Anyone using an AI tool that processes personal data on their behalf — ChatGPT Team/Enterprise, Claude, a CRM with an AI feature, or a Make/n8n automation — needs a data processing agreement (DPA) under Art. 28 GDPR with the provider. Without a valid DPA the processing is unlawful and can result in fines. For brokers, law firms and agencies in the DACH region, the DPA is therefore the first check in 2026, not the last: it has to be complemented by technical measures, a US transfer review and a record of processing activities.
Short answer: do you need a DPA for AI tools?
Anyone using an AI tool that processes personal data on their behalf — for example ChatGPT Team/Enterprise, Claude, a CRM with an AI feature, or a Make/n8n automation — needs a data processing agreement (DPA) under Art. 28 GDPR with the provider. Without a valid DPA the processing is unlawful and can result in fines. For brokers, law firms and agencies in the DACH region, the DPA is therefore the first check in 2026, not the last: it has to be complemented by technical measures, a US transfer review and a record of processing activities.
What is a DPA — and when does processing on behalf apply to AI?
A DPA (in German: AVV — Auftragsverarbeitungsvertrag) is a contract between you as the controller and the AI provider as the processor. Processing on behalf exists when the provider processes personal data exclusively on your instructions — without determining purposes of its own.
Typical cases in practice:
- A broker has ChatGPT generate property listing copy from a client file.
- A law firm summarises client briefs with an LLM.
- An agency uses a Make automation that sends lead data to an AI model for enrichment.
In all three cases personal data (names, addresses, contract details, sometimes special categories) flows to an external service. As soon as that happens, a DPA is mandatory.
When you do NOT need a DPA
- You process exclusively fully anonymised data (no conclusions about individuals are possible).
- The AI tool runs purely locally (on-premise / open-source model on your own server) with no external data outflow.
- You use the tool only for general research without entering personal data.
Pseudonymisation is explicitly not enough to avoid the DPA obligation — pseudonymous data remains personal data.
The 2026 DPA checklist (13 review points)
Every DPA under Art. 28(3) GDPR must cover these points. Use the list as an acceptance protocol before you approve an AI tool:
- Subject matter and duration of the processing are stated.
- Nature and purpose of the processing are described specifically.
- Categories of data subjects and types of data are listed.
- Bound by instructions: the provider processes only on documented instructions.
- Confidentiality: the provider's staff are bound to secrecy.
- Technical and organisational measures (TOMs) under Art. 32 are described (encryption, access control).
- Sub-processors are listed, with a right of approval when they change.
- Support with data subject rights (access, erasure).
- Notification of data breaches within a defined deadline.
- Erasure or return of the data after the contract ends.
- Evidence and audit rights for you as the controller.
- No training on your data — this must be agreed explicitly (the central AI point!).
- Third-country transfer: for US providers, standard contractual clauses (SCCs) or the EU-U.S. Data Privacy Framework are in place.
If even one point is missing, the DPA has gaps — with AI tools it most often fails on point 12 (training) and point 7 (sub-processors).
The AI-specific sticking point: training on your data
The decisive difference from classic software is the question of whether your inputs ("prompts") are used for model training. With consumer versions that is often the case — with business plans it usually is not.
As of 2026, the rule of thumb is:
- OpenAI ChatGPT Team/Enterprise & API: no training on inputs, DPA available, EU data residency bookable as an option.
- Anthropic Claude (Team/Enterprise/API): no training on business data, DPA available.
- Microsoft Copilot (M365): processing within the tenant, DPA part of the Microsoft product contract.
- Google Gemini (Workspace/Vertex AI): DPA in place, data residency configurable.
- Free consumer chatbots: usually NO suitable DPA, training possible — unsuitable for professional personal data.
Rule to remember: the free version of an AI tool is almost never GDPR-compliant for processing client, customer or applicant data. Always use the business plan with a signed DPA.
Industry-specific requirements
Brokers and real estate agencies
You process creditworthiness data, proof of income and sometimes health information (accessible housing). These are subject to heightened protection duties. Practical recommendation: anonymise listing prompts (no real names/addresses) and, for CRM AI features (e.g. in a Softr portal with AI enrichment), conclude a clean DPA covering all sub-processors.
Law firms
Lawyers are additionally subject to professional confidentiality (§ 203 of the German Criminal Code). A pure GDPR DPA is not enough: the AI provider must also be bound to secrecy as a "contributing person" within the meaning of § 203(3). In practice this means: only providers with an explicit confidentiality clause and — ideally — EU data processing are suitable for client data. In 2026 many bar associations additionally recommend a documented risk assessment per tool.
Marketing and creative agencies
Agencies are frequently processors for their own clients. If you use AI tools to process client data, the AI provider becomes your sub-processor. That means: you need (a) your client's approval for the use of AI and (b) your own DPA with the AI provider whose level of protection does not fall short of your client contract.
Third-country transfers and US providers in 2026
Most leading LLM providers are based in the US. Transferring personal data there is permitted if:
- the provider is certified under the EU-U.S. Data Privacy Framework (DPF), or
- standard contractual clauses (SCCs) plus a transfer impact assessment (TIA) are in place.
In 2026, actively check whether your provider is DPF-certified (list at dataprivacyframework.gov). Alternatively, choose EU data residency — OpenAI, Anthropic (via cloud partners), Microsoft and Google now offer EU regions that significantly reduce the transfer overhead.
Six steps to legally sound AI use
- Create an inventory: which AI tools do your teams actually use? "Shadow AI" (privately used chatbots) is the biggest risk.
- Classify the data: which data flows into which tool? Personal yes/no, special categories yes/no.
- Obtain and review the DPA — using the 13-point checklist above.
- Extend your record of processing activities (RoPA) to include every AI tool.
- Write an internal policy: what may go into the tool and what may not (e.g. no real names, no health data in prompts).
- Carry out a data protection impact assessment (DPIA) where there is high risk (e.g. profiling, large volumes of sensitive data).
Good architecture reduces the effort: at Mindflows we build AI workflows in Make/n8n so that personal fields are automatically masked before the LLM call and re-identified afterwards — the provider never sees the real name.
Common mistakes that lead to fines in 2026
- Never signed a DPA, because the tool was assumed to be "just an assistant".
- Consumer plan used for customer data (training active).
- Sub-processors not reviewed — the provider quietly switches cloud provider.
- No TIA for the US transfer.
- Staff unaware: no policy, no training.
FAQ
Is a DPA alone enough for GDPR compliance?
No. The DPA is mandatory, but only one building block. You additionally need a legal basis for the processing, an up-to-date RoPA, technical measures and, where applicable, a DPIA. The DPA only governs the relationship with the provider.
Can I use ChatGPT for free with customer data if I'm careful?
That is not advisable. For the free version there is usually no suitable DPA available, and inputs can be used for training. Use ChatGPT Team/Enterprise or the API with a signed DPA.
Do I have to inform data subjects that I use AI?
Yes, as part of your information duties under Art. 13/14 GDPR. Extend your privacy notice to cover the use of AI, the providers used, the purpose and — where relevant — automated decisions under Art. 22.
What is the difference between a DPA and the EU AI Act?
The DPA governs data protection (GDPR). The EU AI Act governs the safety and admissibility of AI systems themselves. In 2026 both are relevant: for most broker, law firm and agency applications, AI Act transparency obligations apply, while high-risk classifications rarely do. Both frameworks must be met in parallel.
Who is liable if the AI provider processes data incorrectly?
In principle you are liable as the controller towards the data subjects. A clean DPA with a liability clause enables recourse against the provider, but does not release you from the duty of care in selecting one ("only processors providing sufficient guarantees").
Conclusion
In 2026 a DPA for AI tools is not a formality for brokers, law firms and agencies — it is the entry ticket to legally sound AI use. Three points are decisive: a signed DPA excluding training, a clarified third-country transfer, and a technical architecture that minimises personal data. Whoever lays this foundation can use LLMs productively without taking on fine or confidentiality risks. Mindflows helps DACH companies set up GDPR-compliant AI workflows — from tool selection to automated data masking.