# GDPR-Compliant AI in Luxembourg

## Who this is for
- Small businesses, NGOs, and independent professionals in Luxembourg
  using AI tools that touch personal data: customer records, CVs, support
  tickets, case files.
- Teams whose staff already use consumer chatbots at work without a
  written rule on what may go into them.
- Organizations planning a customer-facing chatbot or a document assistant.
- Anyone asked by a client, funder, or the CNPD to explain where their
  AI data goes.

## Problem
- GDPR applies to AI exactly as it applies to any other software: a
  lawful basis, data minimisation, transparency, retention limits, and
  accountability. The CNPD's thematic dossier on AI says so explicitly.
- The risk is rarely the model. It is the plumbing: consumer tools that
  train on prompts, US-hosted services with no data processing agreement,
  and assistants that index files nobody meant to keep.
- Any provider handling personal data on your behalf needs an Article 28
  contract; any data leaving the EU needs a Chapter V transfer mechanism.
  Consumer AI tiers fail both tests.
- A customer-facing chatbot sits under GDPR (where conversations go, what
  the privacy notice says, how long logs are kept) and under the AI Act's
  transparency rule at the same time.
- GDPR and the AI Act ask different questions: data protection versus
  product risk. Both are expected to be supervised by the CNPD in
  Luxembourg under Bill n°8476.

## What we do
- Map what personal data your team actually puts through AI tools today.
- Choose between three hosting routes: US-hosted SaaS (avoid for personal
  data), EU-hosted managed open-weight models under a no-training DPA
  (proportionate for most SMEs), or self-hosted open-source models (for
  sensitive data and organizations under threat).
- Set up the chosen architecture so compliance is the default: EU
  infrastructure, contracts that forbid training on your inputs,
  automatic retention, a human in the loop for decisions about people.
- Write the one-page internal AI-use note that doubles as accountability
  evidence and AI Act literacy.

## Outcomes
- An answer to "where does my data go" that you are happy to give.
- No international transfer question, because the data never leaves the EU.
- A short, current record of processing, retention rule, and AI-use note.
- A chatbot or assistant whose privacy notice and AI disclosure are in
  place from day one.
- Lower running costs than per-seat foreign SaaS after the setup is done.

## How we work
- Starts with a free 20-minute call to map what you already use.
- Fixed-scope setup; retainer only where governance genuinely needs to be
  ongoing.
- This is practical guidance and architecture work, not legal advice:
  Crystallized Intelligence is not a law firm, and we work alongside your
  lawyer when a question needs one.
- Sources: CNPD thematic dossier on AI and data protection, EDPB Opinion
  28/2024 on AI models, the EDPB ChatGPT taskforce report, Regulation (EU)
  2016/679. Regulatory content last reviewed 29 September 2026.
- See also: [EU AI Act readiness](/ai-act-luxembourg/index.md),
  [AI for NGOs](/for-ngos/index.md), [AI for SMEs](/for-smes/index.md),
  [AI in Luxembourg](/ai-in-luxembourg/index.md).

## Next step
Book a pre-discovery call to map where your data goes today and which
hosting route makes the question go away.

Canonical page: https://www.crystallized.lu/gdpr-ai-luxembourg