Prefer to listen? Click play for AI narration

Every AI tool your company uses or builds has two sides. One is the model. The other is the data behind it: customer emails, CRM records, support tickets, photos, and posts scraped from the public web. When any of that data relates to an identifiable person, the General Data Protection Regulation (GDPR) applies.

That is not new. What is new is how much regulators, courts and lawmakers have now said about it. With guidance from the European Data Protection Board (EDPB), rulings from the EU Court of Justice and the EU AI Act being phased in, “we’ll deal with privacy later” is no longer an option in 2026.

Why the GDPR applies to AI at every stage

The GDPR (Regulation (EU) 2016/679) covers any “processing” of personal data, and AI systems process it at three points:

The model itself can be in scope too. In Opinion 28/2024, adopted on 17 December 2024, the EDPB said that AI models trained on personal data cannot automatically be treated as anonymous. A model counts as anonymous only if the likelihood of extracting personal data from it, or getting that data out through queries, is “insignificant”. This is assessed case by case, and the burden of documenting it falls on you.

Under Article 6 GDPR, every processing operation needs a legal basis. For AI training, the realistic options are usually consent (Art. 6(1)(a)) and legitimate interest (Art. 6(1)(f)).

Consent has to be freely given, specific, informed and easy to withdraw, which rarely works at scale or for scraped data. That is why most large developers rely on legitimate interest. The EDPB has confirmed that this can be a valid basis, but only after a documented three-step test:

  1. Legitimate interest. Lawful, clearly articulated, and real and present (the EDPB’s examples include building a conversational agent or detecting fraud).
  2. Necessity. The processing must actually serve that interest, and there must be no less intrusive way to achieve it, which makes data minimisation central.
  3. Balancing. People’s rights and reasonable expectations must not override that interest. Safeguards such as filtering and easy opt-outs can tip the balance.

Meta is a useful example. In June 2024 it paused plans to train its models on EU users’ public posts after the Irish Data Protection Commission (DPC) raised concerns. After the EDPB opinion, Meta added safeguards such as de-identification and objection forms and set 27 May 2025 as its start date, relying on legitimate interest. The DPC did not prohibit the processing, and on 23 May 2025 the Higher Regional Court of Cologne rejected a consumer group’s request for an urgent injunction.

Special categories of data, such as health or biometric data, are stricter still: Article 9 requires a specific exception, and legitimate interest alone is not enough.

The core principles, applied to AI

Article 5 GDPR sets out the principles that regulators return to again and again:

Automated decisions and Article 22

Article 22 gives people the right not to be subject to a decision based solely on automated processing, including profiling, when it produces legal effects or similarly significant effects. Think loan approvals or CV screening. Such decisions are allowed only under specific exceptions (contract, law or explicit consent), and people must still be able to get human intervention and contest the outcome.

The Court of Justice of the EU has read this provision broadly:

For product teams, that means real human review of high-impact decisions and explanations people can actually understand. Regulators now enforce this with large fines: in August 2026 the Dutch authority fined Uber about €825 million over driver deactivations (our article on the Uber case).

Data subject rights in AI systems

The GDPR gives people the right to access their data (Art. 15), to rectify it (Art. 16), to have it erased (Art. 17) and to object to processing (Art. 21). These rights are easy to honour in a database and much harder in a trained model.

Once data has shaped a model’s parameters, removing one person’s information may require output filters, retraining or “machine unlearning” techniques that are still maturing. Technical difficulty does not remove the obligation. Regulators expect safeguards from the start: clean training data, output filters, clear request channels and documentation of what is feasible. The EDPB has also warned that a model developed with unlawfully processed data can affect the lawfulness of how it is later used, unless the model has been effectively anonymised.

DPIAs: required, not optional

Article 35 requires a Data Protection Impact Assessment (DPIA) when processing is likely to result in a high risk to individuals, particularly with new technologies, systematic evaluation of people or large-scale sensitive data. Most significant AI projects qualify.

A good DPIA describes the processing, tests necessity and proportionality, and records risks and mitigations. It is usually the first document a regulator asks to see. See our guide to running a DPIA before launching AI features.

💬
GDPRGard Product
Running AI on customer data? Start with the DPIA

GDPRChat is an AI customer chat widget built with Article 7 consent gates and automatic data deletion — compliance built into the architecture, not bolted on after a regulator starts asking questions.

See GDPRChat →

How the GDPR and the AI Act fit together

The AI Act (Regulation (EU) 2024/1689) adds to the GDPR rather than replacing it, and it states explicitly that it does not affect EU data protection law. The GDPR protects personal data. The AI Act regulates the risks of AI systems themselves.

The AI Act’s timeline matters:

In 2026 the EU adjusted this schedule. The Digital Omnibus on AI, Regulation (EU) 2026/1744, was published on 24 July and entered into force on 27 July 2026. It postponed high-risk obligations to 2 December 2027 for stand-alone systems (for example in recruitment, credit scoring or education) and to 2 August 2028 for AI embedded in regulated products. It also added a ban on AI that generates non-consensual intimate content or child sexual abuse material, applying from 2 December 2026, and softened AI literacy: companies must take measures to support their staff’s AI literacy, but no longer guarantee a specific level. See our 2026 to 2028 compliance calendar.

A separate part of the Digital Omnibus package, published by the Commission in November 2025, proposes amendments to the GDPR itself, including clarifying when legitimate interest can be used for AI development. As of early October 2026, that proposal is not law. The Council and the European Parliament are still negotiating it. For now, the GDPR applies in full.

Enforcement: what the cases teach us

The takeaway: the substantive risks are real, but procedure, including which authority leads a case, can be just as decisive.

Practical checklist for companies using or building AI

A note for Brazilian readers

The GDPR has extraterritorial reach. Under Article 3(2), it applies to companies outside the EU that offer goods or services to people in the EU or monitor their behaviour. Brazil’s LGPD (Law 13.709/2018) follows a similar logic. Its Article 20 also gives people the right to request a review of decisions made solely on the basis of automated processing. In July 2024, the ANPD ordered Meta to suspend the use of personal data to train generative AI in Brazil, under threat of a daily fine of R$50,000.

Conclusion

The GDPR does not prohibit AI. It requires AI to be built with care. The companies that do well will treat data protection as part of product design rather than a last-minute legal check: a clear legal basis, clean data, transparency, human oversight and good documentation. The AI Act will add requirements, and some rules may yet be simplified, but the GDPR’s core principles are here to stay. Getting them right is the surest way to build AI that customers trust.

Book a free consultation with GDPRGard → and we will help you map your AI data flows.

Sources

Share this article

Also read:

⚠️ This article is for informational purposes only and does not constitute legal advice. For complex compliance situations, consult a qualified data protection professional. GDPR and EU AI Act requirements are subject to ongoing regulatory guidance — verify current obligations with your legal adviser.