When does the GDPR apply to AI?
The General Data Protection Regulation (opens in a new tab) applies to any processing of data about an identifiable person. Pasting a customer email into a chat assistant, summarising a CV or analysing named reviews all count as processing.
The AI Act adds to the GDPR rather than replacing it. Data protection authorities such as the ICO publish guidance on AI (opens in a new tab) that explains these duties.
Five questions to ask
- What is the legal basis: contract, legitimate interest, consent?
- Have the people concerned been informed?
- Is the AI provider a processor with an Article 28 compliant contract?
- Does the data leave the European Union, and with what safeguards?
- Is the data used to train the provider’s model?
Reduce risk at the source
The best personal data is the data you never send. Pseudonymisation replaces names, addresses and numbers before sending: that is what our LexPrivacy software does, as shown in our work.
For sensitive data, self-hosted AI avoids sending anything to a third party. The European Data Protection Board (opens in a new tab) stresses that a model’s anonymity cannot be assumed; it must be demonstrated.
Train your teams
Most leaks come from improvised use. Hands-on training teaches people what they can share with AI and what they must keep. It is also an Article 4 AI Act requirement, explained in our article on AI literacy.

