Procedure
An AI policy that holds up in daily work
Under the Court of Justice a legal person is liable for infringements committed by any person acting in the course of its business. A ban without an approved alternative relocates the use to private accounts and removes it from view. And a policy governing conduct at work is subject to co-determination under section 87(1) no. 1 BetrVG, independently of no. 6.
A tool nobody introduced
In one business unit, proposal texts have been produced with a language model for months. The account runs on a private address, it is paid for out of petty cash, and customer data sit in the inputs. The data protection function knows nothing of it, and it does not appear in the record of processing activities.
The organisation answers for tools it does not know about
What follows from employees using tools nobody knows about is often dismissed as the private conduct of individuals. The Court of Justice decided otherwise on 5 December 2023.
Three duties follow from being a controller, and none of them can be met without knowing about the tool.
Three duties that hang on knowledge
Demonstration
Art. 5(2) GDPR requires compliance to be demonstrated. That cannot be done for processing nobody knows about.
Record
Art. 30(1) GDPR requires an entry per activity. A missing entry is, under the case law, a breach of duty in its own right.
Security
Art. 32(1) GDPR requires a level of security appropriate to the risk. The risk of an unknown service cannot be gauged.
3 von 3
A ban relocates the use rather than ending it
What a policy has to contain in order to be used turns on a single property. It has to answer the task that led to the use in the first place. A prohibition does not, and for that reason it is not an appropriate measure under Art. 24(1) GDPR either.
Two versions of the same rule
| Prohibition | Merkmal | Approval with limits |
|---|---|---|
| Not permitted | What the employee reads | These three are freeNaming the tools, the permitted classes of data and the body that assesses new tools. |
| A private accountThe task remains, so the use remains, and it leaves the area in which it would be visible. | What happens next | A known route |
| LostWithout knowledge there is no entry in the record and no demonstration under Art. 5(2) GDPR. | Ability to demonstrate | Available |
| NoneA private account has no contract under Art. 28(3) GDPR, and the inputs fall under the provider's consumer terms. | Contractual position | Settled |
The difference is not one of strictness. The second version is the stricter one, because it ties the use to conditions that can actually be met.
Five items without which a policy goes unused
Which tools are approved
By name, and with the date of the assessment. A generic entry such as “language models” gives no answer, because providers’ terms differ.
Which classes of data may go in
In the categories already used across the organisation. A classification invented for this policy alone is not learnt and therefore not applied.
What happens to the outputs
Who stands behind an output and how it is checked. Without that item the responsibility shifts onto the tool, and there is nobody there to take it on.
Who approves a new tool
With a deadline for the answer. An approval body without a deadline is the most common reason the governed route is abandoned again.
What to do after a mistake
And that reporting it carries no consequences. Without that sentence the data protection function learns of a mistake only from the data subject.
The policy is co-determined, and not only through no. 6
What participation the policy itself calls for is usually assessed against the system deployed. That is the second question. The first is that a rule governing the conduct of employees falls within co-determination under section 87(1) no. 1 BetrVG, without any need for a capacity to monitor.
Alongside it, since 2 February 2025, stands a duty of its own under Art. 4 AI Act. Deployers have to take measures to ensure, to their best extent, that their staff have a sufficient level of AI literacy. A policy without accompanying instruction does not meet that, and conversely instruction is the most effective way of making the policy known.
How we support you with the AI policy
At the outset there is a survey without sanction. It names the task rather than the breach, that is, it asks what a tool is needed for, and it announces that the tools named will be assessed. Out of the answers comes the list of tools to approve, and only out of that the policy. In that order what stands at the end is a rule reflecting a known need, rather than one prohibiting it.
Frequently asked questions
Is a ban enough?
Rarely. A ban without an approved alternative relocates the use to private devices and private accounts. It thereby disappears from the organisation's view, while the controllership remains and the demonstration required by Art. 5(2) GDPR can no longer be made.
Does the policy need the works council?
In an establishment with a works council, as a rule yes. It governs the conduct of employees at work and therefore falls under section 87(1) no. 1 BetrVG. Whether no. 6 applies alongside depends on the system deployed and not on the policy.
Is the policy a legal basis for the deployment?
No. It is a measure under Art. 24(1) GDPR and settles how work is done. The legal basis for the processing follows from Art. 6 GDPR and, for employee data, from section 26 BDSG or an agreement under Art. 88 GDPR.
How does the organisation find out which tools are in circulation?
Most quickly through a survey without sanction, coupled with an announcement that the tools named will be assessed and where possible approved. Technical analysis of network traffic does not reach private devices and would itself have to be measured against section 87(1) no. 6 BetrVG and Art. 6 GDPR.
Get in touch!
Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!
Contact usAlternatively you can request a call back.