For legal teams
Say yes to AI, and keep your confidentiality commitments.
Non-disclosure agreements, tenders, client files, professional secrecy: a text pasted into an AI can breach a commitment without anyone deciding it. Here: the texts article by article, an example charter to adapt, what a clause can cover, and the path to follow when something has left.

Who answers
The organisation answers. Everyone acts on its instructions.
What the texts say, in four lines — each with its article.
The organisation
As controller, it puts appropriate measures in place — data protection policies among them, where proportionate — and must be able to show that its processing complies.
GDPR, article 24
The data protection officer
Informs, advises, monitors compliance, raises awareness and trains the staff. The DPO is not personally responsible when the organisation fails to comply.
GDPR, article 39 · CNIL
Each person
Handles the organisation’s personal data only on its instructions. The charter is where those instructions are written down — the document that shows they were given.
GDPR, articles 29 and 32(4)
AI literacy
Since 2 February 2025, an organisation that uses AI systems takes measures to support its staff’s AI literacy. No certificate is required.
AI Act, article 4, as amended in 2026
The texts, article by article
What each article says, in plain words — a summary: only the text published in the Official Journal of the European Union is authentic.
GDPR, article 24 — the controller’s responsibility
The organisation puts appropriate technical and organisational measures in place — data protection policies among them, where proportionate — and must be able to demonstrate that its processing complies.
GDPR, article 29 — processing under the controller’s authority
Anyone acting under the organisation’s authority who has access to personal data processes it only on the organisation’s instructions, unless the law requires otherwise.
GDPR, article 32 — security of processing
Security appropriate to the risk; and, in paragraph 4, the organisation makes sure that the people acting under its authority process personal data only on its instructions.
GDPR, article 33 — notifying the authority of a breach
A personal data breach is notified to the supervisory authority without undue delay and, where feasible, within 72 hours, unless it is unlikely to result in a risk to people; every breach is documented.
GDPR, article 34 — informing the people concerned
When a breach is likely to result in a high risk to people, they are told without undue delay, in clear and plain language.
GDPR, article 39 — the DPO’s tasks
Inform and advise the organisation and its staff, monitor compliance — awareness-raising and training included —, advise on impact assessments, cooperate with the supervisory authority.
AI Act, article 4 — AI literacy
Providers and deployers of AI systems take measures to support the AI literacy of their staff and of the other people who operate or use AI systems on their behalf, taking into account their knowledge, experience, education and training, and the context of use. This is the wording of Regulation (EU) 2026/1744 (the Digital Omnibus on AI, article 1, point 5), in force since 27 July 2026; the text adopted in 2024 asked for measures to ensure, to their best extent, “a sufficient level” of AI literacy.
Read the official text (EUR-Lex)The AI Act as adopted in 2024, article 4
Liability
Who answers when a client file leaves through a personal account?
The organisation first
As controller, it puts the appropriate measures in place and must be able to demonstrate it (article 24). The person acts under its authority, on its instructions (articles 29 and 32(4)) — provided those instructions are written down, and known at the moment of acting.
Blocking does not help
People route around it, and the DPO sees none of the texts that leave. The frame moves the decision to the moment and the person of the act: before a text reaches an AI, whoever sends it sees what would leave, keeps what the AI needs, and decides.
And the tool?
DoNotLeak is an aid, provided as is: the person decides and stays responsible for what they send, as for their own obligations — the organisation’s rules, confidentiality commitments, the GDPR. Contee limits its liability as far as the law allows, gross or wilful misconduct excepted; its terms of use are governed by French law.
What this sharing does not mean
- It is organisational: it makes no employee a joint controller under the GDPR.
- A signed charter discharges the organisation of nothing.
- Human review is not a guarantee: it needs context, time and the means to decide — the frame is there to give them.
- Pseudonymising is not anonymising: the protected text is still personal data, and the context can be enough to point to someone (GDPR, article 4(5) and recital 26).

The frame
Five parts, measures you can prove.
A rule alone stays in a drawer; a tool alone teaches nothing. The texts ask for appropriate measures the organisation can demonstrate (GDPR, article 24), and protect a trade secret only if reasonable steps kept it secret (Directive (EU) 2016/943, article 2): the five parts, together.
A policy: the charter
The organisation’s instructions, in writing: what is allowed, what is forbidden, what must be protected first, whom to call. Short enough to be read, concrete enough to recognise a situation.
GDPR, articles 24(2) and 29
The tool at everyone’s hand
DoNotLeak on its page, with no account and nothing to install: before a text reaches an AI, the person sees what would leave and decides. For a team, it can also run on the organisation’s own servers, with its API.
Nothing kept: the text is processed in memory, then forgotten.
Training: the Seals
In each team, a volunteer — a Seal: Seal and Engage Against Leaks — relays the reflex and answers questions. Seals against leaks. The tool teaches in the gesture itself: each finding is shown with its type, before sending. Contee can help you build and train this community, with content and advice to launch it.
AI Act, article 4
Measurement: volumes, never people
Count the tools approved, the people trained, the incidents reported. Nobody is watched; what people write is not read.
The calculator: the order of magnitude
DoNotLeak’s own counts inside the organisation — by type of data, never the contentSoon
An incident path
When something left anyway: say it at once, contain, assess, notify when the law requires it. Known in advance, so that nobody hesitates.
GDPR, article 33
An example to adapt
An AI charter to adapt, section by section.
Ten short sections, every field specific to your organisation in [brackets]. Adapt it with your DPO, your counsel and, where required, your staff representatives.
An editable PowerPoint (.pptx), which also opens in LibreOffice.
Word and PDF versionsSoon
Licence: CC BY-SA 4.0
Its ten sections
It holds the instructions within the meaning of article 29, the allowed and forbidden uses, what never enters an AI tool (articles 9 and 10), the sanctions to write under your internal regulations.
- Why this charter
- Scope
- Allowed and forbidden uses
- Protect before any AI use
- The protection tool
- Training and help
- Reporting an incident
- Measurement, not surveillance
- Sanctions — left to your organisation
- Review
It follows the CNIL’s recommendations: a charter that states the allowed and forbidden uses, and users trained before they start.
What the licence lets you do
You may copy, adapt and share it, for any purpose, crediting Contee. ShareAlike (SA): if you publish an adapted version, publish it under the same licence — so that everyone can build on the improvements in turn.

Roll out this frame and its charter in 90 days: the DPO’s kit
Your contracts
What a clause on AI use can cover.
Points to examine, contract by contract, each with the text it comes from — not a ready-made clause.
With an AI provider
The processing contract
When the provider processes personal data on the organisation’s behalf, a contract sets its obligations: documented instructions, its staff’s confidentiality, security, sub-processors, deleting or returning the data at the end, audits.
What it does with what it receives
Depending on the tool, its contract and its settings, the provider may keep, read or reuse what it is sent: the clause says what it does with it, for how long, and for which purposes.
Where the data is processed
Outside the Union, a transfer follows the rules of the GDPR’s chapter V; the processing contract covers transfers too, which take place only on documented instructions.
With a client
Their documents in an AI
A non-disclosure agreement can say whether the client’s documents may enter an AI tool, which one, and on what conditions — protected first, for instance. Disclosing a trade secret without its holder’s consent, in breach of such an agreement, is unlawful.
Reasonable steps
A trade secret is protected only if its holder took reasonable steps to keep it secret. A clause, a charter everyone knows, a tool at hand: steps the organisation keeps a record of. For professional secrecy, the example charter keeps a line for your sector’s restrictions.
The day something leaves
Who tells whom, and how fast: a processor informs the controller without undue delay, and the controller notifies the supervisory authority, within 72 hours where feasible. The contract sets the rest: how soon the client is told, and whom to contact.
And when a client asks how AI use is governed in your organisation
Your charter and its list of approved tools, your teams’ training (AI Act, article 4), your incident path. The frame’s five parts, above, fit on one page.
Nothing on this page is legal advice: it points to the texts; your DPO and your counsel apply them to your case and to your contracts.
When something left anyway
An incident path known in advance, with its deadlines.
A text sent to an AI cannot be recalled — DoNotLeak cannot do it either. What matters then is speed.
Say it at once
To the contact the charter names. An early report is worth more than a perfect one, and nobody is blamed for reporting.
Contain
Delete the conversation where the service allows it; have any password or key that left revoked and replaced.
Assess and notify
The organisation assesses the risk. A personal data breach is notified to the supervisory authority — in France, the CNIL — within 72 hours where feasible (GDPR, article 33).
Then learn: what the incident teaches goes back into the charter and the training.
Go further
The rest of the kit
The change kit: decks for the webinar, the management briefing and the Seals’ training
References
- CNIL — Q&A on the use of generative AI systems (18 July 2024)
- CNIL — becoming a data protection officer (in French)
- CNIL — notifying a personal data breach (in French)
- GDPR — Regulation (EU) 2016/679, articles 24, 28, 29, 32, 33, 39 and 44 among others (EUR-Lex)
- AI Act — Regulation (EU) 2024/1689, article 4 on AI literacy (EUR-Lex)
- Regulation (EU) 2026/1744, the Digital Omnibus on AI, which amended article 4 (EUR-Lex)
- Directive (EU) 2016/943 on trade secrets, articles 2 and 4 (EUR-Lex)
- European Commission — AI literacy, questions and answers
Start from the charter, try the tool.
Adapt the example charter with your DPO and your counsel; the DPO’s kit rolls it out in 90 days. Try the tool on a fictional text, with no account. To run it inside your organisation, with its API, write to Contee.