Using AI with customer data without breaking the law

Pasting a contract, a payslip or a customer list into an AI chat is personal data processing. What the GDPR requires in Spain and Ley 21.719 in Chile, and how to do it properly without giving up the tool.
· AI and data compliance
The scene repeats in almost every office: somebody pastes a contract, a payslip or a customer list into an artificial intelligence chat to have it summarised. Nobody does it with bad intent and almost nobody knows they have just done something with a legal name: a disclosure of personal data to a third party, often outside the country.
This article is not about banning AI. It is about using it without that turning expensive one day.
What the law says, in short
In Spain
The GDPR and the Spanish data protection act apply as soon as the data allows a person to be identified. What they require here is concrete: a legal basis for the processing, a processor agreement with the provider (art. 28), a record of the processing in the record of activities (art. 30) and, if the processing is high risk, a data protection impact assessment (art. 35). If the provider is outside the European Economic Area, safeguards for the international transfer are needed as well.
On top of that comes the Regulation (EU) 2024/1689 on artificial intelligence, which adds transparency obligations: you have to tell a person when they are talking to a machine and when content has been generated with AI. With one important exception for publishers: art. 50.4 exempts text from labelling where there is human review and somebody assumes editorial responsibility.
In Chile
Ley 21.719 replaces the old Ley 19.628 and brings a framework very close to the European one: lawful bases, data subject rights, a record of processing activities, an impact assessment for risky processing, breach notification and a body with power to impose penalties. Its entry into force is gradual, with full effect expected in December 2026, so the moment to put it in order is now and not when the penalties start.
What to do, in practice
1. Pseudonymise before sending, not afterwards
The step that resolves 90 % of the problem: strip the name, the tax number, the address and the account number out of the document on your own machine, before anything goes out to the internet. A document without identifiers still works for the AI to summarise, and it is no longer personal data travelling.
2. Choose a provider on the contract, not on the price
What to check in writing: that it does not train its models on what you send, how long it keeps conversations, where the servers are and whether it offers a processor agreement. A consumer plan almost never brings that; the business plan of the same product often does.
3. Write down who can use what
One sheet, not a manual: which tools are approved, what kind of information never leaves — customer documentation, health data, credentials — and who to ask in case of doubt. Without that sheet, each person decides on their own and you find out afterwards.
4. Leave the final decision with a person
This is the rule that is not negotiable when third-party data is involved: the output of an AI tool with tax, accounting, employment or legal effect is a draft. A professional reviews and signs it before it is filed in anybody's name. Besides being the right thing to do, it is what sustains the labelling exemption of art. 50.4.
The mistake that costs the most
It is not using AI. It is using it without being able to show how. When the authority asks, what it asks for is paper: the record of activities, the contract with the provider, the impact assessment if one was due. A company doing everything right but with nothing documented is, facing an inspection, in the same position as one doing nothing.
If this sounds like you
Putting it in order is not a project of months: it is inventorying which tools are used, pseudonymising whatever goes out, reviewing the providers' contracts and writing down the record and the internal policy. That is exactly AI and data protection compliance. And if you also want the team to learn to use these tools without slipping up, that goes separately: AI training for the team.
We are Mindset & Code: automation, data and development for small businesses. We build these systems with the processing record and the data processing agreement in place from the start, which is exactly what gets forgotten when only the model is looked at. You can see what we do and what it costs.
Sources: Regulation (EU) 2016/679, GDPR; Regulation (EU) 2024/1689 on artificial intelligence; Spanish Data Protection Agency; Ley 21.719 of Chile. General guidance; it does not replace legal advice.