General Data Protection Regulation, AI Provisions
The EU's landmark data protection law contains critical provisions for AI systems that process personal data, including automated decision-making rules.
- European Union
- Law
- Current
- GDPR applies from: 2018-05-25
EU-GDPR-2016-679-ARTS-3-6-9-22-33-35-89Source checked: Resources ↗
Overview
The GDPR entered into force on 24 May 2016 and has applied since 25 May 2018. It is not an AI-specific law, but it can apply when AI involves personal-data processing within Article 3’s territorial scope. Assess establishment, offering goods or services, or monitoring behaviour in the EU as applicable; an individual’s EU citizenship alone is not the scope test.
Article 22 addresses decisions based solely on automated processing that produce legal or similarly significant effects. Identify whether that threshold is met, whether an exception applies and which safeguards are required. Do not infer that every AI-assisted decision is prohibited or gives the same right to human intervention. The information duties in Articles 13 to 15 must be assessed in their own context.
AI processing requires an applicable Article 6 lawful basis. Processing special-category data also needs an Article 9 condition where relevant. Consent and legitimate interests have their own tests; neither is a blanket permission to train a model. Scientific-research safeguards or derogations are not a standalone Article 6 lawful basis. Document the purpose, role and conditions for each processing stage.
Data minimisation (Article 5(1)(c)) presents a fundamental tension with AI development, which often benefits from large datasets. Organisations must ensure they collect only data that is adequate, relevant, and limited to what is necessary for the specified purpose. This impacts AI training data strategies and requires careful justification for dataset scope.
Articles 13 to 15 include information duties concerning covered automated decision-making, including meaningful information about the logic involved and the envisaged consequences where those provisions apply. Provide intelligible information for the affected person; do not promise that publishing a model card alone satisfies every transparency or access obligation.
A DPIA is required before processing likely to create a high risk to people’s rights and freedoms under Article 35. Consider the nature, scope, context and purposes, the listed cases and relevant supervisory-authority criteria. AI use or scale alone is not a substitute for that assessment. Record necessity, proportionality, risks and planned safeguards.
Purpose limitation still applies to training and subsequent use. Article 5 and Article 89 provide specific treatment and safeguards for scientific research and statistical purposes; they do not make all commercial AI training lawful or remove the need for a legal basis. Assess any claimed research purpose and applicable derogation rather than treating an AI project as automatically exempt.
The international transfer provisions (Chapter V) also affect AI systems, particularly cloud-based AI services and models trained on data from multiple jurisdictions. Organisations must ensure adequate safeguards for any transfer of personal data outside the EEA.
Data protection authorities across Europe have been increasingly active in enforcing GDPR against AI systems. Notable enforcement actions have targeted facial recognition companies, AI-driven advertising systems, and automated credit scoring, establishing precedents that shape how organisations must govern AI processing of personal data.
Key Requirements
Establish a lawful basis for processing personal data in AI systems (Article 6)
Implement safeguards for automated individual decision-making (Article 22)
Provide meaningful information where the automated-decision information duties in Articles 13 to 15 apply.
Implement human-intervention and challenge safeguards where required by Article 22 or other applicable law.
Conduct Data Protection Impact Assessments for high-risk AI processing (Article 35)
Apply data minimisation principles to AI training and operational data
Ensure purpose limitation for AI model training and inference
Implement privacy by design and by default in AI systems (Article 25)
Maintain records of processing activities involving AI (Article 30)
Enable data subject rights: access, rectification, erasure, portability for AI-processed data
Appoint a Data Protection Officer if required for AI processing activities
Ensure lawful international data transfers for AI services (Chapter V)
Implement appropriate technical and organisational security measures (Article 32)
Controllers assess supervisory-authority notification without undue delay and, where feasible, within 72 hours of awareness, unless risk to rights and freedoms is unlikely. Processors notify the controller without undue delay (Article 33).
Key Dates & Timeline
GDPR enters into force
GDPR becomes applicable
EDPB adopts its ChatGPT Taskforce report
EDPB adopts Opinion 28/2024 on AI models, including lawful-basis and anonymity assessment
Who It Affects
- Organisations whose AI-related personal-data processing falls within GDPR Article 3
- AI developers with an applicable EU establishment, market-targeting or monitoring connection
- Organisations using AI for automated decision-making about individuals
- Cloud AI service providers handling EU personal data
- Organisations transferring personal data internationally for AI processing
- Data processors providing AI-as-a-service involving personal data
Frequently Asked Questions
Can I train AI models on personal data under GDPR?
Only where the processing has a valid Article 6 basis and meets the other applicable requirements. Special-category data may also require an Article 9 condition. Research safeguards are not a standalone lawful basis. Assess each training purpose, transparency, minimisation and whether a DPIA is required; do not assume a blanket permission.
Do I need to explain how my AI model works under GDPR?
For automated decisions under Article 22, you must provide meaningful information about the logic involved. This doesn't necessarily require full technical explainability, but data subjects should understand the key factors influencing decisions and the general logic of the system.
How does GDPR interact with the EU AI Act?
The EU AI Act complements GDPR without replacing it. AI systems processing personal data must comply with both. The AI Act adds requirements for risk management, conformity assessment, and transparency that go beyond data protection. DPIAs under GDPR and fundamental rights impact assessments under the AI Act may overlap.
Stay Ahead of AI Regulations
Receive AI regulatory updates to help prepare your next review.