Skip to content
Call, +49 511 47 55 58 10
lexICT GmbH, Home

System in use

Introducing Claude deliberately

The purpose set at introduction limits every later use under Art. 5(1)(b) GDPR, and any extension has to be measured against Art. 6(4) GDPR. Every connection to a further system is a processing operation with a legal basis of its own, and the model works there with the permissions of the account under which it runs.

The assessment no longer covers today’s use

The introduction has been decided, the contract is in place, and the assessment has been done. It covered the production of text. Since then the tool has been connected to the ticket system, and a request for the HR system is on the table. Neither connection is covered by that assessment.

The purpose set at introduction limits every later use

What the introduction settles in legal terms is more than an approval. With it the purpose is set, and under Art. 5(1)(b) GDPR that purpose limits every further use.

Three consequences of setting a purpose

  1. The basis holds for that purpose

    A basis under Art. 6(1) GDPR is determined for a particular purpose. For a different one it has to be determined again.

  2. An extension has to be measured

    Art. 6(4) GDPR names five matters to be taken into account on further processing, among them the nature of the data and the consequences for the persons concerned.

  3. The record follows the purpose

    Art. 30(1) GDPR requires a record per processing activity. A tool with three purposes has three entries and not one.

3 von 3

In practice that means setting the purpose narrowly and by name at introduction and treating any extension as a matter of its own. A broadly framed purpose does not spare the second assessment but moves it into the balancing exercise, where it is harder to carry out.

Every tool connection is a processing operation of its own

What follows from a connection is rarely considered at introduction, because technically it appears as a setting. In legal terms it extends the processing by the categories of data and the persons concerned of the system connected.

What changes with a connection

Without a connectionMerkmalWith a connection
What gets enteredThe scope is bounded by the input and therefore by the person entering it.Categories of dataThe holdings of the systemThe model reads what the connected system offers, not only what someone enters.
The person enteringReachThe account of the connectionWhere it runs under a technical account with broad rights, it reaches more than the person asking.
OneLegal basisOne per systemThe purpose of the connected system is a different one from producing text.
OneEntry in the recordOne per activityArt. 30(1) GDPR. The categories of persons concerned and the recipients change with every connection.

The second row is the one that surprises in practice. A connection with broad rights cancels the effect of the access control concept, and the measure under Art. 32(1)(b) GDPR is then no longer effective.

How we support you in introducing Claude

What is needed is a table with one row per connection, and it comes into being before the first one. Each row names the system connected, the categories of data, the persons concerned, the account with its rights and the legal basis. The same table yields the entries under Art. 30(1) GDPR and the question whether an impact assessment is required. Anyone keeping it can judge a new connection in an hour, and anyone not keeping it assesses from scratch every time.

Five items per connection

Liste zu erledigender Punkte

  • The system connected, under the name it is known by in the organisation
  • The categories of data it offers, and not the ones that are needed
  • The persons concerned, that is, whose data sit there
  • The account of the connection, with its rights
  • The legal basis for the purpose of that system

Frequently asked questions

Does every new connection have to be assessed again?

The scope yes, the basis usually. A connection extends the categories of data and the persons concerned, and both determine the legal basis and the entry under Art. 30(1) GDPR. A repeat assessment is therefore shorter than the first, but it does not fall away.

With which permissions does the model work?

With those of the account under which the connection runs. Where it runs under a technical account with broad rights, it reaches more than the person asking. That is a question of the access control concept and therefore of the measures under Art. 32(1) GDPR.

Does the introduction need an impact assessment?

Frequently yes, and the answer turns on the systems connected rather than on the model. Large-scale processing of special categories under Art. 35(3)(b) GDPR arises quickly where a connection reaches personnel files or health data. The assessment has to be carried out before the processing.

What applies to stored conversations?

They are personal data in so far as they contain information about people, and they are therefore subject to storage limitation and to data subject rights. The same period applies to them as to the records they belong with, and that period belongs in the configuration rather than in an instruction.

Get in touch!

Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!

Contact us

Alternatively you can request a call back.