For legal teams

Say yes to AI, and keep your confidentiality commitments.

Non-disclosure agreements, tenders, client files, professional secrecy: a text pasted into an AI can breach a commitment without anyone deciding it. Here: the texts article by article, an example charter to adapt, what a clause can cover, and the path to follow when something has left.

Wide line drawing: a man holding a shield marked with a padlock stands upright among his colleagues — a woman with a tablet, a woman and a man at their laptops; documents follow clear arrows, and a sword lies set aside on a closed cabinet.

Who answers

The organisation answers. Everyone acts on its instructions.

What the texts say, in four lines — each with its article.

The organisation

As controller, it puts appropriate measures in place — data protection policies among them, where proportionate — and must be able to show that its processing complies.

GDPR, article 24

The data protection officer

Informs, advises, monitors compliance, raises awareness and trains the staff. The DPO is not personally responsible when the organisation fails to comply.

GDPR, article 39 · CNIL

Each person

Handles the organisation’s personal data only on its instructions. The charter is where those instructions are written down — the document that shows they were given.

GDPR, articles 29 and 32(4)

AI literacy

Since 2 February 2025, an organisation that uses AI systems takes measures to support its staff’s AI literacy. No certificate is required.

AI Act, article 4, as amended in 2026

The texts, article by article

What each article says, in plain words — a summary: only the text published in the Official Journal of the European Union is authentic.

GDPR, article 24 — the controller’s responsibility

The organisation puts appropriate technical and organisational measures in place — data protection policies among them, where proportionate — and must be able to demonstrate that its processing complies.

GDPR, article 29 — processing under the controller’s authority

Anyone acting under the organisation’s authority who has access to personal data processes it only on the organisation’s instructions, unless the law requires otherwise.

GDPR, article 32 — security of processing

Security appropriate to the risk; and, in paragraph 4, the organisation makes sure that the people acting under its authority process personal data only on its instructions.

GDPR, article 33 — notifying the authority of a breach

A personal data breach is notified to the supervisory authority without undue delay and, where feasible, within 72 hours, unless it is unlikely to result in a risk to people; every breach is documented.

GDPR, article 34 — informing the people concerned

When a breach is likely to result in a high risk to people, they are told without undue delay, in clear and plain language.

GDPR, article 39 — the DPO’s tasks

Inform and advise the organisation and its staff, monitor compliance — awareness-raising and training included —, advise on impact assessments, cooperate with the supervisory authority.

AI Act, article 4 — AI literacy

Providers and deployers of AI systems take measures to support the AI literacy of their staff and of the other people who operate or use AI systems on their behalf, taking into account their knowledge, experience, education and training, and the context of use. This is the wording of Regulation (EU) 2026/1744 (the Digital Omnibus on AI, article 1, point 5), in force since 27 July 2026; the text adopted in 2024 asked for measures to ensure, to their best extent, “a sufficient level” of AI literacy.

Liability

Who answers when a client file leaves through a personal account?

The organisation first

As controller, it puts the appropriate measures in place and must be able to demonstrate it (article 24). The person acts under its authority, on its instructions (articles 29 and 32(4)) — provided those instructions are written down, and known at the moment of acting.

Blocking does not help

People route around it, and the DPO sees none of the texts that leave. The frame moves the decision to the moment and the person of the act: before a text reaches an AI, whoever sends it sees what would leave, keeps what the AI needs, and decides.

And the tool?

DoNotLeak is an aid, provided as is: the person decides and stays responsible for what they send, as for their own obligations — the organisation’s rules, confidentiality commitments, the GDPR. Contee limits its liability as far as the law allows, gross or wilful misconduct excepted; its terms of use are governed by French law.

What this sharing does not mean
  • It is organisational: it makes no employee a joint controller under the GDPR.
  • A signed charter discharges the organisation of nothing.
  • Human review is not a guarantee: it needs context, time and the means to decide — the frame is there to give them.
  • Pseudonymising is not anonymising: the protected text is still personal data, and the context can be enough to point to someone (GDPR, article 4(5) and recital 26).
Line drawing: a data protection officer, a woman, sits at her desk with her head in her hands, under a sword hanging by a thread; around her, documents fly off beyond her reach.
The pressure concentrates on one person, who does not see the uses.

The frame

Five parts, measures you can prove.

A rule alone stays in a drawer; a tool alone teaches nothing. The texts ask for appropriate measures the organisation can demonstrate (GDPR, article 24), and protect a trade secret only if reasonable steps kept it secret (Directive (EU) 2016/943, article 2): the five parts, together.

A policy: the charter

The organisation’s instructions, in writing: what is allowed, what is forbidden, what must be protected first, whom to call. Short enough to be read, concrete enough to recognise a situation.

GDPR, articles 24(2) and 29

The example charter

The tool at everyone’s hand

DoNotLeak on its page, with no account and nothing to install: before a text reaches an AI, the person sees what would leave and decides. For a team, it can also run on the organisation’s own servers, with its API.

Nothing kept: the text is processed in memory, then forgotten.

How it works

Training: the Seals

In each team, a volunteer — a Seal: Seal and Engage Against Leaks — relays the reflex and answers questions. Seals against leaks. The tool teaches in the gesture itself: each finding is shown with its type, before sending. Contee can help you build and train this community, with content and advice to launch it.

AI Act, article 4

Build your Seals with Contee — message us on LinkedIn

Measurement: volumes, never people

Count the tools approved, the people trained, the incidents reported. Nobody is watched; what people write is not read.

The calculator: the order of magnitude

DoNotLeak’s own counts inside the organisation — by type of data, never the contentSoon

An incident path

When something left anyway: say it at once, contain, assess, notify when the law requires it. Known in advance, so that nobody hesitates.

GDPR, article 33

The incident path

An example to adapt

An AI charter to adapt, section by section.

Ten short sections, every field specific to your organisation in [brackets]. Adapt it with your DPO, your counsel and, where required, your staff representatives.

An editable PowerPoint (.pptx), which also opens in LibreOffice.

Word and PDF versionsSoon

Licence: CC BY-SA 4.0

Its ten sections

It holds the instructions within the meaning of article 29, the allowed and forbidden uses, what never enters an AI tool (articles 9 and 10), the sanctions to write under your internal regulations.

  1. Why this charter
  2. Scope
  3. Allowed and forbidden uses
  4. Protect before any AI use
  5. The protection tool
  6. Training and help
  7. Reporting an incident
  8. Measurement, not surveillance
  9. Sanctions — left to your organisation
  10. Review

It follows the CNIL’s recommendations: a charter that states the allowed and forbidden uses, and users trained before they start.

What the licence lets you do

You may copy, adapt and share it, for any purpose, crediting Contee. ShareAlike (SA): if you publish an adapted version, publish it under the same licence — so that everyone can build on the improvements in turn.

Line drawing: at a table, a woman explains a short illustrated sheet to a colleague, a man, who listens with his chin in his hand; the sheet shows three cases — an approved tool, a locked document, a contact for help.
A charter serves when it helps people recognise a situation and act.

Roll out this frame and its charter in 90 days: the DPO’s kit

Your contracts

What a clause on AI use can cover.

Points to examine, contract by contract, each with the text it comes from — not a ready-made clause.

With an AI provider

The processing contract

When the provider processes personal data on the organisation’s behalf, a contract sets its obligations: documented instructions, its staff’s confidentiality, security, sub-processors, deleting or returning the data at the end, audits.

GDPR, article 28(3)

What it does with what it receives

Depending on the tool, its contract and its settings, the provider may keep, read or reuse what it is sent: the clause says what it does with it, for how long, and for which purposes.

The example charter, section 1

Where the data is processed

Outside the Union, a transfer follows the rules of the GDPR’s chapter V; the processing contract covers transfers too, which take place only on documented instructions.

GDPR, articles 28(3)(a) and 44

With a client

Their documents in an AI

A non-disclosure agreement can say whether the client’s documents may enter an AI tool, which one, and on what conditions — protected first, for instance. Disclosing a trade secret without its holder’s consent, in breach of such an agreement, is unlawful.

Directive (EU) 2016/943, article 4(3)

Reasonable steps

A trade secret is protected only if its holder took reasonable steps to keep it secret. A clause, a charter everyone knows, a tool at hand: steps the organisation keeps a record of. For professional secrecy, the example charter keeps a line for your sector’s restrictions.

Directive (EU) 2016/943, article 2

The day something leaves

Who tells whom, and how fast: a processor informs the controller without undue delay, and the controller notifies the supervisory authority, within 72 hours where feasible. The contract sets the rest: how soon the client is told, and whom to contact.

GDPR, article 33

And when a client asks how AI use is governed in your organisation

Your charter and its list of approved tools, your teams’ training (AI Act, article 4), your incident path. The frame’s five parts, above, fit on one page.

Nothing on this page is legal advice: it points to the texts; your DPO and your counsel apply them to your case and to your contracts.

When something left anyway

An incident path known in advance, with its deadlines.

A text sent to an AI cannot be recalled — DoNotLeak cannot do it either. What matters then is speed.

  1. Say it at once

    To the contact the charter names. An early report is worth more than a perfect one, and nobody is blamed for reporting.

  2. Contain

    Delete the conversation where the service allows it; have any password or key that left revoked and replaced.

  3. Assess and notify

    The organisation assesses the risk. A personal data breach is notified to the supervisory authority — in France, the CNIL — within 72 hours where feasible (GDPR, article 33).

Then learn: what the incident teaches goes back into the charter and the training.

Start from the charter, try the tool.

Adapt the example charter with your DPO and your counsel; the DPO’s kit rolls it out in 90 days. Try the tool on a fictional text, with no account. To run it inside your organisation, with its API, write to Contee.