Not sure where to start? Answer 3 questions and get a tailored compliance action plan.
What applies to me? →General Data Protection Regulation (GDPR)
Issued by
European Parliament and Council of the European Union
- September 30, 2026 · Substantive update — Entry created for the GDPR as it applies to AI. Facts checked against EUR-Lex, EDPB Opinion 28/2024, and IAPP reporting on the Digital Omnibus. (Cody Maxwell)
The GDPR is the EU's data protection law. It applies whenever an AI system uses personal data about people in the EU, from training a model to making decisions about individuals. Organizations need a lawful basis for each use, must tell people how their data is used, and must respect their rights. It also limits decisions made solely by automated means that significantly affect people.
Applies To
Overview
The General Data Protection Regulation (Regulation (EU) 2016/679) has applied since 25 May 2018. It covers any organization that processes personal data of people in the EU. That includes companies based elsewhere that offer them goods or services or monitor their behavior. The GDPR is not an AI law, but most AI systems touch personal data somewhere. That makes it the rule that governs AI training data, prompts, and outputs about people. Several provisions matter most for AI. Every use of personal data needs a lawful basis under Article 6, such as consent or legitimate interests. Sensitive data, such as health or biometric data, needs an extra condition under Article 9. Article 22 gives people the right not to be subject to decisions based solely on automated processing that significantly affect them. Where such decisions are allowed, people can ask for human review and contest the result. Processing that is likely to be high risk needs a data protection impact assessment (DPIA) before it starts, and many AI uses meet that bar. Data protection by design means building privacy into systems from the start. People keep their rights to access, correct, and erase their data, which is hard to honor once data is inside a trained model. In December 2024 the European Data Protection Board (EDPB) published Opinion 28/2024 on AI models. It says legitimate interests can support training if a three-step test is met. It also says a model trained on personal data is not automatically anonymous. In November 2025 the European Commission proposed GDPR changes on AI training as part of its Digital Omnibus package. Those changes were still under negotiation in September 2026. National data protection authorities enforce the GDPR. Fines reach EUR 20 million or 4% of worldwide annual turnover, whichever is higher. Regulators have already acted on AI. Italy fined OpenAI EUR 15 million in December 2024, and several authorities fined Clearview AI for building a facial recognition database from scraped images.
Key Requirements
- •Identify a lawful basis under Article 6 for each stage of AI processing, including training, testing, and live use.
- •Meet an Article 9 condition before using sensitive data, such as health, biometric, or ethnicity data.
- •Tell people how AI uses their data, including meaningful information about the logic of automated decisions (Articles 13 to 15).
- •Avoid decisions based solely on automated processing that have legal or similarly significant effects, unless an Article 22 exception applies. Offer human review when one does.
- •Complete a data protection impact assessment before high-risk processing starts (Article 35).
- •Put data processing agreements in place with AI vendors that handle personal data for you (Article 28).
- •Follow the transfer rules when personal data leaves the EU, including when an AI vendor hosts it abroad (Chapter V).
What Your Organization Must Do
- →Map where personal data enters each AI system: training data, prompts, retrieved documents, and outputs.
- →Record the lawful basis for each use, and run a legitimate interests assessment wherever you rely on that basis.
- →Add AI systems to your DPIA screening, and complete a DPIA before launching any that meet the high-risk bar.
- →Check vendor terms to see whether the vendor trains on your data, and document processing agreements and transfer safeguards.
- →Set up a route for people to request human review of significant automated decisions and to exercise their data rights.
- →Decide how you will handle access and erasure requests for data used in model training, and document the approach.
Playbook Guidance
Step-by-step implementation guidance for compliance teams.
Governance Controls
Operational controls that implement requirements from this regulation.
Frequently Asked Questions
- Does the GDPR apply to AI systems?
- Yes, whenever an AI system processes personal data about people in the EU. That includes training data, the prompts people type, and outputs that describe individuals. The GDPR applies alongside the EU AI Act, not instead of it.
- Can we rely on legitimate interests to train AI on personal data?
- It is possible, but you must pass the three-step test the EDPB set out in Opinion 28/2024. The purpose must be legitimate, the processing must be necessary for it, and your interests must not override people's rights. Record the assessment and the safeguards you rely on.
- What does Article 22 mean for AI decisions?
- People have the right not to be subject to decisions based solely on automated processing that have legal or similarly significant effects. Rejecting a loan application or screening out a job candidate are typical examples. Such decisions are allowed only with explicit consent, when necessary for a contract, or when a law authorizes them. Even then, people can ask for a human to review the decision.
- Do we need a DPIA for an AI system?
- Often it is, because a DPIA is required when processing is likely to pose a high risk to people's rights. Regulators name new technologies, large-scale profiling, and automated decision-making as common triggers, and many AI uses meet at least one.
- How does the GDPR relate to the EU AI Act?
- The two laws apply side by side. The GDPR governs personal data, while the AI Act governs the AI system itself. A high-risk AI system that uses personal data must meet both, and the AI Act states that it does not affect the GDPR.
- What are the fines under the GDPR?
- The most serious breaches can cost up to EUR 20 million or 4% of worldwide annual turnover, whichever is higher. Other breaches carry up to EUR 10 million or 2%.
