AI and data protection
in your business

AI becomes particularly valuable to a business when it can work with internal data and documents as well as publicly available information. This includes employee and customer data, contracts, cost calculations, project documentation, technical documents and internal expertise.

Alongside their legal data protection obligations, companies have a commercial interest in protecting this information. If unauthorised parties gain access to it, companies can suffer financial losses and competitive disadvantages. This makes it essential to know where the information is processed, which systems access it and who within the company is allowed to use it.

The IOWIS Platform provides an on-premises AI environment that can be managed centrally. Language models, internal knowledge resources, permissions and external connections can be configured to suit the intended use.

Data protection and protecting company knowledge
go hand in hand

Data protection concerns information relating to people. In day-to-day business, this can include employee records, employment contracts, job applications, customer records, contact details or information in support and project documents.

However, not all information that needs protection is personal data. The following content should also be protected against uncontrolled transfers to external services and access by unauthorised people:

  • cost calculations and quotations,
  • contracts and the status of negotiations,
  • product and development plans,
  • source code and technical documentation,
  • internal processes and work instructions,
  • customer and project information,
  • strategies, analyses and internal expertise.

This knowledge often underpins pricing, products, negotiations, technical solutions and internal decisions. If it is disclosed without authorisation, competitors may gain insight into business models and plans, negotiating positions may be weakened and contractual confidentiality obligations may be breached. The trust of customers, partners and employees can also suffer.

Introducing AI therefore requires companies to consider GDPR requirements and the protection of other confidential company information. A suitable AI environment must support both the lawful handling of personal data and controlled access to confidential company knowledge.

What matters is how data actually flows

Input, files, knowledge excerpts and chat history lead from the company environment to an external AI service. A question mark marks the transfer.

Assessing an AI solution requires more than looking at the server location or where uploaded documents are stored.

A single request can include considerably more than the text an employee types into the input field. Uploaded documents, relevant passages from internal knowledge sources and the conversation so far can also inform the answer.

Companies therefore need to examine both what employees enter and which documents, data sources and stored content the AI application draws on in the background.

With external AI services, requests and the content included in them leave the company’s environment for processing. They are sent to the provider’s systems and processed there.

Companies need to be able to identify:

  • the providers and other service providers involved,
  • where processing takes place,
  • how long data is stored and what it is used for,
  • which people and systems are authorised to access it,
  • any possible transfers to other services or third countries.

Hosting on servers in Germany or the EU can be relevant, but does not fully answer these questions. The decisive factor remains the path the data actually takes.

What changes when AI processing stays local

A user, server and knowledge in the on-premises core environment. Separate switches show web search enabled and external services disabled.

In a fully on-premises deployment of the IOWIS Platform, this entire core process takes place within your infrastructure. Inputs, supplied documents, information retrieved from internal knowledge sources and generated answers are processed there. Platform data, such as chat histories and technical logs, also remains in the local environment.

The language models and core AI processing run on hardware at your company, selected for your requirements. The company content needed for an answer is not sent to external AI or model providers.

The platform’s core functionality works without a continuous internet connection. An external connection is set up only for features explicitly intended to access external information or services. These may include web search, an external data source or a connected business system.

The platform is integrated into your existing systems and network. Your company controls which connections are allowed, which systems can communicate with each other and which features operate exclusively within your own infrastructure.

Your company can specify which features operate exclusively on-premises and which are allowed to exchange data with external systems.

Match data protection to the use case

Data protection requirements depend on the task, the data involved and the intended users. An AI assistant for technical documentation needs a different assessment from an application dealing with HR matters, customer communication or medical information.

Before introducing AI, companies should therefore establish what it will be used for, which content it needs and who will work with it.

Define the purpose and the data needed

An AI assistant should only access the information it needs for its task.

For technical questions, manuals and system documentation may be sufficient. HR files or customer data would be neither necessary nor useful for that use case.

When personal data is processed, the purpose of processing, an appropriate legal basis and any obligations to provide information must also be considered. Applications likely to involve high risks may additionally require a data protection impact assessment.

For a question about equipment maintenance, the data path leads through manuals to AI processing. Branches to HR and customer folders are blocked.

Clarify access and responsibilities

User permissions and assistant permissions meet at an AND junction leading to the available knowledge folders.

Shared access to an AI platform does not mean that all employees can use the same company information.

Documents and knowledge sources can be separated by department, task and level of confidentiality. You can also specify which users and groups are allowed to access a particular assistant or collection of knowledge.

The configuration must ensure that only content authorised for both the user and the selected AI assistant is used. Existing boundaries around responsibilities and confidentiality are preserved even when people work through a shared interface.

The more sensitive the information, the more precisely responsibilities need to be defined. This includes who may manage assistants and knowledge resources, connect data sources and approve configuration changes.

Plan external features deliberately

Web search, communication platforms and connected business applications can extend the IOWIS Platform’s features. Each integration, however, has its own data flow.

For every external feature, it should be clear which data is transferred, what purpose the connection serves and which users are allowed to use it.

This assessment is separate from the core on-premises functionality. The core functionality does not depend on an external AI service being continuously available.

How the IOWIS Platform implements your requirements

The IOWIS Platform provides the features your company needs to implement its requirements for data, access and connections through technical controls.


  • On-premises operation and network controls

    In a fully on-premises deployment, the platform, language models and core processing run on hardware within your infrastructure and are integrated into your systems and network.

    Your company can set its own technical rules to control:

    • which internal systems are accessible,
    • which external connections exist,
    • which features are allowed to access external systems,
    • which areas can be used without a continuous internet connection.

    Updates can also be supplied and installed offline.


  • Roles, permissions and user management

    Administrators can assign permissions for users, groups, assistants, files, knowledge bases, workspaces, tools and integrations.

    Knowledge can be organised separately by task, department or confidentiality level and made available to the intended user groups and assistants.

    Each request uses only content that both the user and the selected assistant are authorised to access.

    Through single sign-on and LDAP, the IOWIS Platform can connect to existing user and group structures. Access to the AI environment can therefore be integrated into your existing identity and user management.

    beatmet24 shows how this works in practice: employees can ask questions about their own employment documents without gaining access to other employees’ documents. Processing takes place on the company’s own infrastructure.


  • Retention and traceability

    Separate retention periods and deletion schedules can be set for different types of content, usage data and logs.

    Storage periods can be limited to suit the purpose, and internal retention and data protection requirements can be implemented through technical controls.

    Audit logs record relevant system activity, usage and administrative actions.

    Authorised administrators can use them to review changes to roles, assistants and knowledge resources, as well as relevant access events and configuration changes.

Use AI with internal data
while retaining control

Together, we discuss your use case and how you could process personal data and confidential company knowledge with the IOWIS Platform.

We look at the features you need, internal data sources, access permissions, storage policies, external connections and your on-premises IT environment.

Frequently asked questions about AI and data protection

  • Is AI running on-premises automatically GDPR-compliant?

  • Can the IOWIS Platform process personal and sensitive data?

  • How are chat histories, documents and other content stored and deleted?

  • Can administrators view other employees’ chats?

  • Does IOWIS have permanent access to the system or receive data from our environment?