According to Wolters Kluwer, 54% of Danish SMEs name data security as a barrier to taking up new technology. Most readers recognise that number. You know the rules exist. You are just not sure what they mean when someone proposes letting a language model read your case files.
Here is a practical answer. It is not legal advice. It does not replace a conversation with whoever carries the responsibility at your end.
The short answer
Yes, usually. GDPR does not forbid the processing. It sets conditions on how you do it. The conditions are the same in a spreadsheet, a CRM and a language model.
What changes is not the rules. It is that data can flow to a third party you did not choose. And it becomes harder to explain what happened along the way.
The five things that must be in place
- A legal basis. You need a reason to process the data that holds. For most office work it is a contract with a client or a legitimate interest. You decide that, not your supplier. And it is decided before, not after.
- A data processing agreement. Anyone processing data on your behalf needs one. That includes us and the sub-processors we use. The agreement says what is processed, why, for how long and who has access. We sign it before we touch data. Not as a formality. As a condition of building anything at all.
- Data minimisation. The workflow gets only what the task needs. A workflow that extracts fields from a lease needs the lease. It does not need the client database. The less data in play, the less can go wrong.
- Processing and hosting in the EU. It is not a legal requirement in every case. But it removes a whole category of questions about transfers to third countries. And it is what Danish firms ask about first.
- Traceability. You must be able to see what was sent where. It is also the log you need if a data subject asks for access. A system where nobody can say what happened on Tuesday is a system nobody dares use.
Whether your data is used for training
It is the question we hear most. The answer depends entirely on the agreement with whoever provides the model.
On business agreements the standard today is that API data is not used for training. But that is an agreement, not a law of nature. Get it in writing. Do not take anyone's word for it. Not ours either.
The EU AI Act
The regulation applies in phases. Ordinary office automations are not in the high-risk category: extracting fields from an invoice, sorting an inbox, drafting a quote. But a firm that uses an AI system still has duties. You must know which systems you use and what they do.
The practical advice is dull, and it works. Make a list of the AI systems you use. What they are. Which data they touch. Who owns them at your end. That list is the foundation under everything else. It takes a morning.
The one honest thing
We do not write that a solution is "fully GDPR compliant". A supplier cannot declare that on your behalf. It depends on your legal basis, your data, your retention and your own routines. We do not own those.
Any supplier promising you full compliance on your behalf has either not read the regulation or is counting on you not having read it.
Our half is EU processing, a data processing agreement, data minimisation, logging and documentation of what happens where. The other half is a conversation with the person responsible at your end. We join it gladly. It is usually the one that makes the rest possible.
Contracts and invoices are the clearest example. But the five things cover the other work that repeats: calls you do not reach, the inbox, quotes, typing between systems, follow-up, invoicing and reminders, reports. Tell us what repeats. Then we find what saves the most.
The next step
Anonymised documents are enough for our audit. You tell us what repeats. We map it for free and write it down within a week: hours, kroner, where to start, and one fixed price — or an honest no. It takes at most 3 hours of your time.
Tell us what repeats.
We map the work and put hours, kroner and one place to start in writing. Free, because nobody can price an automation before seeing the work.
