How to Keep Customer PII Out of LLM Provider Logs

An in-flight anonymization gateway and Zero Data Retention contract as two lines of defense against GDPR violations through AI.

An employee pastes a customer's bank statement into an AI assistant to draft a reply. The statement contains a name, passport number, IBAN, address, and transaction amounts. The assistant calls a cloud model. From this point, the customer's PII has physically left the perimeter and sits in the provider's infrastructure — at minimum in active processing, and by default in abuse-monitoring logs for 30 days. The customer never consented to this transfer.

This is the single most common way companies violate GDPR through AI. Not through malice, but because nothing stood in the request path to strip the data before the model call.

Continue reading “How to Keep Customer PII Out of LLM Provider Logs”