Skip to main content
BLOG

Why Data Protection in AI Applications Starts with Architecture

Nicky LippoldNicky Lippold
2026-09-01
4 Min.

Data protection can easily sound like a matter of legal clauses, guidelines, and approval processes—documents filed away somewhere, or audits conducted at the end of a project.

In practice, however, data protection often begins much earlier: not just with the finished system or at the go-live stage, but right during the planning phase of a technical solution.

We would like to show you how we actively integrate data protection into our projects.

The moment it gets practical

As part of a project, PROTOS developed a cloud-based, AI-powered application designed to automatically tailor existing CVs to specific project inquiries.

The application’s goal is to automatically analyze incoming project inquiries and generate a suitable CV proposal based on them. A staff member then reviews the generated proposal for accuracy and approves it. The application serves solely to support the processing workflow; the final decision always remains with a human.

From a technical standpoint, it is a modern cloud application featuring a web-based frontend, authentication, document upload, automated text extraction, AI-driven processing, and structured storage of results within a cloud infrastructure controlled by PROTOS.

At first glance, it appears to be a straightforward use case. It involves neither live customer service nor a large-scale transformation program—initially, it is simply an internal solution to support a specific work process.

And therein lies a key insight gained from practical experience.

During the technical design phase, the focus was initially on the AI ​​component itself. After all, the language model is what processes the content of the CVs and project inquiries. Intuitively, that also seems to be the part of the application most relevant to data protection.

However, a different picture emerged when examining the overall architecture.

Personal data is processed even before a prompt is sent to the AI ​​model.

User authentication, document uploading and storage, and automated text extraction all involve the processing of personal information. The AI ​​component itself is merely one processing step within a much broader architecture.

What began as a technical AI test evolved into an analysis of the complete data flow—and, consequently, a data protection issue.

Data protection does not begin with AI

In this instance, it was standard practice at PROTOS to involve the data protection officer at an early stage. The aim was not to slow down the project, but to jointly assess the data protection requirements arising from the planned architecture.

The first step was to analyze which personal data would be processed throughout the entire data flow. Next, the team examined the purpose of this processing, the relevant legal bases, and the necessary organizational and technical measures.

As the use case involved the HR domain, existing contractual arrangements were also reviewed in collaboration with the responsible departments. Particularly in an employment context, it is crucial to carefully assess whether the existing legal basis covers the intended processing purpose or if adjustments are required.

The project was then able to proceed—not based on assumptions, but on a documented assessment of the identified risks and measures.

Data protection affects the entire architecture

The technical architecture demonstrates that personal data is processed at multiple points within the application.

The central authentication system processes user data right from the start. Uploaded documents are stored in a secure repository, automatically read, and subsequently processed by the AI. Results are stored in a structured format in a database. Additionally, security, monitoring, and encryption services ensure that the application operates reliably and transparently.

The AI ​​component itself represents just one element within the overall data flow.

For precisely this reason, the data protection analysis is not limited to the language model itself but encompasses all components of the cloud architecture.

Paul Schmidt
With AI applications, the focus is often on the model being used. From a technical perspective, however, data protection begins much earlier. Factors such as authentication, storage, permissions, data flows, and interfaces already determine how personal data is processed. That is why we always consider data protection across the entire architecture rather than focusing solely on the AI ​​component in isolation.

Data protection does not end with the initial release

The ongoing operation of an application is just as important as its initial planning.

In practice, data protection risks often do not arise from flaws in the original architectural design; rather, applications are subject to continuous change.

New user roles are created, additional interfaces are integrated, permissions are adjusted, and further components are added.

From a technical standpoint, such changes often make sense or are even necessary. At the same time, however, they can result in personal data suddenly being processed in new locations or becoming accessible to additional users.

Permission concepts for document storage systems provide a typical example. If a new user role is granted access to a storage area without a thorough review of the underlying permissions, documents containing personal data may become visible to individuals who do not require that information for their work.

While the application continues to function flawlessly from a technical perspective, the situation requires a fresh assessment regarding data protection law. Consequently, data protection does not end with an application’s initial release but remains a factor throughout its entire lifecycle.

Omar Kiwan
A cloud application rarely remains unchanged throughout its entire lifecycle. New deployments, additional services, and modified configurations are part of normal operations. Therefore, we view data protection not as a one-time check, but as an ongoing component of our technical processes. Our goal is to implement changes in a traceable manner and to permanently embed data protection requirements within the infrastructure.

Data Protection as a Sparring Partner

Putting data protection into practice means not viewing it merely as a control function. Instead, the goal is to provide guidance at an early stage and collaboratively develop solutions that are both technically sound and legally robust.

This requires integrating data protection considerations during the architecture and conceptual design phases. If data protection issues are addressed only shortly before launch, making adjustments is often far more complex and time-consuming.

Conversely, if they are evaluated jointly at an early stage, technical and organizational measures can be sensibly incorporated from the very beginning.

Jan Reimers
For me, data protection is not a matter of simply checking a box and moving on. Especially with new technologies like AI, new situations constantly arise that require specific examination. Effective solutions emerge from dialogue between people who want to work together to understand both the functional requirements and what is feasible in terms of data protection compliance.

From Compliance Requirement to Standard Practice

This use case demonstrates that data protection and modern cloud architectures are not mutually exclusive.

The key is to view data protection not merely as a legal issue, but as an integral part of the technical architecture and ongoing operations.

This entails clearly defined responsibilities, documented decisions, appropriate technical measures, and the continuous assessment of changes throughout the application's entire lifecycle.

Therefore, the crucial questions are not limited to:

  • What personal data is being processed?
  • For what purpose is the processing taking place?
  • What is the legal basis for the processing?

They also include:

  • At which points in the architecture is personal data processed?
  • Which components access this data?
  • How do new interfaces, roles, or extensions alter the data flow?
  • How do we ensure that these changes remain permanently traceable?

Only the interplay of architecture, cloud engineering, information security, and data protection creates the foundation for securely and responsibly integrating AI applications into everyday work processes.

Nicky Lippold

Nicky Lippold

Marketing & Sales

Nicky Lippold is your first point of contact for all things IT. With over 8 years in the software industry, he provides what many technical projects need most: a clear, communicative perspective that offers strategic guidance before diving into the technical details.
LinkedIn Profil