GDPR and AI: Compliance Guide

The GDPR does not ban AI, but it applies fully to personal data used by AI systems. This guide covers the obligations that matter most when you deploy AI that touches personal data.

Start the free assessment — results on the page, no email required.

Lawful basis and purpose limitation

Every use of personal data in AI needs a lawful basis and a defined purpose. Document both before processing, and avoid repurposing data for AI without a compatible basis.

DPIAs for high-risk uses

A Data Protection Impact Assessment is expected for high-risk processing, which can include profiling and certain automated decisions. Record the assessment and mitigations.

Data minimisation and accuracy

Use the least personal data required, and address accuracy — AI outputs about people must not rest on inaccurate data without safeguards.

Processor agreements and transfers

AI vendors that process personal data need a data processing agreement, and international transfers need a valid mechanism such as SCCs plus a transfer assessment.

Data subject rights and transparency

People can exercise access, erasure, and objection rights. Know how AI systems can honour them, and be transparent about automated decision-making.

Frequently asked questions

Does the GDPR ban AI?

No. It applies to personal data processed by AI, so the obligations are about lawful basis, risk assessment, minimisation, agreements, transfers, and rights — not a ban on AI itself.

When do we need a DPIA?

For high-risk processing, which can include profiling and some automated decisions. If in doubt, document your reasoning either way.

Can we use AI vendor data for training?

Only where there is a lawful basis and a suitable agreement. Check the vendor's training and data-use terms and record your position.

Related resources