GDPR for AI systems — where data protection law meets the AI Act
If your AI system touches personal data, the GDPR applies in full — alongside the AI Act, not instead of it. We help you work out which rules bite where, and build one set of documentation that satisfies both.
First hour’s on us. No commitment.
What you get
- A legal basis assessment for each processing activity in the model lifecycle — training, fine-tuning, evaluation, inference and logging are not the same thing and often do not share a basis
- A DPIA that covers the AI-specific risks rather than a generic template
- Clarity on automated decision-making — whether Article 22 applies to your system, and what you need if it does
- Transparency wording for privacy notices that survives contact with a regulator
- One evidence base that serves the GDPR and the AI Act together instead of two overlapping projects
How it works
- Intake, 45 minutes. What the system does and what data it touches. Free.
- Assessment, one to three weeks. Data flows, legal bases, roles, risks.
- The output. A DPIA, a legal basis memo and a prioritised list of what to change.
The questions that decide everything
What is your legal basis for the training data?
This is the question that most often has no good answer written down. Consent is rarely workable at training scale. Contract seldom fits, because training a general model is not necessary to perform a contract with the individual. That leaves legitimate interests for most commercial cases — which is available, but requires a documented balancing test that weighs your interest against the reasonable expectations of the people in the dataset.
Scraped data makes this harder, not easier. So does data acquired from a third party: you inherit the question of whether it was lawfully collected, and Article 14 information duties may still be yours.
Are you making automated decisions about people?
Article 22 restricts decisions based solely on automated processing that produce legal effects or similarly significantly affect someone. Recruitment screening, credit decisions, insurance pricing, fraud blocking and access decisions are the usual candidates.
The word doing the work is “solely”. A human who rubber-stamps the output does not take you outside Article 22 — the reviewer needs authority and competence to reach a different conclusion, and evidence that this happens in practice. This is also where the GDPR and the AI Act converge: both require meaningful human oversight, and the same design satisfies both.
Can you explain the system to the people it affects?
The GDPR requires meaningful information about the logic involved. That is not the model weights, and it is not a marketing sentence either. It is a description of what data goes in, what the system optimises for, and how the output is used — specific enough that someone could contest a decision on the basis of it.
Can you honour a deletion request?
Erasure is straightforward for the training set and hard for the model itself. Most organisations resolve this by documenting what deletion means in practice for each layer — source data, training set, model, outputs and logs — and by being precise about it in their privacy notice, rather than promising something the architecture cannot deliver.
Where the AI Act and the GDPR overlap
They are different instruments with different aims — the GDPR protects personal data, the AI Act regulates AI systems as products — but the documentation overlaps substantially.
| Requirement | GDPR | AI Act |
|---|---|---|
| Risk assessment | DPIA (Art. 35) | Risk management system, and a fundamental rights impact assessment for some deployers |
| Data quality | Accuracy principle (Art. 5) | Data governance for high-risk systems (Art. 10) |
| Human oversight | Art. 22 safeguards | Human oversight for high-risk systems (Art. 14) |
| Transparency | Art. 13–15 information duties | Transparency duties (Art. 50) and instructions for use |
| Records | Records of processing (Art. 30) | Technical documentation and logging |
Build these once, mapped to both, and the work roughly halves. Build them twice and they will disagree with each other — which is worse than either alone.
Special categories and inference
A model that was never given health, ethnicity or political opinion data can still infer it. Where inferences of that kind are a foreseeable output rather than an accident, Article 9 is in play, and the exemptions are narrow. This is worth testing early, because the answer can change the design rather than just the paperwork.
Frequently asked questions
We use a third-party model. Are we a controller or a processor?
Usually a controller for how you use it, while the provider may be a controller for its own model improvement. Check what the terms actually say about using your inputs for training — many now offer a setting, and the default is not always the one you want.
Do we need a DPIA for every AI system?
No, but the threshold is low for systems that profile people, process data at scale, or make decisions that affect them. If in doubt, do one — the reasoning is useful even where it is not required.
Does the AI Act replace GDPR obligations?
No. They apply in parallel. Meeting one does not discharge the other.
What about international transfers?
Same rules as any other processing. The complication with AI is that the data flow is often longer than expected — inference, logging, evaluation and support access can all involve different jurisdictions.
Can you review a system we have already built?
Yes, and that is the more common case. A review of a live system usually takes one to three weeks.
Where to start
Bring one system and the questions you are least sure about. That is normally enough to see what needs attention and what is already on solid ground.
Who you’ll work with
Fidan Ibrahimzada, Legal Counsel for AI and technology law, leads this work. She advises companies on AI regulation, data protection and technology contracts, and previously led the legal department of a commercial law firm. She holds an LL.M. in European Business Law from Lund University. Lawgent is Sweden’s first law firm dedicated to AI and EU regulation — meet the team.