GDPR and AI: how to keep your company’s AI use GDPR compliant
By the E-Solutions Web editorial team. Published , updated . How we write
The short answer
The GDPR applies to AI as soon as a prompt, a document or an answer contains personal data. The company that uses the AI tool remains the controller. It needs a legal basis, a processor contract with each AI provider, clear information for the people concerned, an impact assessment for high-risk uses, and a human who can review any decision with legal or similarly significant effects.
This guide is not legal advice. It summarizes the GDPR and the guidance of European data protection authorities as we read them on October 1, 2026, for a company that uses AI tools or has one built. Your data protection officer or a lawyer should confirm any decision. Where the rules are still moving, we say so.
GDPR and AI: when the regulation applies
The GDPR applies to an AI project whenever personal data passes through it, which is almost always. Article 4 defines personal data as “any information relating to an identified or identifiable natural person.” A name in a prompt, a customer email summarized by an assistant, a CV sorted by a model, a support ticket stored in a log: each one counts.
Four places in an AI system usually hold personal data, and a compliance review looks at each of them:
- The inputs: what users type or paste, and the documents the tool reads, such as contracts, tickets or HR files.
- The knowledge base: the documents indexed so that an assistant can answer from them.
- The outputs and logs: the answers, and the history the provider or your own system keeps.
- The model itself: in its Opinion 28/2024, adopted on December 17, 2024, the European Data Protection Board (EDPB) says that “AI models trained with personal data cannot, in all cases, be considered anonymous.” A model counts as anonymous only if extracting personal data from it, or obtaining that data through queries, is insignificant.
The simplest way to shrink all four is to choose where the processing happens. When the AI runs in Europe or on your own servers, as with a private LLM, the questions about providers, transfers and reuse get much shorter answers.
Your role: controller, processor, and the AI provider
The company that decides to use an AI tool for its own purposes is the controller, and the AI provider that processes data on its behalf is usually a processor. The controller carries the obligations: legal basis, information, rights, security. The processor acts on documented instructions.
The French data protection authority, the CNIL, is precise about two common setups in its questions and answers on generative AI, published on July 18, 2024. A company that connects a model to its own knowledge base, the technique known as RAG, is responsible for that processing when the knowledge base contains personal data. A company that fine-tunes a model with its own data becomes responsible for that fine-tuning.
| Your situation | Your GDPR role | What to have in place |
|---|---|---|
| Staff use a consumer chatbot with personal accounts | Controller, with little control over the provider | Usually forbid personal data; the CNIL warns against personal accounts |
| You subscribe to a business AI plan or call a model through an API | Controller; the provider is your processor | A processor contract (Article 28), the list of subprocessors, the training and retention settings |
| An assistant answers from your documents (RAG) | Controller of the knowledge base and the answers | A record of what is indexed, access rules per user, a retention period for logs |
| You fine-tune a model on your data | Controller of the fine-tuning | A legal basis for the training data, minimization, and an impact assessment if the data is sensitive |
| The model runs on your servers or in your own EU cloud | Controller; the hosting provider, if any, is your processor | Your usual security measures, plus the controls specific to the model |
Article 28 lists what the processor contract must contain: processing only on your documented instructions, including on transfers outside the EU; confidentiality of the staff involved; security measures; no subprocessor without your authorization; help with people’s requests and with impact assessments; and deletion or return of the data at the end. If a provider cannot sign such a contract, it should not receive personal data.
The obligations that shape an AI project
Most of the GDPR applies to AI the way it applies to any software; a handful of articles do most of the work in practice. The table maps them to what they mean for an AI tool.
| Obligation | Article | What it means for an AI tool |
|---|---|---|
| Legal basis | 6 | Pick one per purpose. For a business use, it is often the performance of a contract or a legitimate interest, which needs a documented balancing test. |
| Information | 13 and 14 | When data is collected, tell people the purposes, AI processing included, who receives the data and how long it is kept. |
| Data minimization | 5(1)(c) and 25 | The tool reads only the data its task needs. Design it that way from the start: pseudonymize, filter, restrict access. |
| Storage limitation | 5(1)(e) | Set a retention period for prompts, answers and logs, and apply it automatically. |
| Records of processing | 30 | Add each AI use to your record. The exemption for organizations under 250 people does not apply when the processing is regular, likely to create a risk, or involves sensitive or criminal-record data. |
| Security and breaches | 32 and 33 | Protect the tool like any system that holds personal data. Notify a breach to the authority within 72 hours where feasible. |
| Impact assessment (DPIA) | 35 | Required when the use is likely to result in a high risk to people. |
| Automated decisions | 22 | No decision with legal or similarly significant effects based solely on automated processing, outside the listed exceptions. |
| Transfers outside the EU | 44 to 49 | A transfer needs an adequacy decision or appropriate safeguards, such as standard contractual clauses. |
On legitimate interest, the EDPB recalls a three-step test: identify a lawful, precise and present interest; check that the processing is necessary and that no less intrusive way exists; and check that people’s rights do not override it. It gives an example of a legitimate interest in deployment: “improving threat detection in an information system.”
ChatGPT and other public chatbots at work
Using ChatGPT at work can fit the GDPR, but the consumer version and the business plans do not offer the same guarantees. On its enterprise privacy page, read on October 1, 2026, OpenAI says it can sign a data processing addendum for ChatGPT Business, ChatGPT Enterprise and the API, and that by default it does not use business data to train its models. The same page says OpenAI uses “data from versions of ChatGPT and other services for individuals” for training. Other major providers make similar distinctions; our security page links to the terms of OpenAI, Anthropic and Mistral.
The CNIL’s guidance draws the practical line. For non-confidential uses, a consumer service can be considered if employees use dedicated work accounts and, where possible, switch off the provider’s reuse of their data. When the use involves personal data of customers or staff, or sensitive documents, the CNIL says an on-premises deployment generally seems more appropriate and more secure; a remote deployment then requires a processor contract with the host and the provider. It also recommends an internal policy that lists allowed and forbidden uses, and training for users, because the company is usually liable for its staff’s misuse.
Enforcement is still being tested in court. On December 20, 2024, the Italian data protection authority announced a 15 million euro fine against OpenAI over ChatGPT, citing among other things the lack of an adequate legal basis for training on users’ data. A notice on the authority’s site now states that the Court of Rome upheld the appeal against that decision in judgment No. 4153/2026, published on March 18, 2026, and that the decision has been temporarily removed from the site.
Where the data goes: hosting and transfers
A transfer of personal data outside the European Economic Area is allowed only under the conditions of Chapter V of the GDPR, so the location of your AI provider and of its subprocessors matters. Article 44 sets the principle. In practice, a transfer relies on an adequacy decision or on safeguards such as standard contractual clauses (Article 46).
For the United States, the current adequacy decision is the EU-US Data Privacy Framework, whose legal history is still open. Our guide to sovereign AI covers it in detail, together with the US CLOUD Act and the difference between where servers sit and which law reaches the provider.
The CNIL adds a point specific to APIs: with a model consumed through an API, control of the system lies almost entirely with the provider, so the company should avoid entering personal data where it can and read the contractual terms closely, transfers included. This is one reason we often recommend hosting in an EU cloud or on the client’s servers for sensitive data. Your data can stay in Europe.
Automated decisions and the impact assessment
An AI that scores, ranks or filters people needs two safeguards above all: a person who can review the decision, and an impact assessment done before go-live. Article 22 gives people “the right not to be subject to a decision based solely on automated processing” that produces legal effects or similarly significant effects. Where an exception applies, such as a contract or explicit consent, Article 22(3) still requires at least the right to human intervention, to express one’s point of view and to contest the decision.
The impact assessment, often called a DPIA, is required by Article 35 when a processing “in particular using new technologies” is likely to result in a high risk. It is explicitly required for a systematic and extensive evaluation of people, based on automated processing, on which decisions with legal or similar effects are based. The controller must seek the advice of its data protection officer.
In design terms, this means the human review step is part of the workflow, with the reasons the tool gives and the data it used, and the person has the authority to overrule it. That is how we build AI agents that act in business processes. If the use also falls into a high-risk category of the EU AI Act, such as recruitment or credit scoring, our EU AI Act compliance guide explains the deployer duties that come on top, and how a GDPR impact assessment can be reused.
What is still moving, and what the penalties are
The reading of the GDPR for AI is being written now, so a compliance file made today needs a review date. On October 1, 2026, we read the following on official sources:
- European guidance: the EDPB’s Opinion 28/2024 on AI models, and the CNIL’s recommendations on applying the GDPR to the development of AI systems, including the set it announced on February 7, 2025.
- A proposed amendment: the digital omnibus covering the GDPR and other data rules, procedure 2025/0360(COD), proposed on November 19, 2025, was still “awaiting committee decision” in the European Parliament, with a committee draft report dated June 22, 2026. It is a proposal and changes nothing yet.
- The United Kingdom: the UK GDPR applies there. The ICO’s guidance on AI and data protection, last updated on March 15, 2023, states that it is under review following changes made by the Data (Use and Access) Act.
Penalties are set in Article 83. Breaches of the basic principles, the legal bases, people’s rights or the transfer rules can cost up to 20 million euros or 4% of total worldwide annual turnover, whichever is higher. Breaches of the controller’s and processor’s obligations, including the impact assessment and the processor contract, can cost up to 10 million euros or 2%.
A GDPR checklist before your first AI project
Before an AI tool touches personal data, five answers should be written down: what data it reads, on which legal basis, who processes it and where, how long it is kept, and who reviews its decisions. In order:
- List the data the tool will read and produce, and remove what the task does not need.
- Choose the legal basis for each purpose, and document the balancing test if it is a legitimate interest.
- Sign the processor contract with each provider, check the subprocessors and their locations, and switch off training on your data.
- Update the record and the privacy notice, with a retention period for prompts, answers and logs.
- Run an impact assessment if the tool evaluates people or touches sensitive data, and design the human review into the workflow.
To see what a well-behaved assistant looks like, try our knowledge assistant demo: it answers from fictional documents and cites the passage behind each answer, and nothing you type in it is stored. An AI knowledge assistant built for you follows the same rules on your documents, with access per user and logs kept for the period you set.
You do not have to sort this out alone. In a free 30-minute assessment, we go through the AI uses you have in mind, point out the personal data involved and the first safeguard to put in place. An AI readiness assessment can then map every use, usually in two to three weeks, with the scope and price fixed in writing before we start. Book your free 30-minute assessment: we reply within one business day.
Frequently asked questions
Is ChatGPT GDPR compliant?
The question is whether your use of it is. OpenAI offers a data processing addendum for ChatGPT Business, ChatGPT Enterprise and the API, and says it does not train on business data by default. Its consumer versions are different: OpenAI says it uses data from services for individuals to train its models. For personal data, use a business plan under a signed contract.
Can employees paste customer data into an AI tool?
Only into a tool your company has approved for that data, under a processor contract that sets what the provider may do with it. The CNIL recommends an internal policy that lists allowed and forbidden uses, and advises never sharing personal or confidential data with a consumer service. A model hosted in Europe or on your servers removes most of the question.
Do I need a DPIA for an AI project?
You need one when the processing is likely to result in a high risk to people’s rights, and Article 35 names new technologies as a factor. It is required in particular for systematic, automated evaluation of people that leads to decisions with legal or similar effects. Pending its further recommendations on AI, the CNIL advises involving your data protection officer and, where appropriate, carrying one out.
Does the GDPR ban decisions made by AI?
Article 22 gives people the right not to be subject to a decision based solely on automated processing that has legal or similarly significant effects. Exceptions exist for contracts, laws and explicit consent, and even then the person keeps the right to human intervention, to give their view and to contest. Keeping a person in the loop for those decisions is the simplest design.
Is an AI model trained on personal data itself personal data?
It can be. In its Opinion 28/2024, the European Data Protection Board says that models trained with personal data cannot, in all cases, be considered anonymous. Anonymity is assessed case by case: the chance of extracting personal data from the model, or obtaining it through queries, must be insignificant. Ask your provider how it demonstrates this.
What makes a chatbot GDPR compliant?
A clear notice before the first message, saying who processes the data and why; a retention period for conversations, applied automatically; a processor contract with the model provider; no training on conversations without a legal basis; and a way for users to exercise their rights. Since August 2, 2026, the EU AI Act also requires telling users they are talking to an AI, unless it is obvious.
Sources
- Regulation (EU) 2016/679, General Data Protection Regulation, EUR-Lex, Official Journal of the European Union, published 2016-05-04, accessed 2026-10-01.
- Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models, European Data Protection Board, adopted 2024-12-17, accessed 2026-10-01.
- Les questions-réponses de la CNIL sur l’utilisation d’un système d’IA générative, CNIL (French data protection authority), published 2024-07-18, accessed 2026-10-01.
- IA et RGPD : la CNIL publie ses nouvelles recommandations pour accompagner une innovation responsable, CNIL (French data protection authority), published 2025-02-07, accessed 2026-10-01.
- Enterprise privacy at OpenAI, OpenAI, accessed 2026-10-01.
- ChatGPT: the Italian DPA concludes its investigation (press release, with notice of the Court of Rome judgment No. 4153/2026), Garante per la protezione dei dati personali, published 2024-12-20, notice added after 2026-03-18, accessed 2026-10-01.
- Simplification of the digital legislative framework, Digital Omnibus, procedure 2025/0360(COD), European Parliament, Legislative Observatory, accessed 2026-10-01.
- Guidance on AI and data protection, Information Commissioner’s Office (UK), updated 2023-03-15, under review, accessed 2026-10-01.