LEVEL 2 · THE AI-POWERED AGENCY PLAYBOOK

AI, client data and GDPR: the agency #Rulebook

Which data can go into which AI, what GDPR requires when an agency uses AI on client work, what the EU AI Act asks of you since 2025 and 2026, and when a local model is the right answer. With a data traffic light and a contract clause generator you can use today.

✓ Reviewed Oct 5, 202618 min readNot legal advice

The client data traffic light

SHORT ANSWER

Green data (public, already published) can go into any AI. Amber data (unpublished campaigns, client strategy, internal numbers) only into business AI plans with no training and a DPA. Red data (customer personal data, credentials, special category data, anything under NDA without client consent) only into a local model or not into AI at all.

TOOLClick a data type to see where it may go. Print it and pin it next to the coffee machine.

What can go where?

LightTypical dataAllowed in
GREENPublished posts, public websites, public competitor content, generic briefs without namesAny AI, including free plans (still keep training off where you can)
AMBERUnpublished campaigns, strategies, analytics exports, internal reports, client brand books, meeting notesBusiness AI plans with no training on your data and a signed or incorporated DPA, used through company accounts
REDCustomer lists, DMs and comments with names, e-mail addresses, health or financial data, passwords and API keys, anything under NDA the client has not cleared for AIA local model on agency hardware, a specially approved setup, or no AI at all. Passwords never.

Does AI train on what we paste in?

SHORT ANSWER

On consumer plans, often yes by default unless you switch it off. On business plans from the major vendors, no: ChatGPT Business and Enterprise, Claude Team and Enterprise, Gemini in Google Workspace and Microsoft 365 Copilot all exclude customer content from model training by their terms.

PlanUsed for training?Good to know
ChatGPT Free, Plus, ProYes by default, can be switched offSetting "Improve the model for everyone" in Data controls
ChatGPT Business, Enterprise, APINo by defaultDPA available; EU data residency for Enterprise and API
Claude Free, Pro, MaxYour choice since Aug 2025; the option was presented switched onRetention up to 5 years if training is allowed, 30 days if not
Claude Team, Enterprise, APINo, by commercial termsDPA incorporated into the terms
Gemini app (consumer)Yes while activity is kept (default)A sample of chats may be read by human reviewers
Gemini in Google WorkspaceNoNot reviewed by humans; Workspace data protections apply
Microsoft 365 CopilotNoWithin the EU Data Boundary (with stated exceptions)

Sources checked Oct 5, 2026: OpenAI enterprise privacy, OpenAI data controls FAQ, Anthropic consumer terms update, Anthropic commercial terms, Gemini Apps privacy hub, Gemini for Workspace FAQ, Microsoft 365 Copilot privacy.

The lesson for agencies is simple: the brand of the AI matters less than the plan. A personal ChatGPT Plus account used for client work is the single most common data leak we see in agencies, and it is entirely avoidable.

For a practical list of what never belongs in an AI chat, read What your social media team should never paste into an AI chat.

GDPR: who is responsible for what?

SHORT ANSWER

When an agency handles personal data for a client, the client is usually the controller and the agency is its processor. An AI vendor you use on that work becomes your sub-processor. You need a DPA with the AI vendor, and under Article 28 GDPR the client must authorise sub-processors, which is why your client contract should mention AI.

The chain, step by step

  1. Client (controller) decides why personal data is processed, for example comments and DMs from its customers.
  2. Agency (processor) handles that data on the client's instructions under a processing agreement.
  3. AI vendor (sub-processor) processes the data when your team uses AI on it. That requires a DPA with the vendor and the client's general or specific authorisation of sub-processors.

A consumer AI plan breaks this chain: the vendor typically acts as an independent controller of chat data and there is no DPA. That is the legal reason behind the amber and red lights above.

What European regulators have said

The European Data Protection Board's Opinion 28/2024 says that whether an AI model is "anonymous" must be assessed case by case, and that a model developed in breach of GDPR can affect the lawfulness of using it. Practical consequence for agencies: choose established vendors that document how their models were built and give you contractual guarantees, rather than unknown tools with no paperwork.

Source: EDPB Opinion 28/2024 (PDF) ↗

TOOLGenerates a starting draft in your browser. Have your lawyer review it before use.

AI clause for client contracts

Most agency contracts were written before AI. This generator drafts a transparent clause that tells the client which AI tools you use, for what, and under which safeguards.

Is US-based AI legal under GDPR?

SHORT ANSWER

Yes, with the right safeguards. Transfers to US vendors certified under the EU-US Data Privacy Framework are currently lawful. The EU General Court upheld the framework in September 2025; an appeal is pending at the Court of Justice, so keep an eye on it and prefer vendors that also offer EU data residency or standard contractual clauses.

EU data residency options as of October 2026: OpenAI offers it for ChatGPT Enterprise, Edu and the API; Anthropic's Claude is available in EU regions through cloud providers such as AWS Bedrock and Google Vertex AI; Google Workspace and Microsoft 365 apply their own data region and EU Data Boundary commitments. For red data, a local model removes the transfer question entirely.

Sources: OpenAI EU data residency, Claude regional compliance, WilmerHale on the DPF appeal.

What does the EU AI Act require from agencies?

SHORT ANSWER

Two obligations matter for most agencies today. Since February 2, 2025, organisations using AI must take measures to support AI literacy among staff (Article 4, softened in 2026 by the Digital Omnibus). Since August 2, 2026, the transparency rules of Article 50 apply, including disclosure of deepfakes and of AI-generated text published to inform the public on matters of public interest.

AI literacy (Article 4)

The AI Act treats any company using AI professionally as a "deployer". The Digital Omnibus, Regulation (EU) 2026/1744, in force since July 27, 2026, changed the wording: deployers must now take measures to support the development of AI literacy, rather than guarantee a sufficient level. In practice: train your people, document it, and keep the record. Working through this playbook with your team and ticking the checklists is a reasonable start for that record.

Transparency (Article 50)

From August 2, 2026, image, audio or video content that is a deepfake must be disclosed as artificially generated or manipulated, and AI-generated text published to inform the public on matters of public interest must be disclosed unless it went through human editorial review. For agencies the practical rules are: label photorealistic AI people, places and events; never publish synthetic people as if they were real customers or employees; and keep human review in your approval workflow. Platforms add their own labelling rules on top, see Reach Myths.

High-risk AI

Typical agency use (content, reporting, research) is not high-risk under the Act. Deadlines for high-risk systems were moved by the Omnibus to December 2, 2027 and August 2, 2028.

Sources: AI Act Explorer: Digital Omnibus, White & Case: AI Omnibus enters into force.

When should an agency use a local model?

SHORT ANSWER

Use a local model when the data is red: customer lists, private messages, health or financial details, or material under strict NDA. Open-weight models in the 20 to 30 billion parameter range now run on a well-equipped laptop or office Mac, and nothing you type ever leaves the device.

TOOLS

LM Studio and Ollama download and run open-weight models with a few clicks. Both can act as an MCP host, so a local model can still use your tools.

MODELS

Popular open-weight families in 2026 include OpenAI's gpt-oss, Google's Gemma, Alibaba's Qwen, Mistral and Meta's Llama. Pick one that handles your client languages well.

HARDWARE

About 16 GB of memory runs a 20B model; 32 GB runs most 24 to 32B models comfortably; 64 GB and more opens the 70B class.

Be honest about the trade-off: local models are good at summarising, classifying, anonymising and drafting, but still behind frontier models on complex reasoning and polished copy. A smart pattern is to use a local model to strip personal data from a red file, then send the anonymised amber version to your business AI.

Hardware and model sizes based on published model files as of September 2026; actual performance depends on quantisation and workload.

A one-page AI policy for your team

1. We use only company-approved AI tools on business plans. No personal accounts for client work.

2. We follow the data traffic light: green anywhere, amber only in approved business tools, red only locally or not at all.

3. Passwords, API keys and payment data never go into any AI.

4. A person reviews everything AI produces before it reaches a client or the public.

5. We label photorealistic AI-generated people, places and events.

6. AI agents connect to our tools only through official integrations with OAuth, and create drafts, not live posts.

7. We tell clients which AI tools we use and why, in our contracts.

8. When unsure, we ask the AI champion before we paste.

Level 2 checklist

Run your agency from the #AI you already use

ZoomSphere MCP connects Claude, ChatGPT and other AI assistants to your publishing calendar. Drafts by default, human approval always, and you pay only per published post.

This playbook is general guidance, not legal advice. Laws, vendor terms and prices change; every page shows its last review date and every change is logged in the changelog on the playbook home. Spotted something outdated? Write to podpora@zoomsphere.com.