Labs

GDPR-compliant AI for public administration

Data sovereignty, EU AI Act, national data protection laws — all covered. We build AI systems for authorities that run entirely on German servers. Open-source models, fully auditable, legally compliant.

What we build for authorities

Case Worker Assistant

Searches through specialist laws, internal regulations and case law in seconds. Provides answers with source references — case workers retain control and save research time.

Document Processing

Classify applications, extract form data, structure information. The AI reads invoices, contracts and official notices — faster and more accurate than manual processing.

Citizen Chatbot

Answers standard questions 24/7: opening hours, applications, responsibilities. Relieves the telephone switchboard and citizen services — without data ever leaving the town hall.

File & Record Summarization

Summarize meeting minutes, lengthy procedures and extensive files in seconds. With source references to the relevant passages for review.

How the project runs

1

Workshop & Analysis

We analyze your processes, identify use cases with the greatest impact and assess the legal framework. Output: a prioritized roadmap.

2

Pilot Project

In 8-12 weeks we build a first system with clearly defined scope. Typically: one concrete use case, measurable results, full documentation.

3

Rollout & Operations

Scaling to other departments or use cases. We handle monitoring, updates and training — or transfer the know-how to your team.

The problem: standard AI can't enter public offices

ChatGPT, Gemini, Claude — the well-known AI tools process data in the US. For German authorities this is taboo under GDPR. At the same time the pressure is rising: staff shortages, digitization mandates, EU AI Act. The solution: AI that runs exclusively on German servers, with open-source models and full auditability.

Legally airtight

Our solutions meet all relevant compliance requirements — audited and documented.

  • GDPR — Data processing exclusively within the EU, no third-country transfers
  • National data protection laws (BDSG) and specialist regulations
  • EU AI Act — Transparency, risk classification, documentation
  • IT baseline protection — compatible with BSI standards, audit logs
  • BITV 2.0 — Accessibility in all interfaces

Technology stack for sovereignty

We exclusively use open-source models and European infrastructure. No dependencies on US providers.

Models: Llama 3, Mistral, Teuken-7B (German model), Mixtral

Hosting: STACKIT (Schwarz Group), plusserver, Open Telekom Cloud, Hetzner, or on-premise

Infrastructure: Kubernetes, vector databases (Qdrant, Weaviate) — completely on-premise

Frequently Asked Questions

Bring AI into your office — securely

We provide non-binding consulting on your use cases and show you concretely what's feasible. Including an initial assessment of costs and timeline.

Schedule consultation
GDPR-Compliant AI for Government & Public Sector | CAZ Labs | CAZ Labs