A GDPR-safe AI document workflow for consultants, in 5 steps
The short answer. A defensible AI workflow for client documents has five steps: classify the document, pseudonymise it, review the result, work with the AI on the safe version, and translate the answer back with a key only you hold. This satisfies GDPR's data minimisation requirement, keeps your client's identifiable data out of AI vendors' systems, and takes minutes instead of the hour manual redaction costs. It is also simple enough to document once and follow daily.
Why consultants specifically
Advisory work is the worst case for casual AI use: high document volume, other people's confidential data, professional duty of confidentiality, and clients who will ask how you work with AI. Sooner or later an RFP or a DPA negotiation will contain the question "describe how you use AI with our data". A written workflow turns that question from a threat into a differentiator.
The 5-step workflow
Step 1 — Classify in three seconds. Does the document contain personal data or client-confidential information? If genuinely not (public reports, your own templates), use AI directly. Everything else goes through steps 2 to 5. When in doubt, it is not in doubt.
Step 2 — Pseudonymise. Drop the document into ShareSafe.ai. Names, companies, amounts, IBANs, addresses and identifiers become consistent placeholders. EU processing, no account, nothing stored after the run.
Step 3 — Review. Check the before and after view. Add what detection missed, especially indirect identifiers: roles in small companies, dates plus places, project names a sector insider would recognise. Thirty seconds that carry most of the safety.
Step 4 — Work with the AI. Summarise, compare, rewrite, analyse on the safe file. Consistent labels keep the document fully workable: [NAME_01] stays [NAME_01], ratios between [AMOUNT_01] and [AMOUNT_02] stay intact.
Step 5 — Translate back. The AI's output contains placeholders. Your Identity Key, generated in your session and held only by you, restores the real names locally. The key never reaches the AI vendor, and not us either.
Writing it into your processing register
GDPR Article 30 asks you to record processing activities. This workflow is easy to record because it is fixed:
- Purpose: document analysis and drafting support using AI assistants.
- Safeguard: pseudonymisation prior to any transfer to AI vendors (Art. 4(5), Art. 32), with human review; key held by the firm.
- Minimisation: no directly identifying client data is transferred (Art. 5(1)(c)).
- Retention: safe files and keys per your existing client-file retention policy; the pseudonymisation tool retains nothing.
Five lines. Compare that to documenting ad hoc raw uploads, which you cannot.
Team habits that make it stick
- Make the safe version the default artifact: store it next to the original so colleagues reuse it instead of re-uploading raw.
- One rule for juniors: no client document enters any AI tool without a receipt. The receipt is the proof the workflow ran.
- Put the workflow in your proposal boilerplate. Clients increasingly ask; answering before they ask wins trust.
- When document volume grows, the per-file routine becomes the bottleneck. That is the moment for VaultLM: vaults, team access, audit trail and safe sharing around the same principle.
FAQ
- Does this make our AI use "GDPR compliant"?
- No tool makes you compliant; compliance is about your whole processing. This workflow implements the specific obligations that AI use triggers most directly: minimisation, safeguards and accountability. Document it and you have a defensible answer.
- What about documents under NDA rather than GDPR?
- Same workflow, same logic. An NDA restricts disclosure to third parties; placeholders mean no confidential substance is disclosed. Check whether your NDA defines third-party tooling explicitly.
- How do we handle AI output in client deliverables?
- After translating back with the key, the output contains real names again and is treated like any draft you wrote yourself: reviewed by a human before it leaves the firm.
- Can we standardise this across the team?
- That is exactly the graduation path. The free tool proves the habit per person; VaultLM makes it a team workflow with shared vaults, roles and an audit trail.
ShareSafe.ai is part of VaultLM. Raw files stay in the EU. Minimal retention. You hold the key. Try it with your own document →