GDPR & AI: What's Allowed, What's Required?
Complete guide to GDPR-compliant AI deployment in European companies. With practical checklists.
GDPR & AI: What’s Allowed, What’s Required?
The GDPR has been in force since 2018, AI systems have grown explosively in recent years. Many European companies are uncertain: Can I use AI at all? What do I need to consider? Here are the answers.
Basic Principle: AI Is Not Forbidden
GDPR does not fundamentally prohibit AI. It requires you to meet certain prerequisites before processing personal data with AI.
The Three Prerequisites
1. Legal Basis (Art. 6 GDPR)
For most B2B applications, legitimate interest (Art. 6(1)(f)) suffices:
- You have a legitimate business interest (e.g., efficiency gains)
- Processing is necessary to achieve this goal
- Interests of data subjects do not override
For marketing, profiling, or automated individual decisions, you usually need explicit consent (Art. 6(1)(a)).
2. Data Protection Impact Assessment (Art. 35 GDPR)
A DPIA is mandatory when processing is likely to result in high risks to the rights and freedoms of natural persons. This is almost always the case with AI.
A DPIA includes:
- Description of the processing
- Assessment of the risks
- Measures to minimize risk
- Consultation of the data protection officer
3. Transparency (Art. 13/14 GDPR)
The data subjects must know that you use AI. In practice this means:
- Notice in the imprint/privacy policy
- Information at first interaction (“You are now talking to our AI assistant”)
- Explanation of which data is processed
Special Categories: Art. 9 GDPR
Certain data enjoys special protection:
- Health data
- Religious beliefs
- Political opinions
- Sexual orientation
- Biometric data
For this data you need explicit consent — “legitimate interest” is not enough.
Hosting and Third-Country Transfer
Since the Schrems II ruling (2020), third-country transfer to the US and other unsafe third countries is only possible under strict conditions. Practical consequence:
- EU hosting is mandatory for GDPR-compliant AI deployment
- Standard contractual clauses alone are not enough
- TIA (Transfer Impact Assessment) is required
We recommend: Hosting in Frankfurt, no API calls to US providers, or at least EU region with DPA.
Draft-Only Mode as Solution for Art. 22
Art. 22 GDPR prohibits automated individual decisions with legal effect. A fully autonomous AI that rejects customers or cancels contracts is not allowed.
Draft-only mode solves this: AI suggests, human decides. No automated decisions with legal effect, full compliance.
Checklist: GDPR-Compliant AI Deployment
- Legal basis identified and documented
- DPIA conducted (for high risk)
- Privacy policy updated
- Data subjects are informed
- Hosting in the EU
- DPA with all processors
- Draft-only mode for customer communication
- Deletion concept implemented
- Employees trained
- Incident response plan in place
Common Mistakes
- “We use ChatGPT, that’s EU-compliant” — No, OpenAI uses US servers without sufficient guarantees
- “We have a privacy policy, that’s enough” — Without DPIA and technical measures, no
- “The AI decides, the human checks randomly” — Random samples are not sufficient, draft-only is mandatory
- “We host in Ireland, that’s EU” — Yes, but US providers can be forced by authorities to hand over data
Conclusion
GDPR-compliant AI deployment is doable, but requires care. With the right prerequisites (EU hosting, draft-only, DPIA, DPA) you are on the safe side and can fully leverage the benefits of AI.