AI under the GDPR and EU data law
Where an AI system meets European data protection law: lawful basis, DPIAs, transfers, automated decisions, and what happens to a trained model when a subject exercises a right.
The GDPR does not have an AI chapter, and it did not need one to apply. Every article in it was written against a picture of processing in which personal data is held somewhere you can point at — a row, a file, a log line. Training a model does not fit that picture. The data goes in, the weights come out, and nothing in the result looks like a record you can retrieve, correct or delete. The obligations still attach; it is the familiar answers to them that stop working.
These pages take one instrument at a time and work out what it actually requires of a system built on a language model. Where the position is settled, the article and the case are named. Where it is not — and on the questions that matter most, it is not — the page says who disagrees and what would resolve it, rather than picking the reading that makes the paragraph tidier. None of this is legal advice.
DPIA Triggers Specific to an AI System
How Article 35(3) and the nine-criteria screening test land on real AI processing, and the scenarios where the answer is genuinely no.
9 min read
Structuring a DPIA for a Generative AI Feature
The four sections Article 35(7) actually requires, written out against a customer-facing chat feature, with the questions each section has to answer.
10 min read
Article 22's “Meaningful Human Involvement” Threshold
What a human reviewer has to actually do before a decision stops being solely automated, and the review designs that fail the test.
9 min read
What Counts as a “Solely Automated Decision” Under GDPR
The two limbs of Article 22(1) — a decision, and a legal or similarly significant effect — read against the CJEU's SCHUFA ruling on scores that drive somebody else's decision.
9 min read
Can You Get “Your Data” Out of a Trained Model? Article 15 Access Requests
What a controller can honestly return under Article 15 when the personal data is diffused across weights rather than stored in a record, and which parts of the request are still easy.
10 min read
Rectifying AI-Hallucinated Personal Data Under GDPR
What Article 16 requires when a model states something false about a named person, and why the complaints testing this question have not been resolved.
9 min read
Data Portability and AI-Derived Profiles Under GDPR
Why Article 20's “provided by the data subject” limit generally stops short of inferred profiles, and which other right the requester probably wanted.
8 min read
The Right to Object to Profiling by an AI System
How Article 21 works against profiling that is entirely lawful, why it is a different right from Article 22, and what a controller has to do when it is exercised.
9 min read
When an AI-Heavy Company Must Appoint a Data Protection Officer
Article 37(1)'s core activities, large scale and regular systematic monitoring tests applied to the processing patterns AI companies actually run.
9 min read
Writing a Legitimate Interest Assessment for AI Training
The three cumulative conditions the Court of Justice reads into Article 6(1)(f), written out line by line against a model-training scenario.
10 min read
What Happens to a Trained Model When Consent Is Withdrawn
Article 7(3) stops future processing and does not undo the past; the harder question is what Article 17 reaches once the data is inside a set of weights.
9 min read
Purpose Limitation and Reusing Customer Data to Train a Model
The Article 6(4) compatibility test, when it is available at all, and how its five factors land on support tickets and product telemetry.
9 min read
Data Minimisation and Large AI Training Datasets: the Tension
The argument that Article 5(1)(c) constrains purpose-fit rather than dataset size is right about the text and does less work than its users need it to.
9 min read
Records of Processing Activities for an AI System (Article 30)
The fields an Article 30 record actually needs when the processing activity is an AI feature, filled in as a working structure rather than described.
10 min read
Biometric AI and Special Category Data Under GDPR Article 9
When biometric processing by an AI system becomes special category data, and which of the narrow Article 9(2) exceptions can actually carry it.
9 min read
Children's Data and AI Products Under GDPR Article 8
When Article 8 engages for an AI product, why the age of consent is different in every member state, and what a product serving EU minors has to implement.
9 min read
Joint Controllership Between an AI Vendor and Its Customer
How the CJEU's joint controllership case law applies to an AI vendor, and when a vendor stops being a processor without anyone renegotiating the contract.
10 min read
Standard Contractual Clauses for an AI Processor: Which Modules Apply
Which of the four 2021 SCC modules fits an AI vendor relationship, and what the annexes have to say that a generic completion does not.
9 min read
Transfer Impact Assessments for a US-Hosted AI Provider
The six-step assessment Clause 14 of the SCCs requires, worked through for a US-hosted model API, including the government-access question it has to answer.
11 min read
The EU-US Data Privacy Framework and AI Vendors
What a DPF self-certification does and does not cover for an AI vendor, and why an SCC-based assessment is often still needed alongside it.
9 min read
Schrems II's Effect on US-Based LLM Providers
The chain from the 2020 judgment to the paperwork an EU company needs today before it can call a US-hosted model, and what the ruling did not decide.
9 min read
Data Processing Agreement Clauses Specific to AI Sub-Processing
The clauses an AI vendor DPA needs beyond the generic Article 28 template, and the one obligation the deletion clause cannot deliver.
11 min read
Sub-Processor Disclosure Obligations for AI Vendors Under GDPR
What Article 28(2) requires when an AI vendor routes your prompts to an upstream model provider, and why a web page nobody is notified about is not enough.
9 min read
Breach Notification Timelines When an AI System Leaks Personal Data
When the 72-hour Article 33 clock starts for an AI-specific leak, and what to file when the facts are still unclear.
10 min read
Privacy by Design Applied to an AI Feature (Article 25)
What Article 25 requires of an AI feature in concrete design terms — defaults, retention windows, opt-in training use — and when the obligation actually bites.
10 min read
Anonymised or Just Pseudonymised? AI Training Data Under GDPR
The test EU regulators actually apply to decide whether a training dataset has left the GDPR's scope, and why most de-identified corpora have not.
10 min read
What Recital 71 Actually Requires as a Right to Explanation
Recital 71 is not an enforceable right, and the transparency duties that are enforceable ask for something different from what people expect.
9 min read
The Exemptions to GDPR's Automated Decision-Making Ban
The three gateways in Article 22(2), the safeguards Article 22(3) attaches to two of them, and the separate bar that Article 22(4) puts in front of special-category data.
9 min read
Web-Scraped Training Data and GDPR's Lawful Basis Question
How the legitimate-interest test in Article 6(1)(f) has actually been applied to scraping-for-training by EU regulators, and which parts of it the scraper controls.
10 min read
Handling a Rights Request Against a Fine-Tuned Model
What a controller can honestly produce and honestly delete when a data subject's request names data that went into a fine-tune, and how to say what cannot be undone.
10 min read
AI Employee Monitoring and Works Council Co-Determination
Why a GDPR-compliant AI monitoring rollout can still be blocked in Germany, France and the Netherlands by a works council right that sits outside the GDPR entirely.
10 min read
GDPR Fines for AI Processing: the Notable Ones, Dated
The enforcement decisions against AI and biometric processing that are actually worth knowing, each with its authority, its date, its amount as announced and its appeal position.
9 min read
Cookie Consent and AI Personalisation Under ePrivacy
Article 5(3) of the ePrivacy Directive governs the storage and access on the device; the GDPR governs what your model then does with what you read. They are different tests.
9 min read
UK GDPR Article 22 After the Data (Use and Access) Act 2025
The DUAA 2025 replaces Article 22 with Articles 22A to 22D, inverting the default for most automated decisions while keeping the restriction for special-category data.
9 min read
Retention Limits for AI Training Datasets Under GDPR
How the storage-limitation principle applies to a training corpus once the model is trained, and why the reasons to keep it are weaker than teams assume.
9 min read
A GDPR Due Diligence Checklist for an AI Subprocessor
The questions a controller should be able to get answered from an AI vendor before signing, built from Articles 28, 30, 32 and 44 to 49 rather than from a generic security questionnaire.
11 min read
The EU Data Act's Device Data Access Rule and AI Training
Articles 3 and 4 give users access to the data their connected products generate, and Article 6 limits what a recipient of that data may build with it.
10 min read
The EU Data Act's Cloud-Switching Rules and AI Infrastructure
Chapter VI removes switching charges entirely from 12 January 2027 and imposes contractual and technical duties in the meantime, with weaker guarantees for the service layers AI actually runs on.
10 min read
Trade Secret Protection When Sharing Data Under the EU Data Act
How the Data Act lets a data holder condition, suspend or refuse an access request to protect a trade secret, and what that ladder means when the requester wants the data for model training.
9 min read
The DMA’s Gatekeeper Rules and Default AI Assistants
How the Digital Markets Act treats virtual assistants as a core platform service, what Article 6(3) requires when one is set as an operating-system default, and what remains undecided about generative assistants.
9 min read
The DMA’s Interoperability Duty and AI-Powered Features
What Article 6(7) actually obliges a gatekeeper to open up, how the security proviso is limited, and why AI features on a designated platform are the hardest case for the duty.
9 min read
The DMA’s Self-Preferencing Rules and AI Answer Engines
How Article 6(5)'s ranking prohibition applies when a gatekeeper search engine places its own generated answer above organic results, and which parts of that question are open.
9 min read
Colorado’s AI Act: the Duty of Care Standard, Explained
What “reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination” imports as a legal standard, and how the presumption and affirmative defence change what it costs to meet.
9 min read
Colorado’s AI Act: How It Defines Algorithmic Discrimination
The statutory definition, the protected classes it lists, the exclusions it carves out, and why the word “unlawful” inside it borrows the whole of existing discrimination law.
9 min read
Colorado’s AI Act: the Impact Assessment Requirement
What SB 24-205 requires a deployer's impact assessment to contain, the annual and modification triggers that make it recurring, the retention period, and who is exempt.
9 min read
Colorado’s AI Act: the Effective Date, and Why It Moved
The dates: signed May 2024, originally effective 1 February 2026, moved to 30 June 2026 by an August 2025 special-session bill — with each date sourced to the legislature's own record.
7 min read
Colorado’s AI Act: the Separate Developer and Deployer Duties
The two obligation sets side by side, which role you are actually in, and the substantial-modification rule that turns a deployer into a developer.
10 min read
California’s AI Transparency Act (SB 942): the Provenance Requirements
Who counts as a covered provider under SB 942, the three duties it imposes — a detection tool, latent disclosure, optional manifest disclosure — the licensee revocation rule, and the operative date after AB 853.
9 min read
California’s AB 2013: the Training Data Disclosure Law
The twelve-ish items AB 2013 requires a generative AI developer to publish about its training datasets, who counts as a developer, the January 2026 posting date, and the enforcement gap in the statute.
10 min read
California’s AB 1008: Applying the CCPA to AI-Generated Output
What AB 1008 changed in the CCPA's definition of personal information, why the change is about format rather than about new rights, and which consumer rights become hard to answer once a model is inside scope.
9 min read
Other topics
- LLM fundamentals & architecture
- Tokens, tokenization & context windows
- Prompt engineering
- Reasoning models & test-time compute
- Multimodal AI: vision, audio, video
- RAG & retrieval
- Embeddings & vector search
- AI agents & tool use
- Structured output & function calling
- Fine-tuning & post-training
- Local inference errors, string by string
- Running local models day to day
- Testing code that calls an LLM
- Snapshot and property testing for model output
- Regression suites for prompts
- Eval gates in CI
- Flaky tests against a model
- Determinism and the cost of testing
- Contract and streaming tests
- Testing tool calls and retrieval
- Inference, serving & latency
- Rolling out a prompt change
- Testing AI systems in practice
- Forecasting a time series
- Machine learning on tabular data
- Geospatial data and models
- Understanding audio that is not speech
- Understanding video
- Core computer vision tasks
- Machine learning on graphs
- Point clouds and 3D
- Evaluation, benchmarks & LLM-as-judge
- Sensor and IoT data
- Logs and event streams
- Models over biological sequences
- Machine learning on molecules
- Embedding and searching code
- Extracting invoices and purchase orders
- Receipts, statements and tax forms
- Insurance policies and contracts
- Deeds, court filings and patents
- Extracting from medical records
- Observability & LLMOps
- CVs, certificates and identity documents
- Shipping, customs and technical documents
- Meetings, email, chat and filled-in forms
- Building an extraction pipeline
- Business, property and inspection documents
- Contract clauses and insurance claims
- Regulated and compliance documents
- Consumer, travel and closing documents
- Mapping one chat API onto another
- SDK and framework migrations
- Hallucination & failure modes
- Re-embedding and model deprecation
- Cutting over between providers
- Parity gaps, shims and legacy endpoints
- Moving between model versions
- Migrating vector stores and caches
- Mapping capabilities and parameters
- Migrating pipelines and agents
- Contracts, runbooks and rollback
- Auditing a codebase before a cutover
- Compliance and fine-tune migration
- LLM cost engineering
- Routing, cost tracking and multi-tenancy
- What a migration does to your prompts
- AI security & prompt injection
- Privacy, compliance & data residency
- AI governance, policy & society
- Building reliable AI applications
- AI hardware, GPUs & compute
- Open-weight models & local inference
- AI for developers & coding agents
- AI in industry: vertical playbooks
- AGI, superintelligence, alignment & the long future
- Machine learning foundations
- NLP fundamentals & classical tasks
- Data engineering for AI
- Synthetic data & dataset curation
- AI product design & UX
- Search, ranking & recommendation
- Enterprise adoption & change management
- AI careers, skills & teams
- Reading AI research
- AI in science & discovery
- Robotics & embodied AI
- AI economics, markets & business models
- AI myths, hype & media literacy
- Context engineering
- Shipping AI features: patterns & anti-patterns
- Build it: end-to-end AI tutorials
- Python for AI: hands-on recipes
- TypeScript, React and the web
- Frameworks and SDKs
- Errors and troubleshooting
- AI facts, numbers and statistics
- The history of AI
- The maths behind AI
- Architectures beyond the transformer
- Reinforcement learning
- Diffusion and generative media
- Speech, audio and voice engineering
- Benchmarks, one at a time
- AI search visibility
- Infrastructure and operations
- Databases and storage for AI
- Knowledge graphs and structured knowledge
- Classical ML in production
- Regulation, jurisdiction by jurisdiction
- Prompt recipes and pattern library
- AI for people who do not write code
- Writing, media and creative work
- Edge and on-device AI
- Interpretability and model internals
- Field notes
- OpenAI model behaviour
- Claude model behaviour
- Gemini model behaviour
- Llama model behaviour
- Mistral model behaviour
- Qwen model behaviour
- DeepSeek model behaviour
- Cohere model behaviour
- Grok model behaviour
- Small model behaviour
- Hybrid model architectures
- Token cost by language and script
- Transliteration, romanization and script handling
- Locale-correct output
- Multilingual generation quality
- Multilingual pipelines
- The EU AI Act, article by article
- US AI regulation, state and sector
- International AI governance and standards
- AI litigation and enforcement
- Running AI workloads on AWS
- Running AI workloads on Google Cloud
- Running AI workloads on Azure
- AI at the edge: Workers, Vercel and Netlify
- Serving models on Kubernetes
- Operating AI infrastructure
- Quantization formats and what they cost
- llama.cpp, flag by flag
- Ollama and the desktop local-model runtimes
- Local models on Apple Silicon
- Hardware for local inference
- Running speech and embedding models locally
- Model files, adapters and conversion
- VRAM arithmetic for local models