What never to feed an AI: client data, the CNIL and one paragraph of prompt

You copy a client’s letter into a chat to get help with the reply. At that moment you have passed a name, an address and the contents of a conversation to a third-party company — and that is processing of personal data, with everything that follows. It is neither forbidden nor unrestricted: there are a few rules, and they fit into a single evening.

This guide is informational and covers general rules. It is not legal advice; if you process sensitive data — health, convictions, biometrics — have your case reviewed by a professional.

Why this is not an abstraction

The CNIL’s position on generative AI is simple and works in our favour: using these tools with personal data is neither forbidden nor free of obligations. It is processing under the GDPR, which means it needs a purpose, a legal basis and the minimum necessary amount of data.

One caveat worth stating up front: the CNIL’s detailed guidance is written above all for those who build AI systems. For someone who merely uses them the set of rules is markedly shorter — and that is what this guide covers.

What counts as personal data

Broader than people assume. Personal data is anything that identifies a specific person, directly or indirectly.

  • first name, surname, address, phone number, email;
  • a sole trader’s SIRET — it is tied to a natural person and their home address;
  • account number, IBAN, social security number;
  • a photograph, a voice recording;
  • text by which someone can be recognised even without a name: “the owner of the only bakery on rue de la République in Istres”.

A separate category covers data on health, origin, opinions and convictions. The bar there is higher and improvising is not advisable at all.

The minimisation rule: one paragraph instead of the whole file

The CNIL’s main recommendation for prompts is to enter only what is strictly necessary for the task. In practice: before pasting a document, ask yourself whether the model’s answer would change if you removed the names and numbers. Almost always it would not.

Bad: “Client Marie Dupont, 14 rue des Lilas, 13800 Istres, has not paid invoice FA-2026-014 for €1,240, here is the entire correspondence [12 emails]. Draft a reminder.”

Good: “A client is 45 days late on an invoice of roughly €1,200, after two polite reminders that went unanswered. Draft a third letter, firm in tone but not threatening, mentioning the statutory late-payment penalties.” The name, address and invoice number you will add yourself, in your text editor.

The second version also produces a better result: the model is not distracted by irrelevant detail.

A contract with the provider: when you genuinely need one

If you regularly process personal data through an AI service, that service becomes your processor, and you need a data processing agreement (DPA). Major providers keep one ready in their business section — you accept the terms, there is nothing to negotiate.

The practical line is this. A one-off “translate this paragraph, no names” needs no contract. A chatbot on your site talking to visitors does: the flow of personal data there is constant and you initiate it. The same goes for any service you hand your client base, your mail or your form submissions to.

Training on your data: the line is not drawn by price

First misconception to clear: a paid subscription does not take your data out of training. A personal paid plan is the same consumer product. What takes you out is not price but the type of contract: team, enterprise or API access, where the processing terms are set out separately.

The setting exists almost everywhere, but in different places. Checked on 17 August 2026:

  • ChatGPT. Settings → Data Controls, the model-improvement toggle. On every personal plan, Plus and Pro included, it is on by default. On business plans and the API, training is excluded by contract rather than by a switch.
  • Claude. Settings → privacy, the model-improvement item. Here it is the other way round: off by default, active only if you turn it on. If you do, anonymised data lives in training for up to five years.
  • Gemini. The activity page in your Google account (myactivity.google.com, Gemini section). A subscription does not change the status. Worth knowing: some conversations are read by human reviewers, and those copies are kept for up to three years — they are not deleted along with your activity.
  • Mistral. Account settings, the option to object to your inputs and outputs being used for training. In the API, data is kept for thirty days for abuse monitoring, and a zero-retention mode is available.

Menu labels change more often than the rules themselves, so search by meaning: “model improvement”, “training”, “activity”.

If searching bores you: ask the service itself

The question suits any chat:

Answer according to your service’s current terms, not from general impressions. 1) Are my conversations used to train models on my current plan? 2) Is this on by default or does it require my consent? 3) Where exactly is it switched off — give the precise path through the menus. 4) How long is my data kept after I delete a conversation and after I switch training off? 5) Give links to the official pages that state this. If you do not know something for certain, say so, do not guess.

The caveat matters more than the question: the model’s answer is a hint, not proof. Models get their own service’s rules wrong, especially if those rules changed recently. Which is why the fifth point is the valuable one: the links let you check the setting by hand and read what the terms say today rather than six months ago.

When an impact assessment becomes necessary

A formal data protection impact assessment (DPIA) is required when processing is likely to carry a high risk to people. For our readers that is rare, but three cases are worth naming: screening job candidates, processing health data and systematic monitoring — video analytics on your premises, for instance.

If you fall into one of them, that is the point where talking to a specialist costs less than working it out alone.

Risks ordinary software does not have

The CNIL separately names threats specific to AI, worth knowing even if you will not be fighting them directly:

  • extracting data from the model — under certain conditions, fragments of the training data can be pulled back out;
  • instruction injection through text (prompt injection) — a document or page you hand the model for analysis may contain a hidden command, and the model will carry it out;
  • data poisoning — corrupting the training set.

The practical conclusion: do not let the model act on a document that came from an outsider. Analysing a letter, yes. Allowing it to “do what the letter says”, no.

A chatbot on your site is a separate matter

Putting an assistant on your site creates three duties at once: a contract with the provider, an honest warning that the other side is a program, and a revision of your privacy policy along with the consent banner.

Who exactly has to declare that the bot is a bot — and why that is usually not you — is covered in our analysis of the AI Act transparency rules. For cookies, consent and the compulsory pages, see the guide “A website for a micro-entrepreneur”.

An evening's checklist

  1. Open the service’s settings and switch off training on your data — remembering that a personal paid subscription does not exempt you by itself.
  2. Build the habit: before pasting a document, strip out names, addresses and numbers — you will put them back yourself in the editor.
  3. Do not give the model instructions that came from someone else’s document.
  4. For regular working tasks, move to a plan with a contract — team, enterprise or API.
  5. If your site has or will have a chat, get the DPA from the provider and update your privacy policy.
  6. If you screen people, work with health data or run monitoring, stop and have the case reviewed separately.

Information is current as of 17 August 2026 and matches the CNIL’s recommendations and general GDPR rules, with sources linked in the text. Services change their privacy settings — check them with your provider rather than against this text. Webinkub accepts no responsibility for decisions taken on the basis of this guide.

Get in touch

Not sure whether this applies to you?

Tell me who you work with — businesses or private individuals. I’ll tell you what to do and by when.

Want your whole situation looked at?

Mentoring covers the whole path: from registration to reporting and choosing your tools.