Key Takeaways
- Data protection is the biggest AI hurdle: 77 percent name it, ahead of skills shortage (70 percent) and cost (58 percent).
- Two guardrails, not a roadblock: Data protection and data security belong along the sides of the road - not across it.
- No anticipatory obedience: Where no personal data is processed, data protection law is not even engaged.
- Five criteria to check: A data processing agreement, a selectable EU region, an opt-out from model training, proper administration with single sign-on and logs, and a realistic cost case.
- Business accounts, not consumer accounts: In free and entry-level tiers, training on your data is often switched on by default.
- Concrete alternatives: Langdock from Berlin, Microsoft Copilot with data in Frankfurt, AWS Bedrock, ChatGPT Enterprise and smaller models running locally.
AI did not start with ChatGPT
The concept goes back to Ada Lovelace in 1843. The term artificial intelligence was coined in 1956 at the Dartmouth conference. Then came two AI winters, for two reasons: the hardware was not there - hard drives of five megabytes filled rooms - and the interface was strictly for specialists. Amber terminal screens are not how you get an organisation to adopt anything. What changed with ChatGPT was not primarily the intelligence. It was the door handle.
Data protection and data security: two guardrails
The GDPR matters, and much of it makes genuine sense. But I like to start one step earlier. If the content on your website is public and contains no personal data, data protection law is simply not engaged. Please do not be the data protection officer who lays the guardrail across the road. There are two guardrails: one for data protection and one for data security. Both belong along the sides. What I often see is data protection placed crossways and data security missing entirely - so you get blocked in the middle and can still drive off the edge.
The numbers back the frustration: 77 percent name data protection as the largest obstacle to AI, ahead of the skills shortage at 70 percent and cost at 58 percent. A good part of that is anticipatory obedience. When someone says we are not allowed to because of data protection, my first question is whether personal data is involved at all. Often the answer is no.
Where the risk actually sits: consumer versions
With free tiers you frequently pay with data instead of money, and the training opt-in is set by default. Even business tiers deserve a second look: with some providers the strongest model is only available if you allow your data to be used for training, particularly on free or entry-level plans. On the higher business and enterprise tiers you can genuinely prevent it. Alongside that, a data processing agreement is mandatory - most providers now offer it for download.
Five criteria for a GDPR-compliant AI tool
One: is there a data processing agreement? If I cannot find one, the tool is out for business use. Two: can I select an EU region? Three: can I exclude training on my data - and is that setting on by default? Four: is there real administration, with single sign-on, role management and logs? That is data security more than data protection, but both belong in the decision. Five: does the cost case hold up? Thirty minutes saved per week per person is a realistic threshold. And do not rely on yesterday knowledge: terms and systems change constantly in this field.
Alternative: Langdock from Berlin
Langdock is a Berlin company that runs the leading models on European servers, typically hosted on AWS in Europe. The decisive point is corporate structure: as a German company, Langdock has no US parent that could be compelled under the Patriot Act. The interface is close to what people know from ChatGPT, agents are easy to build, there are good templates and automations - and you can tell the system prompt was written for business use. The output is dry in the best sense.
Microsoft Copilot as an alternative
Copilot has the advantage that your data is already there. Storage is in Frankfurt and AI processing runs in Ireland at the furthest. The residual risk is that Microsoft is a US company - which is exactly where Langdock differs. If you do not use Microsoft 365 for whatever reason, Langdock is my first suggestion.
Further options: AWS Bedrock and local models
ChatGPT is available as a Team and Enterprise product, and companies such as Moderna have even deployed it on premise. Claude can be run through AWS Bedrock in Frankfurt, which gives you a European hosting layer at the price of not always having the newest model and a small cost premium. Frontier models like the largest ChatGPT or Claude versions are currently too big to run locally, but smaller models are already capable and local-ready. A sensible combination for many companies: a frontier model for demanding work, Copilot for context across your own data, and Langdock or a local model for highly confidential material.
Mentioned Tools & Resources
- Langdock - Berlin provider running leading models on European servers. German company with no US parent, including agents and automations.
- Microsoft Copilot - works on data already in Microsoft 365. Storage in Frankfurt, AI processing in Ireland at the furthest.
- AWS Bedrock - run models such as Claude from data centres in Frankfurt. Slightly older model versions and a small cost premium.
- ChatGPT Enterprise - enterprise tier with extended data protection options, in some cases deployable on premise.
- Data processing agreement - mandatory document, available for download from most providers.
- Bitkom SME study 2026 - source of the figures on data protection, skills shortage and cost as AI obstacles.
Frequently Asked Questions
What does GDPR-compliant AI use actually mean?
That responsibilities, legal basis and data flows are settled: a data processing agreement with the provider, a known server location, no model training on your data, and administration you can audit.
Which criteria should I check in an AI tool?
Five: is there a data processing agreement? Can I select an EU region? Can training on my data be excluded? Is there administration with single sign-on and logs? And does the benefit realistically outweigh the risk?
Does the server have to be in the EU for GDPR compliance?
No. You can work in a GDPR-compliant way outside the EU as long as the provider follows European rules. An EU location simplifies matters considerably, as does a European corporate structure without a US parent.
Why are consumer versions of AI tools risky?
Because you often pay with data rather than money. In free and entry-level tiers, using your input for model training is frequently preset and has to be switched off deliberately.
Is Langdock a real alternative to ChatGPT?
For many companies, yes. Langdock is a German company running the leading models on European servers, with a familiar interface, agents and automations - and no US parent company.
Can AI models run locally inside a company?
The large frontier models are currently too big for that. Smaller models are already capable and can run locally - most useful as a component alongside a strong frontier model for uncritical tasks.
Conclusion
Data protection is solvable. Use business contracts instead of consumer accounts, check the five criteria, and pay attention not only to the server location but to the corporate structure behind the provider. In the end the tool that wins is the one that is approved and actually used. If you want to shorten the evaluation and need professional guidance up to extended CIO support, feel free to get in touch.




