GDPR and AI: Compliance Guide
The GDPR does not ban AI, but it applies fully to personal data used by AI systems. This guide covers the obligations that matter most when you deploy AI that touches personal data.
Start the free assessment — results on the page, no email required.
Lawful basis and purpose limitation
Every use of personal data in AI needs a lawful basis and a defined purpose. Document both before processing, and avoid repurposing data for AI without a compatible basis.
DPIAs for high-risk uses
A Data Protection Impact Assessment is expected for high-risk processing, which can include profiling and certain automated decisions. Record the assessment and mitigations.
Data minimisation and accuracy
Use the least personal data required, and address accuracy — AI outputs about people must not rest on inaccurate data without safeguards.
Processor agreements and transfers
AI vendors that process personal data need a data processing agreement, and international transfers need a valid mechanism such as SCCs plus a transfer assessment.
Data subject rights and transparency
People can exercise access, erasure, and objection rights. Know how AI systems can honour them, and be transparent about automated decision-making.
Frequently asked questions
Does the GDPR ban AI?
No. It applies to personal data processed by AI, so the obligations are about lawful basis, risk assessment, minimisation, agreements, transfers, and rights — not a ban on AI itself.
When do we need a DPIA?
For high-risk processing, which can include profiling and some automated decisions. If in doubt, document your reasoning either way.
Can we use AI vendor data for training?
Only where there is a lawful basis and a suitable agreement. Check the vendor's training and data-use terms and record your position.