AI compliance starts before you press Send.
When you paste a document into a chatbot, the data leaves your company. Under the GDPR you remain responsible for it. Redacting it first is the simplest move.
Minimisation and accountability
Only necessary data, and the ability to prove it. The per-file report is that proof.
Privacy by design and pseudonymisation
Technical measures built in from the start. "Redact first, then upload" is privacy by design in practice.
AI literacy
Organisations using AI must take measures to train their staff. A clear rule on what not to give AI is the first one.
The AI Act timeline.
Updated for the Digital Omnibus on AI, in force since 27 July 2026.
Prohibited practices and AI literacy.
Rules for general-purpose AI models.
Transparency obligations (Art. 50).
High-risk systems in Annex III.
High-risk systems embedded in products.
For information only, not legal advice. Easy4Privacy supports data minimisation: it does not guarantee the removal of all personal data and does not by itself make any processing compliant. Updated 30 September 2026.
Put minimisation into practice.
Try Easy4Privacy on the documents you use with AI.