For the people who have to say yes or no: DPOs, legal counsel and works councils. What GDPR actually requires when AI enters the workplace — and how to enable adoption instead of just blocking it.
When AI tools arrive in the workplace, data protection officers and works councils end up in an impossible position: approve something they can't fully assess, or block it and watch it happen anyway — in the shadows, without contracts, without controls, without any of the safeguards a proper review would have secured.
The way out is competence, not caution. GDPR does not prohibit AI — it sets conditions: a valid legal basis, transparency, purpose limitation, data minimisation, answers to the hard questions about retention and deletion when personal data has flowed through a model or a vendor's logs. Those conditions are workable — if you know where the real friction points are and what good vendor terms look like.
This workshop gives privacy and employee-representation professionals exactly that working knowledge: concrete enough to review a DPA line by line, practical enough to turn the works council from a late-stage veto into an early-stage design partner.
Where personal data actually flows in AI systems — prompts, logs, embeddings, fine-tuning — and which processing operations you're really approving.
Legitimate interest vs. consent in workplace AI, information duties, and the automated-decision boundaries of Article 22.
When a data protection impact assessment is required for AI, and how to run one that produces decisions instead of paperwork — with a template we fill in against a real tool.
DPAs, sub-processor chains, international transfers, "we may use your data to improve our services" clauses — what to accept, negotiate, or refuse.
What deletion means when data has entered logs, backups, embeddings or training sets — honest technical limits and defensible positions.
The works council's role in AI adoption: information rights, framework agreements (Rahmen-BV), and how early involvement speeds adoption up rather than slowing it down.
No. Before every workshop we run a 30-minute briefing call and tailor examples, exercises and depth to your industry, your stack and your team's starting point. The agenda above is the frame — the content inside it is yours.
Pricing depends on group size, location and how much customisation your context needs. We'll give you a fixed quote after the briefing call — no surprises, no hidden day rates.
Both work. On-site tends to be stronger for group discussion and hands-on exercises; remote splits well into two half-sessions. We run workshops across Europe in English or German.
GDPR content applies EU-wide. The co-determination module is built on German works-constitution law (BetrVG) but adapts to Austrian and other European frameworks — tell us your jurisdiction in the briefing call.
A free 30-minute get-to-know call — we look at your situation, confirm this is the right format and find out if it’s a fit. No pitch, no commitment.
Book a Free Call →Prefer to write it down first? Tell us about your team and what you're working on — we'll get back to you within 24 hours.