Guidelines on the Responsible Use of Artificial Intelligence (AI) at the University of Greifswald

Section: Data protection and information security | Last revised: April 2026


Purpose and scope

These guidelines provide guidance and practical assistance for the responsible use of artificial intelligence at the University of Greifswald. They are aimed at all members of the University of Greifswald who use, develop or commission AI-based systems or applications.

The aim is to promote the legally compliant, transparent and secure use of AI, taking particular account of requirements regarding data protection, information security, research data management, and the secure handling of login credentials. The guidelines are based on the relevant legal provisions, in particular the General Data Protection Regulation (GDPR), the requirements regarding the security of processing set out in Article 32 of the GDPR, the guidelines on IT and information security, the regulations of the University Computer Centre, and the provisions of the EU AI Act. They specify existing legal requirements for everyday working practice, without replacing an individual legal assessment.

These guidelines are reviewed on an ongoing basis, adapted to technical, legal and organisational developments, and communicated accordingly. Nevertheless, when using AI, you must observe the relevant legal provisions as amended from time to time.


Basic principles when using AI

Transparency | When using AI, users must ensure a level of transparency that correspond to the respective circumstances. If there are specific guidelines on disclosing the use of AI for particular areas of application, these must be observed (e.g. a declaration of independent work for theses).

Human responsibility | AI merely supports humans. Users remain responsible at all times for decisions, content and documents produced with the aid of AI.

Protection of data and personal data | AI may only be used to process personal data if there is a legal basis for such processing as required under Article 6 of the GDPR and if the specific use of AI falls within the scope of the permitted purposes of processing. Furthermore, any use of AI in research, teaching, and administration must ensure that no confidential university information is disclosed to third parties. This applies, for example, to internal strategies, sensitive contract data, and internal university information. 


Permitted and prohibited use of AI

The use of the university’s internal AI (AppHubAI) is generally permitted without restrictions, as, unlike external tools, it does not continue to learn from user inputs (prompts). Consequently, the content and data are not used to train the AI and are not passed on to third parties. However, when using personal data, it must be kept in mind – as always – that the use of AI must remain within the scope of the purpose for which the data in question was collected. 

When using AI that is not hosted at the university, care must be taken to ensure that no personal and/or confidential data is disclosed. Examples of permitted use, unless specific regulations apply to certain subject areas:

  • Editorial help for writing texts: Editing or simplifying texts, provided that only neutral, non-confidential and/or no personal content is entered.
  • Gathering ideas: Suggestions for presentations, planning events or optimising processes.
  • Explanation of technical or subject-specific concepts without any specific reference to individuals and/or confidential information.
  • Drafts for internal training courses, provided that only publicly available or anonymised information is used.
  • Drawing up general checklists or process descriptions, provided that no confidential and/or personal details are disclosed.

It is not permitted to enter confidential and/or personal data into AI tools hosted outside the university. This includes:

  • Human resources or application documents (names, addresses, performance appraisals, etc.)
  • Student data (e.g. information regarding examinations, illness, disability, or support)
  • Draft contracts containing sensitive information, invoicing details, internal calculations
  • Information from internal systems
  • Internal or confidential emails
  • Strategic decision-making processes, project evaluations

This also applies if confidential and/or personal information containing internal university details is entered into AI services on private devices, even if these are used for work purposes.

Permitted:

  • “Rewrite the following general statement in a more polite way: Please note the deadline.”
  • “Draw up a checklist for a typical office handover” without mentioning any individuals or internal information.
  • “Explain the difference between authenticated and anonymous web access.”

Not permitted:

  • “Please assess Ms. X’s application based on these certificates.”
  • “Summarise these internal minutes.” (contains confidential information)
  • “Reply to this email.” (if it contains personal or internal details)
  • ‘Analyse this contract/funding grant/staff record.’

IT security

Principle | There is no general work-related requirement to use AI at the university. The use of AI is entirely voluntary and is the sole responsibility of the persons using it.

Password and login details security | Staff bear full responsibility for the security of their personal login details. The following shall apply in addition to the provisions on the handling of passwords and login credentials set out in § 6(2) Items (2) to (4) of the University Computer Centre Regulations:

  • Never use the password or any part of the password for your central user account in AI services.
  • Passwords must be strong, unique, and secure.
  • Login details must not be stored in documents or passed on to others.

Responsibilities and support

If you have any questions, please contact:

  • IT Security Officer
  • Data Protection Officer/Data Protection Management Officer 
  • University Computer Centre and Chief Information Officer (CIO)

Breaches

Breaches of data protection and information security regulations may result in consequences under employment or civil service law, as well as organisational consequences (for example, temporary or permanent exclusion from the use of the University Computer Centre’s IT systems in accordance with § 7 of the University Computer Centre Regulations).