Up to €20 million for one pasted spreadsheet? Why HR and finance teams should think twice before opening ChatGPT
More and more companies in Poland and Germany are telling employees to "just use AI" — it speeds things up, competitors are already doing it, the CEO saw a demo on LinkedIn. Rarely does anyone stop to ask: what actually happens to the data an employee just pasted into that chat window?
That question is especially uncomfortable in the two departments that, by nature, work with the densest possible mix of personal and financial data: HR and finance. Payroll lists, candidate data, national ID numbers, salaries, vendor data, tax IDs — exactly what GDPR protects most strictly, and exactly what these departments would most love to feed into AI to speed up a report, summary or analysis.
The fines are not theoretical
GDPR allows for administrative fines of up to €20 million, or 4% of a company's total worldwide annual turnover — whichever is higher. This is not a rule that exists only on paper. In recent years, European data protection authorities have repeatedly reached for the upper end of that range:
Meta paid a record €1.2 billion (May 2023) for unlawfully transferring European users' data to the US. TikTok was fined €530 million (May 2025) for a similar violation — transferring data to China. Uber paid €290 million (August 2024) for transferring driver data outside the EU without adequate safeguards. These are companies with legal resources a small or mid-sized business will never have — and they still made mistakes that regulators punished at the maximum level.
AI adds a new, very specific leak channel
Fines for large, systemic violations are one thing. But increasingly, the source of the problem is something much more mundane: a single employee pasting company data into a public AI tool without stopping to think where that data goes, or how long it stays there.
The best-known example: in April 2023, Samsung engineers pasted fragments of the company's confidential source code into ChatGPT, hoping the AI would help debug it. Once Samsung found out, it banned employees from using generative AI outright — there was no guarantee the pasted data could ever be removed from external servers. A few months earlier, Amazon's legal department reacted similarly, warning employees after ChatGPT's answers started resembling confidential internal materials. Apple followed the same path.
The scale of the problem isn't marginal. Cyberhaven, analyzing ChatGPT usage across 1.6 million corporate employees, found that 4.7% of employees had pasted confidential company data into it, and 11% of all data pasted into ChatGPT was classified as sensitive or confidential. These aren't isolated incidents — it's daily practice across thousands of companies that have no mechanism to control it.
HR and finance have the most to lose — and the most to gain
No department combines these two things — density of sensitive data and appetite for AI — quite like HR and finance. An HR team that wants AI to summarize recruitment results or analyze employee turnover is, by necessity, working with national ID numbers, salaries and candidates' personal data. A finance team that wants AI to help categorize expenses or spot trends in invoices is working with vendor data, amounts and tax IDs.
An outright ban on using AI in these departments doesn't work in practice — employees will find a way to use a tool that genuinely speeds up their work anyway, just without the security team's knowledge. The real alternative is anonymizing data before it reaches AI — so the model gets the full context and structure of the data, but not the sensitive values themselves.
That's exactly what HideReveal does: it turns national IDs, names, addresses, amounts and tax IDs in Excel, Word and PowerPoint files into safe tokens before the file ever reaches an AI tool — and restores the original data afterward, locally, on your own computer. HR can ask AI to analyze a personnel spreadsheet, and finance can ask for an invoice summary, without a single real national ID number or account number ever leaving the company.
This isn't a guarantee of 100% GDPR compliance — no tool can promise that, and responsibility for data processing always stays with the company. But it's a concrete, practical step that meaningfully reduces risk exactly where leaks most often actually happen — in the ordinary, everyday copy-paste into a chat window.
← Back to home