms related to this service
Technical terms that appear on this page – explained in one sentence in our glossary.