30 jours d'essai gratuit, risques IA générative :Commencer
Aller au contenu principal

GDPR AI Compliance

GDPR AI Compliance for European Enterprises

AI tools processing personal data without a lawful basis, DPIAs, or data processing agreements put your organisation at risk of GDPR enforcement. Aona discovers AI use on covered endpoints, applies configured data-protection policies to supported interactions and provides evidence for your privacy review.

supported data protection
Policy-led
input to your DPIA review
Inventory
evidence for privacy review
Usage
record retention
Configurable

What GDPR Requires for AI Tools

GDPR applies to all processing of EU personal data, including when employees use AI tools that were never assessed by your DPO.

Lawful Basis for ProcessingArticle 6

Establish a Legal Ground for AI Data Processing

Article 6 of GDPR requires a lawful basis for every instance of personal data processing. When employees use AI tools with personal data, the organisation must identify the applicable legal ground, whether consent, legitimate interest, or contractual necessity. Most consumer AI tools do not provide the contractual or technical framework needed to establish a valid lawful basis.

Data Protection Impact AssessmentsArticle 35

DPIAs for AI Tools Processing Personal Data

Article 35 mandates a DPIA when processing is likely to result in high risk to individuals. AI tools that process personal data at scale, involve profiling, or use new technologies trigger this requirement. A DPIA must assess the necessity and proportionality of the processing, evaluate risks to data subjects, and identify measures to mitigate those risks.

Automated Decision-MakingArticle 22

Rights Related to AI-Driven Decisions

Article 22 grants individuals the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. Organisations using AI for hiring, credit scoring, or customer segmentation must ensure human oversight, provide explanations of the logic involved, and allow individuals to contest automated decisions.

Data MinimisationArticle 5

Limit Personal Data in AI Prompts

Article 5(1)(c) requires that personal data be adequate, relevant, and limited to what is necessary. When employees paste customer records, emails, or support tickets into AI tools, they often share far more personal data than required for the task. Data minimisation principles must be enforced technically, not just through policy.

Cross-Border TransfersChapter V

Transfer Rules for AI Services Outside the EU

Chapter V of GDPR restricts transfers of personal data to countries outside the EU/EEA that do not provide adequate protection. Many AI tools, including ChatGPT, Claude, and Gemini, are operated by US-based companies. Organisations must ensure appropriate safeguards such as Standard Contractual Clauses (SCCs) or adequacy decisions are in place before personal data is processed by these services.

The Shadow AI Problem Under GDPR

Employees are adopting AI tools faster than privacy teams can assess them. These tools frequently process EU personal data without the safeguards GDPR requires.

  1. US-Based AI Tools with EU Data

    Employees routinely use ChatGPT, Gemini, and other US-based AI tools to process customer emails, support tickets, and internal documents containing EU personal data, often without Standard Contractual Clauses or any data processing agreement in place.

  2. ChatGPT Storing Conversation Data

    By default, ChatGPT stores conversation data for model training. When employees enter personal data of EU residents into ChatGPT, that data may be retained, processed for purposes beyond the original intent, and stored outside the EU, all without a lawful basis.

  3. AI Tools Without DPAs

    Many AI tools used by employees lack proper Data Processing Agreements (DPAs) as required by Article 28. Without a DPA, the organisation has no contractual control over how the AI vendor processes personal data, no audit rights, and no guarantees on data deletion or sub-processor management.

How Aona Helps With GDPR AI Compliance

Employee AI visibility and supported data-protection controls to inform your organisation's GDPR review.

  1. Discover AI Use on Covered Endpoints

    Aona discovers AI tool use where its browser plugin or native app is deployed. Use the inventory and recorded data-risk information to identify tools for privacy review. Your team assesses processing activities and whether appropriate DPAs and SCCs are in place.

  2. Inform DPIAs With AI Usage Evidence

    Use AI tool inventory, data-risk information and policy events from covered endpoints to inform your DPIA review. Your privacy team determines whether a DPIA is required, manages its completion and decides whether processing may proceed.

  3. Apply Personal Data Protection Policies

    Aona detects sensitive data in supported AI interactions and applies configured policies to block or redact it. Your team determines which tools are approved for the relevant data and contractual requirements. Supported controls can contribute to your data-minimisation practices.

  4. Evidence for Your GDPR Review

    Review recorded AI usage and policy events to support your Article 30 records, privacy assessments and investigations. Records depend on endpoint deployment, supported clients and input paths, and configured retention; they are not a complete record of organisational processing or proof of GDPR compliance.

FAQ

Frequently Asked Questions

Does GDPR apply to AI tools used by employees?
Yes. When employees use AI tools to process personal data of EU residents, GDPR applies in full. This includes entering customer names, email addresses, or any identifiable information into AI tools like ChatGPT. The organisation remains the data controller and is responsible for ensuring lawful processing, even when employees use AI tools without IT approval.
Do I need a DPIA for AI tools?
In most cases, yes. Article 35 of GDPR requires a Data Protection Impact Assessment when processing is likely to result in a high risk to individuals. AI tools that process personal data at scale, involve automated decision-making, or use new technologies generally require a DPIA. Many data protection authorities have specifically identified AI as a technology that triggers DPIA requirements.
Can employees use ChatGPT under GDPR?
Employees can use ChatGPT for tasks that do not involve personal data of EU residents. However, entering personal data into ChatGPT raises significant GDPR concerns: there may be no lawful basis for the processing, OpenAI may transfer data outside the EU, and the organisation likely lacks a proper data processing agreement. Organisations should implement clear AI usage policies and technical controls to prevent personal data from entering unapproved AI tools.
How does GDPR Article 22 apply to AI?
Article 22 gives individuals the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects. When organisations use AI to make decisions about employees, customers, or applicants, Article 22 requires human oversight, the right to contest the decision, and transparency about the logic involved.
Get started

Secure AI Across Your European Operations

Discover AI use on covered endpoints, configure supported data-protection controls and gather usage evidence for your GDPR review.

GDPR AI Compliance, Managing AI Under EU Data Protection Rules | Aona AI