
With AI applications, the focus is often on the model being used. From a technical perspective, however, data protection begins much earlier. Factors such as authentication, storage, permissions, data flows, and interfaces already determine how personal data is processed. That is why we always consider data protection across the entire architecture rather than focusing solely on the AI component in isolation.
Data protection does not end with the initial release
The ongoing operation of an application is just as important as its initial planning.
In practice, data protection risks often do not arise from flaws in the original architectural design; rather, applications are subject to continuous change.
New user roles are created, additional interfaces are integrated, permissions are adjusted, and further components are added.
From a technical standpoint, such changes often make sense or are even necessary. At the same time, however, they can result in personal data suddenly being processed in new locations or becoming accessible to additional users.
Permission concepts for document storage systems provide a typical example. If a new user role is granted access to a storage area without a thorough review of the underlying permissions, documents containing personal data may become visible to individuals who do not require that information for their work.
While the application continues to function flawlessly from a technical perspective, the situation requires a fresh assessment regarding data protection law. Consequently, data protection does not end with an application’s initial release but remains a factor throughout its entire lifecycle.

A cloud application rarely remains unchanged throughout its entire lifecycle. New deployments, additional services, and modified configurations are part of normal operations. Therefore, we view data protection not as a one-time check, but as an ongoing component of our technical processes. Our goal is to implement changes in a traceable manner and to permanently embed data protection requirements within the infrastructure.
Data Protection as a Sparring Partner
Putting data protection into practice means not viewing it merely as a control function. Instead, the goal is to provide guidance at an early stage and collaboratively develop solutions that are both technically sound and legally robust.
This requires integrating data protection considerations during the architecture and conceptual design phases. If data protection issues are addressed only shortly before launch, making adjustments is often far more complex and time-consuming.
Conversely, if they are evaluated jointly at an early stage, technical and organizational measures can be sensibly incorporated from the very beginning.

For me, data protection is not a matter of simply checking a box and moving on. Especially with new technologies like AI, new situations constantly arise that require specific examination. Effective solutions emerge from dialogue between people who want to work together to understand both the functional requirements and what is feasible in terms of data protection compliance.
From Compliance Requirement to Standard Practice
This use case demonstrates that data protection and modern cloud architectures are not mutually exclusive.
The key is to view data protection not merely as a legal issue, but as an integral part of the technical architecture and ongoing operations.
This entails clearly defined responsibilities, documented decisions, appropriate technical measures, and the continuous assessment of changes throughout the application's entire lifecycle.
Therefore, the crucial questions are not limited to:
- What personal data is being processed?
- For what purpose is the processing taking place?
- What is the legal basis for the processing?
They also include:
- At which points in the architecture is personal data processed?
- Which components access this data?
- How do new interfaces, roles, or extensions alter the data flow?
- How do we ensure that these changes remain permanently traceable?
Only the interplay of architecture, cloud engineering, information security, and data protection creates the foundation for securely and responsibly integrating AI applications into everyday work processes.



