dsgvo

GDPR & AI: What's Allowed, What's Required?

10. Juni 2026 · EN

Complete guide to GDPR-compliant AI deployment in European companies. With practical checklists.

GDPR & AI: What’s Allowed, What’s Required?

The GDPR has been in force since 2018, AI systems have grown explosively in recent years. Many European companies are uncertain: Can I use AI at all? What do I need to consider? Here are the answers.

Basic Principle: AI Is Not Forbidden

GDPR does not fundamentally prohibit AI. It requires you to meet certain prerequisites before processing personal data with AI.

The Three Prerequisites

For most B2B applications, legitimate interest (Art. 6(1)(f)) suffices:

  • You have a legitimate business interest (e.g., efficiency gains)
  • Processing is necessary to achieve this goal
  • Interests of data subjects do not override

For marketing, profiling, or automated individual decisions, you usually need explicit consent (Art. 6(1)(a)).

2. Data Protection Impact Assessment (Art. 35 GDPR)

A DPIA is mandatory when processing is likely to result in high risks to the rights and freedoms of natural persons. This is almost always the case with AI.

A DPIA includes:

  • Description of the processing
  • Assessment of the risks
  • Measures to minimize risk
  • Consultation of the data protection officer

3. Transparency (Art. 13/14 GDPR)

The data subjects must know that you use AI. In practice this means:

  • Notice in the imprint/privacy policy
  • Information at first interaction (“You are now talking to our AI assistant”)
  • Explanation of which data is processed

Special Categories: Art. 9 GDPR

Certain data enjoys special protection:

  • Health data
  • Religious beliefs
  • Political opinions
  • Sexual orientation
  • Biometric data

For this data you need explicit consent — “legitimate interest” is not enough.

Hosting and Third-Country Transfer

Since the Schrems II ruling (2020), third-country transfer to the US and other unsafe third countries is only possible under strict conditions. Practical consequence:

  • EU hosting is mandatory for GDPR-compliant AI deployment
  • Standard contractual clauses alone are not enough
  • TIA (Transfer Impact Assessment) is required

We recommend: Hosting in Frankfurt, no API calls to US providers, or at least EU region with DPA.

Draft-Only Mode as Solution for Art. 22

Art. 22 GDPR prohibits automated individual decisions with legal effect. A fully autonomous AI that rejects customers or cancels contracts is not allowed.

Draft-only mode solves this: AI suggests, human decides. No automated decisions with legal effect, full compliance.

Checklist: GDPR-Compliant AI Deployment

  • Legal basis identified and documented
  • DPIA conducted (for high risk)
  • Privacy policy updated
  • Data subjects are informed
  • Hosting in the EU
  • DPA with all processors
  • Draft-only mode for customer communication
  • Deletion concept implemented
  • Employees trained
  • Incident response plan in place

Common Mistakes

  • “We use ChatGPT, that’s EU-compliant” — No, OpenAI uses US servers without sufficient guarantees
  • “We have a privacy policy, that’s enough” — Without DPIA and technical measures, no
  • “The AI decides, the human checks randomly” — Random samples are not sufficient, draft-only is mandatory
  • “We host in Ireland, that’s EU” — Yes, but US providers can be forced by authorities to hand over data

Conclusion

GDPR-compliant AI deployment is doable, but requires care. With the right prerequisites (EU hosting, draft-only, DPIA, DPA) you are on the safe side and can fully leverage the benefits of AI.