AI Data Security in Public Tenders: GDPR, Confidential Documents and Access Control

Jędrzej Stoiński
Customer Success Manager at Minerva, helping companies make better use of tender data in their day-to-day operations. He combines experience in B2B customer service and sales with a practical understanding of contractors’ needs. He helps companies structure their bidding processes and make better-informed decisions in future tenders.

Yes, AI can analyse confidential tender documents, but only under clear conditions. Data should be processed in a controlled environment, access must be limited by roles, and the provider should be able to explain where documents are stored, who can access them, whether they are sent to external language models and whether they are used to train AI systems. In practice, AI data security is not about a broad claim that a platform is “GDPR-compliant”. It is about concrete safeguards: encryption, access control, activity history, a data processing agreement, purpose limitation and clear data retention rules.
This matters especially for tender teams in sectors such as healthcare, utilities, IT, critical infrastructure and defence. Tender documentation is rarely neutral. It may contain pricing, technical assumptions, personal data, certificates, bidding strategy, subcontractor information, operational capabilities or planned margins. When this material is meant to be analysed by an AI tool, board members and IT teams are right to ask: what exactly happens to these files?
This article answers that question without marketing shortcuts.
Can AI analyse confidential tender documents?
It can, provided the organisation treats AI as part of an information processing workflow, not as “a chat window for uploading files”. This distinction is crucial.
A general-purpose language model may help draft text, summarise a document or structure notes. But on its own, it is not a tender workflow. It does not know your live opportunities, it has no company-specific procurement context and it often gives teams limited control over how documents are stored, who can access them and whether the data may be used further.
Minerva is positioned differently: as a platform built for tender discovery, document analysis, source-based answers and procurement workflows, rather than as a generic LLM for broad responses. So the right question is not: “is AI safe?”. The right question is: does this specific AI tool have the architecture, contracts and procedures required to analyse confidential tender documents safely?
When assessing a tool, check five things first:
- whether documents are stored in the EU or another approved data location,
- whether data is encrypted in transit and at rest,
- whether documentation is sent to external language models,
- whether customer data is used to train models,
- whether file access is controlled at user, role and team level.
In Minerva’s case, public materials indicate that documentation analysed in the platform is not sent to an external language model, data is processed in a closed environment on European servers, and company knowledge is not used to train external systems or shared with other customers. This model is described on the page Minerva for small and medium-sized businesses.
Where and how should tender documents be stored?
For IT and security teams, data location is not a technical detail. It is one of the basic elements of risk assessment.
In a secure model, tender documents should be stored in an environment that meets the organisation’s requirements for location, encryption, backups, availability and business continuity. GDPR does not prescribe one specific technology, but it requires controllers and processors to implement technical and organisational measures appropriate to the risk. Article 32 GDPR refers to measures such as encryption, confidentiality, integrity, availability and resilience of processing systems, as well as regular testing of security controls.
In practice, a team buying an AI document analysis tool should ask the provider about:
- Data location. Is data stored in the EU? Is there any transfer outside the EEA? If so, on what legal basis?
- Encryption. Are files encrypted in transit and at rest?
- Customer data isolation. Are one company’s documents logically separated from other customers’ data?
- Retention. How long are documents stored, and can the customer request deletion?
- Sub-processors. Does the provider use further processors, and how are they controlled?
- Administrative access. Who on the provider’s side can access the data, and in what situations?
It helps to separate two layers of Minerva documents. The privacy policy covers website data (contact forms, analytics, logs) and states that for any transfers outside the EEA Minerva uses GDPR mechanisms, including adequacy decisions, standard contractual clauses (SCC), encryption, pseudonymisation, access control and limitation of the scope of transferred data. Processing of the tender documents uploaded to the platform is governed by separate documents, in particular the customer agreement and the data processing agreement. That is where you confirm that documentation is analysed in a closed EU environment and is not passed to external language models.
This does not remove the customer’s responsibility to assess risk. It does, however, give IT teams specific points they can turn into an internal security checklist.
Access control in the tender process: definition for citation
Access control in the tender process is a set of rules, roles and permissions that defines who in an organisation may view, analyse, edit, download or approve tender documents and offer-related data. Its purpose is to restrict access to confidential information to people who genuinely need it to perform their work, while preserving activity history and accountability for decisions.
Access control matters in tenders because one process often involves many people: sales, bid teams, finance, legal, technical experts, management and sometimes external consultants. Without clear roles, the process becomes messy quickly: too many people have access to sensitive files, nobody knows which version is current, and accountability for the go / no-go decision becomes blurred.
Example role and permission table
| Role | Document access | Typical permissions | What this role should not do |
|---|---|---|---|
| Board / director | Summaries, risks, recommendations | Go / no-go decision, budget approval, strategy sign-off | Edit working analyses without change history |
| Bid manager | Full tender documentation | Process coordination, task assignment, comments, deadline control | Independently approve legal or financial terms |
| Technical expert | Scope of work, specifications, technical attachments | Requirement review, equivalence analysis, technical risk identification | Change the final offer without process owner approval |
| Legal team | Draft contract, clauses, formal conditions | Review penalties, liability, termination rules and formal risks | Make commercial decisions without business data |
| Finance | Budget, price criteria, bid bonds, guarantees | Assess profitability, cash flow and proposal preparation costs | Approve technical compliance |
| IT / security | Metadata, settings, logs, configuration | Access control, audit, security configuration | Read offer content without justified need |
| External consultant | Selected files or excerpts | Provide expert opinion in a limited scope | Receive full access to pricing strategy and commercial data |
The simplest rule is this: access should be granted based on business need, not convenience. Someone reviewing a technical clause does not need to see the full margin model. A consultant helping with one attachment should not receive the entire tender history.
GDPR and AI document analysis: what should you check in practice?
GDPR does not prohibit the use of AI for document analysis. It requires personal data processing to have a legal basis, be aligned with the processing purpose, limited to what is necessary and properly secured. The European Commission explains that personal data may be processed on grounds such as consent, contract, legal obligation, public interest or legitimate interest, depending on the specific purpose (legal grounds for processing data, European Commission).
In the tender context, two layers should be separated.
The first layer is personal data in documents. This may include names of signatories, representatives, project team members, technical experts, references, certificates or contact details. The second layer is confidential business information, which is not always personal data but still carries high commercial value: prices, schedules, know-how, delivery conditions, market entry strategy or planned subcontracting.
For GDPR purposes, four questions are especially important.
1. Who is the data controller?
Usually, the controller of personal data included in tender documents will be the company using the tool, because it decides which documents are uploaded for analysis and for what purpose.
2. Who is the processor?
The AI tool provider may act as a processor if it processes personal data on behalf of the customer. In that case, the relationship should be regulated by a data processing agreement. Article 28 GDPR requires processing by a processor to be governed by a contract or other legal act that defines, among other things, the subject matter, duration, nature and purpose of processing, type of data, categories of data subjects and the obligations of both parties.
3. Is data processed only for the agreed purpose?
Tender document analysis has a specific purpose: extracting requirements, risks, deadlines, evaluation criteria and information needed to make a bid decision. Data should not be used for secondary purposes, especially for training public or external models, unless the customer has accepted it.
4. Does the organisation have evidence of compliance?
In practice, saying “we follow GDPR” is not enough. Teams should have a data processing agreement, a description of safeguards, a list of sub-processors, retention rules, a deletion procedure, access history and a clear explanation of how AI document analysis works.
How can AI work on documents without increasing leakage risk?
The safest model for using AI in tenders is not one where the system “makes up answers”. It is one where the system helps teams find, structure and quote information that already exists in the documentation.
That is a major difference.
When a bid manager asks, “does the tender specification require ISO 27001?”, the answer should show where the requirement appears in the documents. When a lawyer asks, “what are the penalties for delay?”, the system should point back to the relevant clause in the draft contract. In Minerva’s materials, this approach is described as a shift from passive reading to actively querying documents: instead of scrolling through hundreds of pages, the team can ask the file about a specific clause, deadline or requirement.
For security, three rules matter most.
First, AI should not replace human accountability. Minerva does not automatically submit final offers. This is a deliberate product decision that helps users maintain legal and commercial control over the tender documentation.
Second, answers should be verifiable. The system should shorten the path to information, but the decision should remain with a person who can see the source, context and business consequences.
Third, documents should not enter an uncontrolled circulation. When a tool states that data is processed in a closed environment, in the EU, without training external systems, IT teams have a basis for further security review instead of relying on general trust in “AI”.
Security checklist to discuss with an AI provider
Before deploying AI for tender document analysis, go through a short checklist:
- Data encryption in transit and at rest.
- Data storage in the EU or a clear description of transfers outside the EEA.
- No model training on customer data without explicit approval.
- No transfer of tender documentation to external language models, or a clear explanation of when and on what basis this happens.
- User roles and permissions inside the organisation.
- Activity and change history showing who worked on the documents.
- Data processing agreement compliant with Article 28 GDPR.
- Data deletion or return procedure after the cooperation ends.
- List of sub-processors and how they are controlled.
- Administrative access rules on the provider’s side.
- Incident response procedures and customer notification rules.
- Ability to discuss safeguards with the provider’s team, including data location, access control, retention and the way AI works on documents.
This list is not a formality. It is a practical way to move the AI conversation from emotion to control.
Why does this matter for larger teams?
In a small company, one person may be enough to “watch tenders”. In a larger organisation, the process is distributed. Someone searches for opportunities, someone analyses the tender specification, someone calculates profitability, someone reviews legal risk, and someone approves the final decision. The more people are involved, the higher the risk that documents start circulating through email, messaging tools and local folders.
Paradoxically, a properly implemented AI tool can reduce risk rather than increase it. Instead of sending attachments between departments, the team works in one environment, with role-based access, activity history and structured analysis. This is especially important where tender document confidentiality overlaps with regulatory requirements: in healthcare, energy, critical infrastructure, IT and the public sector.
Minerva automates tender discovery, qualification and document analysis, but leaves final responsibility with experts. That is a healthy model for using AI in public tenders: technology accelerates selection and extracts information, while people make the decision. If you want to connect this process to your own systems, see how tender process automation with CRM, ERP and BI works in practice.
For IT and security teams, it is also worth reviewing the privacy policy and speaking directly with the Minerva team about safeguards, data location and access control.
FAQ: GDPR and AI data security in tenders
Can AI analyse confidential tender documents?
Yes, provided the tool operates in a controlled environment, has clear data storage rules, does not use customer documents for unapproved model training and allows access to be restricted by user role. The label “AI” is not enough. Architecture, contracts and process matter.
Do tender documents contain personal data?
Often, yes. They may include data of signatories, representatives, experts, project team members, references, certificates or contact details. That is why AI document analysis should also be assessed from a GDPR perspective.
Does GDPR prohibit using AI for document analysis?
No. GDPR requires lawful processing, purpose limitation, data minimisation, security and accountability. The organisation must know why it processes data, on what basis, to whom it entrusts the data and how it secures it.
Where should data be stored?
For EU companies, the simplest and safest operational model is data storage in the EU. When data is transferred outside the EEA, the provider should explain the transfer mechanism, such as standard contractual clauses, and any additional safeguards.
Can data from tender documents train an AI model?
It should not, unless the customer has knowingly and explicitly agreed to it. In the tender context, the default rule should be no training of external models on customer data, because documents contain strategy, pricing and confidential information.
Who should have access to tender documents?
Only people who need access to perform their role. A bid manager needs a broader view than a technical consultant. Finance does not need to see every technical attachment, and an external consultant should not receive the full pricing strategy.
Does Minerva automatically submit offers?
No. Minerva supports tender discovery, qualification and document analysis, but it does not automatically submit final offers. This matters from the perspective of legal control and business accountability.
What should IT ask before approving the tool?
IT should ask about data location, sub-processors, retention rules, the data processing agreement, access control and whether documents are sent to external language models or used to train models.
What should you do next?
When your team considers using AI for tenders, do not start with the question: “is AI safe?”. Start with a checklist: where is the data, who has access, is there a data processing agreement, do documents train the model and are AI answers based on source citations?
Want to assess this with IT or security? Book a call with the Minerva team to see how procurement data protection, access control and document analysis work in practice.
Book a call in 30 seconds
You will receive:
Trusted by 450+ organisations, from growing businesses to large enterprises.



