Privacy & Law
AI use your data protection officer can approve.
This page is written for data protection officers, compliance and legal teams. No superlatives, just the articles that matter.
CLOUD Act and GDPR
Two legal systems, one contradiction.
US CLOUD Act (2018)
- US authorities may require US companies to disclose stored data.
- This applies regardless of where the data is physically stored.
- No judicial review by EU standards is required.
- It affects OpenAI®, Google®, Microsoft®, Anthropic®, AWS® and other US providers.
EU GDPR
- Transferring personal data to a third country requires a legal basis.
- The CJEU’s Schrems II ruling invalidated the Privacy Shield.
- The EU-US Data Privacy Framework only applies to certified companies.
- Art. 48 GDPR prohibits disclosure without a mutual legal assistance treaty.
Why an EU data centre alone is not enough
Many organisations book AI models via AWS® Bedrock or Microsoft® Azure® in a European data centre. Physically, the data never leaves the EU. But the CLOUD Act applies based on where the company is headquartered. AWS® belongs to Amazon®, Azure® to Microsoft®, both based in the US. This has been confirmed by the European Data Protection Board and the CJEU’s Schrems II ruling.
With Anonix, the AI provider, whether direct or via an EU data centre, only receives placeholders. The mapping to the original data never leaves your side. Even under a disclosure order, the text held by the provider contains no personal data in plain text.
The CLOUD Act, GDPR and AI in detail: read the whitepaper → (opens in a new tab)
US group · subject to the CLOUD Act
Data centre Frankfurt · EU
- Ingrid Bergmann · housing benefit[PERSON_1] · housing benefit
- DE89 3704 0044 0532 0130 00[IBAN_1]
- Thomas Weber · type 2 diabetes[PERSON_2] · [DIAGNOSIS_1]
- TechVision GmbH · EUR 4.2 m[ORG_1] · [AMOUNT_1]
US authority
Disclosure order
1.2bn €
Meta®, 2023, for third-country transfers
530m €
TikTok, 2025, for unlawful data transfers
45m €
highest fine in Germany (Vodafone, 2025)
4%
of worldwide annual turnover as the GDPR maximum
Sources: DLA Piper GDPR Fines Survey 2025, supervisory authority announcements, Art. 83 GDPR
An honest classification
Pseudonymisation or anonymisation?
Technically
Anonix performs pseudonymisation within the meaning of Art. 4(5) GDPR. Data is replaced so that it can no longer be attributed to a person without additional information. That additional information, the mapping, only exists in memory during processing.
From the AI provider’s perspective
The AI provider never receives the mapping. For the provider, the data is effectively anonymous. We phrase this precisely on purpose, because this is exactly the distinction your data protection officer will examine.
Whitepaper
US AI and data protection.All in 26 pages.
How your organisation can use ChatGPT®, Claude® and Gemini® without giving away personal data. Prepared for management, data protection officers and IT.
- CLOUD Act and GDPR: why an EU data centre alone is not enough
- Practical examples from 12 industries, from public administration to software
- Architecture, pricing and sample calculations
- Compliance check under the GDPR, the EU AI Act and industry law
PDF, 26 pages, 1.3 MBDeutsche Version (opens in a new tab)
GDPR mapping
The technical measures, article by article.
- Art. 5(1)(c)Data minimisationOnly placeholders reach the AI provider. Personal data is reduced to the technically necessary minimum.
- Art. 25Data protection by designPseudonymisation precedes every AI call. Unprotected use through the proxy is not possible.
- Art. 28ProcessorsThe AI provider receives no personal data in plain text. The requirements for this processor are significantly reduced.
- Art. 30Records of processing activitiesComplete audit log of all requests, exportable as CSV.
- Art. 32Security of processingAES-256-GCM encryption, Argon2id password hashing, two-factor authentication and isolated tenant databases.
EU AI Act
Not a high-risk system.
Anonix is a data minimisation tool and does not fall into any high-risk category under Regulation (EU) 2024/1689. It makes no automated decisions about people, creates no profiles and affects no rights. Rather, it reduces the risks posed by the actual AI models.
Industry regulation
What applies to your industry.
| Regulation | Industry | How Anonix helps |
|---|---|---|
| § 203 StGB | Lawyers, tax advisers, doctors | Professional secrecy is preserved because no client or patient data is transmitted. |
| DORA (EU 2022/2554) | Banks, insurers | ICT risk management through controlled, logged AI use. |
| State data protection laws | Public administration | Citizen data is replaced before any external processing. |
| SGB (social data protection) | Social services, youth welfare | Social data is pseudonymised before external processing. |
Security architecture
Security at every level.
AES-256-GCM
Encryption of all stored API keys
Argon2id
State-of-the-art password hashing
Isolated tenants
Separate database per tenant
TOTP
Two-factor authentication
Rate limiting & CSRF
Protection against abuse and forged requests
Audit logging
Structured, complete logging
EU hosting
Operated exclusively on EU infrastructure
No stored mapping
Placeholder mapping only in memory
Note: this page does not constitute legal advice. We are happy to provide your data protection officer with technical documentation for review.
Let’s talk abouthow you useAI.
In a short conversation we show you how Anonix fits your organisation: which providers, which data, which rules. No obligation.
