Skip to content

AI under the GDPR and EU data law

Where an AI system meets European data protection law: lawful basis, DPIAs, transfers, automated decisions, and what happens to a trained model when a subject exercises a right.

The GDPR does not have an AI chapter, and it did not need one to apply. Every article in it was written against a picture of processing in which personal data is held somewhere you can point at — a row, a file, a log line. Training a model does not fit that picture. The data goes in, the weights come out, and nothing in the result looks like a record you can retrieve, correct or delete. The obligations still attach; it is the familiar answers to them that stop working.

These pages take one instrument at a time and work out what it actually requires of a system built on a language model. Where the position is settled, the article and the case are named. Where it is not — and on the questions that matter most, it is not — the page says who disagrees and what would resolve it, rather than picking the reading that makes the paragraph tidier. None of this is legal advice.

DPIA Triggers Specific to an AI System

How Article 35(3) and the nine-criteria screening test land on real AI processing, and the scenarios where the answer is genuinely no.

9 min read

Structuring a DPIA for a Generative AI Feature

The four sections Article 35(7) actually requires, written out against a customer-facing chat feature, with the questions each section has to answer.

10 min read

Article 22's “Meaningful Human Involvement” Threshold

What a human reviewer has to actually do before a decision stops being solely automated, and the review designs that fail the test.

9 min read

What Counts as a “Solely Automated Decision” Under GDPR

The two limbs of Article 22(1) — a decision, and a legal or similarly significant effect — read against the CJEU's SCHUFA ruling on scores that drive somebody else's decision.

9 min read

Can You Get “Your Data” Out of a Trained Model? Article 15 Access Requests

What a controller can honestly return under Article 15 when the personal data is diffused across weights rather than stored in a record, and which parts of the request are still easy.

10 min read

Rectifying AI-Hallucinated Personal Data Under GDPR

What Article 16 requires when a model states something false about a named person, and why the complaints testing this question have not been resolved.

9 min read

Data Portability and AI-Derived Profiles Under GDPR

Why Article 20's “provided by the data subject” limit generally stops short of inferred profiles, and which other right the requester probably wanted.

8 min read

The Right to Object to Profiling by an AI System

How Article 21 works against profiling that is entirely lawful, why it is a different right from Article 22, and what a controller has to do when it is exercised.

9 min read

When an AI-Heavy Company Must Appoint a Data Protection Officer

Article 37(1)'s core activities, large scale and regular systematic monitoring tests applied to the processing patterns AI companies actually run.

9 min read

Writing a Legitimate Interest Assessment for AI Training

The three cumulative conditions the Court of Justice reads into Article 6(1)(f), written out line by line against a model-training scenario.

10 min read

What Happens to a Trained Model When Consent Is Withdrawn

Article 7(3) stops future processing and does not undo the past; the harder question is what Article 17 reaches once the data is inside a set of weights.

9 min read

Purpose Limitation and Reusing Customer Data to Train a Model

The Article 6(4) compatibility test, when it is available at all, and how its five factors land on support tickets and product telemetry.

9 min read

Data Minimisation and Large AI Training Datasets: the Tension

The argument that Article 5(1)(c) constrains purpose-fit rather than dataset size is right about the text and does less work than its users need it to.

9 min read

Records of Processing Activities for an AI System (Article 30)

The fields an Article 30 record actually needs when the processing activity is an AI feature, filled in as a working structure rather than described.

10 min read

Biometric AI and Special Category Data Under GDPR Article 9

When biometric processing by an AI system becomes special category data, and which of the narrow Article 9(2) exceptions can actually carry it.

9 min read

Children's Data and AI Products Under GDPR Article 8

When Article 8 engages for an AI product, why the age of consent is different in every member state, and what a product serving EU minors has to implement.

9 min read

Joint Controllership Between an AI Vendor and Its Customer

How the CJEU's joint controllership case law applies to an AI vendor, and when a vendor stops being a processor without anyone renegotiating the contract.

10 min read

Standard Contractual Clauses for an AI Processor: Which Modules Apply

Which of the four 2021 SCC modules fits an AI vendor relationship, and what the annexes have to say that a generic completion does not.

9 min read

Transfer Impact Assessments for a US-Hosted AI Provider

The six-step assessment Clause 14 of the SCCs requires, worked through for a US-hosted model API, including the government-access question it has to answer.

11 min read

The EU-US Data Privacy Framework and AI Vendors

What a DPF self-certification does and does not cover for an AI vendor, and why an SCC-based assessment is often still needed alongside it.

9 min read

Schrems II's Effect on US-Based LLM Providers

The chain from the 2020 judgment to the paperwork an EU company needs today before it can call a US-hosted model, and what the ruling did not decide.

9 min read

Data Processing Agreement Clauses Specific to AI Sub-Processing

The clauses an AI vendor DPA needs beyond the generic Article 28 template, and the one obligation the deletion clause cannot deliver.

11 min read

Sub-Processor Disclosure Obligations for AI Vendors Under GDPR

What Article 28(2) requires when an AI vendor routes your prompts to an upstream model provider, and why a web page nobody is notified about is not enough.

9 min read

Breach Notification Timelines When an AI System Leaks Personal Data

When the 72-hour Article 33 clock starts for an AI-specific leak, and what to file when the facts are still unclear.

10 min read

Privacy by Design Applied to an AI Feature (Article 25)

What Article 25 requires of an AI feature in concrete design terms — defaults, retention windows, opt-in training use — and when the obligation actually bites.

10 min read

Anonymised or Just Pseudonymised? AI Training Data Under GDPR

The test EU regulators actually apply to decide whether a training dataset has left the GDPR's scope, and why most de-identified corpora have not.

10 min read

What Recital 71 Actually Requires as a Right to Explanation

Recital 71 is not an enforceable right, and the transparency duties that are enforceable ask for something different from what people expect.

9 min read

The Exemptions to GDPR's Automated Decision-Making Ban

The three gateways in Article 22(2), the safeguards Article 22(3) attaches to two of them, and the separate bar that Article 22(4) puts in front of special-category data.

9 min read

Web-Scraped Training Data and GDPR's Lawful Basis Question

How the legitimate-interest test in Article 6(1)(f) has actually been applied to scraping-for-training by EU regulators, and which parts of it the scraper controls.

10 min read

Handling a Rights Request Against a Fine-Tuned Model

What a controller can honestly produce and honestly delete when a data subject's request names data that went into a fine-tune, and how to say what cannot be undone.

10 min read

AI Employee Monitoring and Works Council Co-Determination

Why a GDPR-compliant AI monitoring rollout can still be blocked in Germany, France and the Netherlands by a works council right that sits outside the GDPR entirely.

10 min read

GDPR Fines for AI Processing: the Notable Ones, Dated

The enforcement decisions against AI and biometric processing that are actually worth knowing, each with its authority, its date, its amount as announced and its appeal position.

9 min read

Cookie Consent and AI Personalisation Under ePrivacy

Article 5(3) of the ePrivacy Directive governs the storage and access on the device; the GDPR governs what your model then does with what you read. They are different tests.

9 min read

UK GDPR Article 22 After the Data (Use and Access) Act 2025

The DUAA 2025 replaces Article 22 with Articles 22A to 22D, inverting the default for most automated decisions while keeping the restriction for special-category data.

9 min read

Retention Limits for AI Training Datasets Under GDPR

How the storage-limitation principle applies to a training corpus once the model is trained, and why the reasons to keep it are weaker than teams assume.

9 min read

A GDPR Due Diligence Checklist for an AI Subprocessor

The questions a controller should be able to get answered from an AI vendor before signing, built from Articles 28, 30, 32 and 44 to 49 rather than from a generic security questionnaire.

11 min read

The EU Data Act's Device Data Access Rule and AI Training

Articles 3 and 4 give users access to the data their connected products generate, and Article 6 limits what a recipient of that data may build with it.

10 min read

The EU Data Act's Cloud-Switching Rules and AI Infrastructure

Chapter VI removes switching charges entirely from 12 January 2027 and imposes contractual and technical duties in the meantime, with weaker guarantees for the service layers AI actually runs on.

10 min read

Trade Secret Protection When Sharing Data Under the EU Data Act

How the Data Act lets a data holder condition, suspend or refuse an access request to protect a trade secret, and what that ladder means when the requester wants the data for model training.

9 min read

The DMA’s Gatekeeper Rules and Default AI Assistants

How the Digital Markets Act treats virtual assistants as a core platform service, what Article 6(3) requires when one is set as an operating-system default, and what remains undecided about generative assistants.

9 min read

The DMA’s Interoperability Duty and AI-Powered Features

What Article 6(7) actually obliges a gatekeeper to open up, how the security proviso is limited, and why AI features on a designated platform are the hardest case for the duty.

9 min read

The DMA’s Self-Preferencing Rules and AI Answer Engines

How Article 6(5)'s ranking prohibition applies when a gatekeeper search engine places its own generated answer above organic results, and which parts of that question are open.

9 min read

Colorado’s AI Act: the Duty of Care Standard, Explained

What “reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination” imports as a legal standard, and how the presumption and affirmative defence change what it costs to meet.

9 min read

Colorado’s AI Act: How It Defines Algorithmic Discrimination

The statutory definition, the protected classes it lists, the exclusions it carves out, and why the word “unlawful” inside it borrows the whole of existing discrimination law.

9 min read

Colorado’s AI Act: the Impact Assessment Requirement

What SB 24-205 requires a deployer's impact assessment to contain, the annual and modification triggers that make it recurring, the retention period, and who is exempt.

9 min read

Colorado’s AI Act: the Effective Date, and Why It Moved

The dates: signed May 2024, originally effective 1 February 2026, moved to 30 June 2026 by an August 2025 special-session bill — with each date sourced to the legislature's own record.

7 min read

Colorado’s AI Act: the Separate Developer and Deployer Duties

The two obligation sets side by side, which role you are actually in, and the substantial-modification rule that turns a deployer into a developer.

10 min read

California’s AI Transparency Act (SB 942): the Provenance Requirements

Who counts as a covered provider under SB 942, the three duties it imposes — a detection tool, latent disclosure, optional manifest disclosure — the licensee revocation rule, and the operative date after AB 853.

9 min read

California’s AB 2013: the Training Data Disclosure Law

The twelve-ish items AB 2013 requires a generative AI developer to publish about its training datasets, who counts as a developer, the January 2026 posting date, and the enforcement gap in the statute.

10 min read

California’s AB 1008: Applying the CCPA to AI-Generated Output

What AB 1008 changed in the CCPA's definition of personal information, why the change is about format rather than about new rights, and which consumer rights become hard to answer once a model is inside scope.

9 min read

Other topics