Other people's data comes with it
An email thread carries names, addresses, bank details and salary figures of people who never chose to share them with an AI system. Searching a drive returns whatever matches, not only what the task needs.
GDPR
When an AI assistant reads a mailbox, a shared drive or a Slack channel, the personal data in it goes to the AI provider along with everything else. The GDPR asks you to limit that to what the task needs, to protect it, and to be able to show how. PrivacyFence puts a checkpoint on that path that runs on your own computers: a person sees what would be released, personal data is checked for locally, whole categories can be withheld, and every decision is logged.
It is a tool for doing that work, not a substitute for it. PrivacyFence does not make a deployment meet the GDPR by itself; see what PrivacyFence does not claim. This page is not legal advice.
The problem
An email thread carries names, addresses, bank details and salary figures of people who never chose to share them with an AI system. Searching a drive returns whatever matches, not only what the task needs.
Whatever the assistant reads is sent to the AI provider to be processed, often outside the EU. That needs a legal basis, a processing agreement and, outside the EU, a transfer mechanism.
A connection to Gmail or Drive lets the assistant read anything the account can. The assistant chooses what to fetch, and a permission granted once covers every later request.
Where it helps
| GDPR | What PrivacyFence does | What stays your job |
|---|---|---|
| Data minimisation Art. 5(1)(c) | Sensitive reads wait on a card that previews the actual content before it reaches the AI. On deny, the AI gets nothing. The privacy filter redacts or blocks whole categories, such as Gmail attachments or contact notes, before anything is shown. | Deciding what a task needs, and setting the filter to match. |
| Protection by design and by default Art. 25 | In a fresh configuration, reads that release content go to review, the personal-data check is on, and categories such as Gmail attachments and contact notes are blocked. Categories you haven't listed default to block, and in an organization deployment so does a missing filter group. | Keeping those defaults, or recording why you changed them. |
| Security of processing Art. 32 | Connector credentials are never passed to the AI client, and on packaged installs they sit under a separate service account where it can't read them. Approving a write or a flagged read can require a passkey. | Securing the computers and servers it runs on, and your identity provider. |
| Accountability and records Art. 5(2), Art. 30 | Every gate decision is written to an audit log chained with HMAC-SHA256, recording the tool, the outcome and the AI system as it identifies itself. For personal data it records the category, never the matched text. Organization mode can forward entries to syslog or an HTTP endpoint. | Your records of processing, and how long you keep the log. |
| Processors Art. 28 | There is no PrivacyFence service. The software runs on your computers or your server, and no data passes through infrastructure operated by PrivacyFence: the project does not receive or process your data. | Agreements with the AI provider and with Google, Slack, Salesforce or Atlassian. |
| Transfers outside the EU Chapter V | PrivacyFence runs where you put it, including on a server in the EU. What you release still goes to the AI provider, wherever it processes data. | The transfer mechanism for the AI provider. |
The article references are to Regulation (EU) 2016/679. The European Data Protection Board's guidelines on Article 25 explain data protection by design and by default in more detail.
The personal-data check
Before a read is shown for review, PrivacyFence scans it on your machine, with no network calls, for likely personal data in Hungarian, English and German: IBANs, card numbers, national ID, tax and social-security numbers, salary information and similar. The full list is in PII detection keywords.
It is a pattern-based heuristic, not a classifier. It can miss personal data and flag things that aren't. Email addresses and phone numbers are deliberately not detected, because nearly every email signature carries them. A match means "look more carefully", nothing more.
For your assessment
If you run a data protection impact assessment (Art. 35) for AI assistants, these are the facts about PrivacyFence it will need.
| Question | Short answer | Details |
|---|---|---|
| Where does the data flow? | From the computer or server running PrivacyFence straight to Google, Slack, Salesforce, Atlassian or Telegram, and only what is released on to the AI client. | Deployment modes |
| What does the AI see before approval? | Only the tool, the arguments it sent and a status. Content held for review stays inside PrivacyFence. | What the AI sees |
| Who can approve? | Only a person, in a session opened through the companion app or signed in through your identity provider. On a packaged install or an organization server, the AI client cannot approve its own request. | Security model |
| What is withheld automatically? | Whatever the privacy filter redacts or blocks, per category and per service. | Privacy filter |
| What is logged? | Each gate decision, approval and security event, chained so that edits show. Personal data appears as a category name only. | Audit log |
| Which services and actions? | A fixed list of connectors and tools, each with a gate that cannot be widened by the AI. | Tools reference |
EU AI Act
The EU AI Act applies in stages. Its rules for high-risk AI systems, which include human oversight, were moved back in 2026 and apply from 2 December 2027 for the uses listed in Annex III. Using a general-purpose assistant for email and documents is usually not one of those uses. Whether your use is, and what follows from it, is a question for your own legal review; the European Commission's overview has the current timeline.
Either way, a person approving what an assistant reads and changes, with a record of each decision, supports the GDPR's accountability principle and is similar in spirit to the AI Act's human-oversight requirements.
Next
Follow one email thread with personal data in it from the assistant's request to your decision, or read the full security model.