The right question is not only “where is the model?”
When an institution assesses an AI assistant, it is natural to begin with the model provider. Under the GDPR, however, the entire system should be examined: ingested sources, purposes, access, logs, excerpts sent to the model and retention of interactions.
This article provides general criteria and does not replace legal advice or an impact assessment for a specific context.
Purpose and minimisation
Every document set should have a defined purpose. An internal knowledge base must not automatically become a public source, and a team’s access to a document does not mean all its content is required for every question.
Minimisation means limiting documents, fields, excerpts and retention periods to what the service needs.
Permissions before retrieval
Access control must operate before content is retrieved and sent for generation. Filtering only the final answer leaves room for inappropriate disclosure in the context processed by the model.
In practice, retrieval must respect organisation, role, collection, embargo and other relevant rules at every layer.
Providers and data residency
The institution needs to know which entities process data, in which regions and under what retention or training conditions. The subprocessor list, data processing agreement and international transfer safeguards must reflect the actual technical flow.
Whenever a cloud service receives context, it should receive only the necessary excerpts, not a complete copy of the collection.
When to consider a DPIA
A data protection impact assessment may be required where processing presents high risk, involves sensitive data, systematic monitoring or decisions with significant effects. Even where it is not mandatory, documenting risks, measures and responsibilities improves the decision.
Operational evidence
Compliance also requires evidence: access logs, source versions, retention settings, incidents and provider changes. A written policy without a corresponding system control is not enough.
The objective is not to add GDPR compliance after the product is complete. It is to limit from the beginning what the system can retrieve, transmit, record and reveal.