GDPR

AI assistants and the GDPR: decide what leaves, and keep a record.

When an AI assistant reads a mailbox, a shared drive or a Slack channel, the personal data in it goes to the AI provider along with everything else. The GDPR asks you to limit that to what the task needs, to protect it, and to be able to show how. PrivacyFence puts a checkpoint on that path that runs on your own computers: a person sees what would be released, personal data is checked for locally, whole categories can be withheld, and every decision is logged.

It is a tool for doing that work, not a substitute for it. PrivacyFence does not make a deployment meet the GDPR by itself; see what PrivacyFence does not claim. This page is not legal advice.

The problem

What changes when an assistant reads your mailbox.

Other people's data comes with it

An email thread carries names, addresses, bank details and salary figures of people who never chose to share them with an AI system. Searching a drive returns whatever matches, not only what the task needs.

A new recipient

Whatever the assistant reads is sent to the AI provider to be processed, often outside the EU. That needs a legal basis, a processing agreement and, outside the EU, a transfer mechanism.

Access is broad by default

A connection to Gmail or Drive lets the assistant read anything the account can. The assistant chooses what to fetch, and a permission granted once covers every later request.

Where it helps

The GDPR principles, and what PrivacyFence does for each.

GDPRWhat PrivacyFence doesWhat stays your job
Data minimisation
Art. 5(1)(c)
Sensitive reads wait on a card that previews the actual content before it reaches the AI. On deny, the AI gets nothing. The privacy filter redacts or blocks whole categories, such as Gmail attachments or contact notes, before anything is shown.Deciding what a task needs, and setting the filter to match.
Protection by design and by default
Art. 25
In a fresh configuration, reads that release content go to review, the personal-data check is on, and categories such as Gmail attachments and contact notes are blocked. Categories you haven't listed default to block, and in an organization deployment so does a missing filter group.Keeping those defaults, or recording why you changed them.
Security of processing
Art. 32
Connector credentials are never passed to the AI client, and on packaged installs they sit under a separate service account where it can't read them. Approving a write or a flagged read can require a passkey.Securing the computers and servers it runs on, and your identity provider.
Accountability and records
Art. 5(2), Art. 30
Every gate decision is written to an audit log chained with HMAC-SHA256, recording the tool, the outcome and the AI system as it identifies itself. For personal data it records the category, never the matched text. Organization mode can forward entries to syslog or an HTTP endpoint.Your records of processing, and how long you keep the log.
Processors
Art. 28
There is no PrivacyFence service. The software runs on your computers or your server, and no data passes through infrastructure operated by PrivacyFence: the project does not receive or process your data.Agreements with the AI provider and with Google, Slack, Salesforce or Atlassian.
Transfers outside the EU
Chapter V
PrivacyFence runs where you put it, including on a server in the EU. What you release still goes to the AI provider, wherever it processes data.The transfer mechanism for the AI provider.

The article references are to Regulation (EU) 2016/679. The European Data Protection Board's guidelines on Article 25 explain data protection by design and by default in more detail.

The personal-data check

A local check that makes you look twice.

Before a read is shown for review, PrivacyFence scans it on your machine, with no network calls, for likely personal data in Hungarian, English and German: IBANs, card numbers, national ID, tax and social-security numbers, salary information and similar. The full list is in PII detection keywords.

  • It overrides your rules. A match sends the request to a card even if an always-allow rule covers it.
  • It asks twice. The card names the categories found and highlights them, and approving needs a second confirmation.
  • It logs the category, not the data. The audit log records "IBAN (bank account number)", never the number.

It is a pattern-based heuristic, not a classifier. It can miss personal data and flag things that aren't. Email addresses and phone numbers are deliberately not detected, because nearly every email signature carries them. A match means "look more carefully", nothing more.

For your assessment

Questions a DPIA will ask, and where the answers are.

If you run a data protection impact assessment (Art. 35) for AI assistants, these are the facts about PrivacyFence it will need.

QuestionShort answerDetails
Where does the data flow?From the computer or server running PrivacyFence straight to Google, Slack, Salesforce, Atlassian or Telegram, and only what is released on to the AI client.Deployment modes
What does the AI see before approval?Only the tool, the arguments it sent and a status. Content held for review stays inside PrivacyFence.What the AI sees
Who can approve?Only a person, in a session opened through the companion app or signed in through your identity provider. On a packaged install or an organization server, the AI client cannot approve its own request.Security model
What is withheld automatically?Whatever the privacy filter redacts or blocks, per category and per service.Privacy filter
What is logged?Each gate decision, approval and security event, chained so that edits show. Personal data appears as a category name only.Audit log
Which services and actions?A fixed list of connectors and tools, each with a gate that cannot be widened by the AI.Tools reference

EU AI Act

Human oversight is where the rules are heading.

The EU AI Act applies in stages. Its rules for high-risk AI systems, which include human oversight, were moved back in 2026 and apply from 2 December 2027 for the uses listed in Annex III. Using a general-purpose assistant for email and documents is usually not one of those uses. Whether your use is, and what follows from it, is a question for your own legal review; the European Commission's overview has the current timeline.

Either way, a person approving what an assistant reads and changes, with a record of each decision, supports the GDPR's accountability principle and is similar in spirit to the AI Act's human-oversight requirements.

Next

See what a reviewed read looks like.

Follow one email thread with personal data in it from the assistant's request to your decision, or read the full security model.