Skip to content
AI training

Safe use of AI and GDPR in your company

A practical workshop after which your team knows what may and may not be put into AI tools, how to verify outputs, and how to set internal rules — so you can more easily demonstrate compliance. It is not legal advice, but a usable framework for everyday operation.

Training on the safe use of AI and GDPR for a company team
18
years in business
4 h
response for retainer clients
NIS2
cybersecurity and backups
Brno
own infrastructure
  • Response within 4 hours
    SLA for retainer clients
  • NIS2 compliance
    Cybersecurity and backups
  • IT outsourcing
    Managed service and projects
  • Brno + 50 km radius
    On-site and remote
  • 18 years in the field
    Since 2008

Quick summary

Practical training tailored to your team, after which it knows exactly what belongs in workplace AI tools and what is already a risk. Instead of general phrases, you take away specific skills for verifying outputs and setting internal guardrails, so that the company can more easily demonstrate compliance. It is part of our broader AI training for businesses.

  • What does not belong in AI — personal data, un-anonymised contracts, and sensitive know-how whose leak can cost you more than the time saved.
  • Verifying outputs — how to systematically check what AI has generated and not be caught out by hallucinations that look convincing.
  • Internal rules and permissions — who may use which tool, what to copy where, and how to separate public services from those where data stays under control.
  • Demonstrability of compliance — we set up record-keeping so that in an audit or incident you can show the rules and records, instead of a complex reconstruction of what happened.

What you will learn in the training

We go through model situations on your real data and documents. We explain the difference between ordinary operational data and sensitive data, including borderline cases where a single copied sentence changes the risk category. We show how to recognise when a tool may send data outside the EU or use it to train models — and how to verify this before you let it into the company.

We set up a simple framework that determines what employees may put into public AI services and what belongs solely in internal or locally operated tools. We teach your team to verify outputs through cross-checking and basic validation procedures, so they understand the results and do not rely on them blindly. Together we also build clear record-keeping and an internal directive that addresses access rights, the approval of new tools, and the recording of incidents. This is not a legal analysis, but a practical signpost with which you can more easily demonstrate that you are addressing the risks.

Who the training is for

We build the training for three levels that must pull together — management, who approve the tools and bear the responsibility; administration, sales, and HR, who work daily with personal data and contracts; and the IT team, who are meant to watch the deployed services and keep the rules technically enforceable. We adapt the level of explanation and the practical exercises to the audience — we do not run a universal scenario, but what you are dealing with.

How the training runs

No generic lecture along the lines of „AI is great, but watch out for personal data". We prepare a workshop built on your documents, real working procedures, and the tools you already use or are considering. We can come to you, run it in our lab in Brno-Židenice, or online — we adapt the format to what suits you. The concrete output is a set of usable internal rules and a practical checklist that will guide your team in everyday operation.

Why ITHOPE

  • Practitioners, not just trainers — we really do deploy AI, test it in live operation, and know its weaknesses first-hand, not from someone else’s slides.
  • Reach into IT security — we make a living managing servers, backups, and data recovery, so we cannot ignore the risks of a leak or badly set permissions.
  • Our own infrastructure — when the cloud is not enough for sensitive data, we can follow up with AI deployment on infrastructure under your control, without sending anything out.
  • One partner for several layers — you handle IT, cybersecurity, and AI with us, without having to assemble a mosaic from several suppliers.

Arrange a consultation

We will arrange a no-obligation consultation where we talk about how you really use AI and where you perceive the greatest risks. Send us ideally the departments involved and a few typical situations you are dealing with — we will save time and can show straight away how AI training for businesses would look tailored to your operation.

FAQ

Frequently asked questions

What must not be entered into public AI tools like ChatGPT?
Generally, personal data, un-anonymised contracts, access credentials, and sensitive know-how do not belong there — with many public services you have no certainty about where the data flows and whether the operator will use it further. In the training we go through specific borderline cases from your operation.
Do we break GDPR if employees use AI?
It depends on what data they enter, into which tool, and where it is processed. Using AI itself is not prohibited. The key is clear internal rules and suitable tools. We show how to set them so you can more easily demonstrate compliance — but it is not legal advice.
How do we tell whether an AI tool sends data outside the EU?
It follows from the service terms, the location of the servers, and the account settings, which tend to be unclear. In the training we show where to look for this information and how to verify it before you let the tool into the company. For sensitive data we recommend an option under your control.
Is this training legal advice on GDPR?
No. We are practitioners in IT and AI, not lawyers. We give you a usable technical and procedural signpost — what belongs where, how to set rules and records. For a binding legal interpretation of a specific situation, we recommend a consultation with your lawyer or data protection officer.
How do we verify that an AI output is correct?
We teach cross-checking and basic validation procedures: verify facts against the source, watch for confidently sounding hallucinations, and for important outputs always include a human review. The aim is for the team to understand AI and not rely on it blindly, especially for sensitive decisions.
Do we get internal rules for working with AI after the training?
Yes, if that is the goal. Together we build a clear directive and a checklist — who may use which tool, what to copy where, and how to record an incident. We split the rules by data sensitivity so that they are understandable and observable in practice.
What if the public cloud is not enough for our data?
Then it makes sense to address a local or controlled deployment, where sensitive information does not leave the company. We operate our own infrastructure and can follow up the training straight away with AI deployment under your control. But we always assess fairly whether you need it in your case.
Call Contact