web analytics
Sector Rules

GDPR and AI

EU Data Protection Rules for AI

The one-paragraph answer

GDPR AI compliance applies to any AI system processing personal data of individuals in the European Economic Area, regardless of where the company is based. The General Data Protection Regulation requires a lawful basis for processing, transparency, data-subject rights, security safeguards, and, for high-risk AI processing, a Data Protection Impact Assessment (DPIA). Article 22 specifically restricts fully automated decision-making with legal or similarly significant effects.

The pain GDPR AI compliance is causing our customers

US companies expect GDPR to be a European issue. It is not. GDPR reaches any organization processing personal data of EU residents, regardless of where the organization is located. AI amplifies GDPR exposure because AI often processes large volumes of personal data and often produces the kind of automated decision-making Article 22 restricts. When a US company's AI system evaluates an EU applicant, an EU customer, or an EU user, GDPR obligations attach, and enforcement authorities are not shy about pursuing extraterritorial cases.

What GDPR AI compliance requires

Lawful basis

Every processing operation needs one of six lawful bases: consent, contract, legal obligation, vital interests, public task, or legitimate interests. For AI training on personal data, most organizations rely on consent or legitimate interests, both of which carry specific documentation and transparency obligations.

Transparency and information rights

Data subjects must be informed about how their data is used, including AI processing. Privacy notices must be specific, not generic. AI use should be disclosed.

Article 22: Automated decision-making

Data subjects have the right not to be subject to decisions based solely on automated processing (including profiling) that produce legal effects or similarly significantly affect them, except in narrow cases (contract necessity, explicit consent, member state law). Where automated decisions are permitted, the controller must implement safeguards including the right to human intervention, explanation, and challenge.

Data Protection Impact Assessments

DPIAs are required for high-risk processing, which includes many AI use cases: systematic and extensive profiling, large-scale processing of sensitive data, and systematic monitoring of publicly accessible areas. DPIAs must document the processing, assess risks, and identify mitigations.

Data subject rights

Access, rectification, erasure, restriction, portability, objection. AI systems must support all of these, which raises specific challenges (e.g., how to delete data from a trained model).

International data transfers

Transferring EU personal data outside the EEA requires appropriate safeguards: Standard Contractual Clauses, Binding Corporate Rules, or an adequacy decision. This affects US companies training AI on EU data.

Why GDPR AI compliance matters to you

Fines under GDPR can reach 20 million euros or 4 percent of global annual turnover, whichever is higher. Enforcement is active. Data protection authorities have pursued AI cases against major US technology companies. The EU AI Act adds further obligations on top of GDPR for high-risk AI, but GDPR remains the baseline data protection framework.

What the research says about GDPR AI

The academic literature on GDPR AI is ahead of most corporate practice, and it is unusually blunt. Two findings are worth putting in front of any executive who thinks this is a compliance formality.

“concerns about their impact on individual and societal wellbeing, particularly due to the lack of transparency and accountability”

That is the gap between having AI and governing it. The second finding is the one that tends to change the room.

“the understanding of how such principles can be operationalized in designing, executing, monitoring, and evaluating AI applications is limited”

Neither of these is a fringe position. Both come from peer-reviewed work, and both describe the condition most organisations are actually in when the question about GDPR AI arrives from the board, the buyer, or the regulator.

How to get compliant with GDPR and AI: a 5-step path

This is the sequence that works, and it is not the sequence most organisations choose. They start with the framework and work backwards toward reality. Start with reality.

  1. Inventory the AI in scope. List every AI system that could fall under GDPR AI. Record what it does, what decision it influences, what data it touches, and who owns it. You cannot govern AI you cannot name, and almost every organisation we assess is running more AI than its leadership believes.
  2. Determine whether you are actually in scope. Work out precisely which of your AI systems and activities GDPR AI reaches, and write the determination down with its reasoning. Do this in writing. A documented scope determination, right or wrong, is defensible. An undocumented assumption is not.
  3. Assign one accountable owner. Name a person, not a committee, with the authority to stop a deployment. Governance without someone who can say no is documentation, not control.
  4. Build the evidence file. Assemble the documentation GDPR AI expects: the scope, the risk assessment, the controls, the testing evidence, and the incident record. Assemble it before anyone asks. Reconstructing it under a regulator's deadline costs several times more and looks exactly like what it is.
  5. Set a review cadence and hold it. Re-run the assessment on a schedule and after any material change to the model, the data, or the use case. Alignment decays. A control tested once is a snapshot, not a control.

Done in this order, GDPR AI becomes tractable. Done out of order, it becomes a document nobody uses and a control nobody exercises.

Frequently asked questions about GDPR AI compliance

Does GDPR apply if we have no EU office?

Yes, if you process personal data of individuals in the EEA in connection with offering goods or services or monitoring their behavior. Location of the controller does not matter.

Can we train AI on EU personal data?

Yes, with appropriate lawful basis, transparency, and safeguards. Legitimate interests is a common basis but requires documented balancing.

What is the right to explanation under GDPR?

Where automated decisions with significant effects are made, data subjects have the right to meaningful information about the logic involved and the significance and envisaged consequences. Not a full source-code disclosure, but a meaningful explanation.

Where does GDPR AI compliance fit in SRJ's work?

Volume III of The Operating Discipline for AI Library™ addresses GDPR-specific AI compliance in the international addendum. The AI Business Enablement Audit™ assesses GDPR exposure for US clients with EU-facing operations.

Primary sources on GDPR AI

The authoritative texts and agency pages behind this summary. We keep this page current, but where a compliance decision turns on exact wording, read the source. Anything concerning GDPR AI that carries legal consequence should be confirmed against the enrolled text or the issuing body, not against a secondary summary, including this one.

Ready to see where you stand?

The AI Business Enablement Audit™ measures your organization against every framework in this library, including GDPR and AI, and delivers a defensible governance dossier. Start or finish your audit below.

Start or finish your AI Audit →
Schedule a Free AI Consultation