GDPR AI compliance
- A programme runs in six stages: inventory, purpose and basis mapping, DPIA, safeguards, transparency and rights, then ongoing review.
- Purpose and basis mapping is the stage that determines everything else, and it is the stage most often skipped.
- Typical first programmes run £12,000 to £40,000, driven by system count and how much training data is personal.
- The DPIA is the artefact a supervisory authority asks for first.
- Build against current law. The proposals that would ease AI training are not adopted.
Stage 1: Inventory
GDPR compliance for AI is a programme with six stages: find the systems, map purposes and lawful bases, assess risk, put safeguards in place, handle transparency and rights, then review as things change. This overview covers each stage and the numbers attached.
For the plain explanation of how the GDPR applies to AI, see GDPR for AI Explained.
Every AI system that touches personal data, including systems you bought rather than built, and including AI features inside software you already use.
For each: what personal data it uses, where that data came from, whether any of it is special category, whose data it is, whether those people are your customers, and what the system does with it.
The two things most often missed are training data provenance for models built in house, and AI features inside purchased tools where the vendor processes personal data on your behalf.
Stage 2: Purposes and lawful basis
The stage that determines everything else, and the one most often collapsed into a single line.
Collecting training data, training the model, evaluating it, and operating it in production are separate purposes. Each needs a lawful basis and reasoning. In many organisations the production basis is clear and the training basis has never been articulated at all.
Where you rely on legitimate interests, write the three-part assessment: purpose, necessity, balancing. Record the safeguards that made the balance acceptable. Regulator decisions have consistently treated the safeguards as the reason the basis held.
Where special category data is involved, an Article 9 condition is needed on top of the Article 6 basis, and the available conditions are narrow.
Stage 3: DPIA
Required where processing is likely to result in high risk. For AI affecting individuals, assume yes and record your reasoning if you conclude otherwise.
The DPIA should describe the processing, assess necessity and proportionality, identify risks to people, and set out the measures that address them. For AI, it should reach into training data provenance, accuracy and bias, human oversight, and what happens when the system is wrong.
Covered in GDPR for AI - DPIA Consultants.
Stage 4: Safeguards
What the DPIA identified, actually implemented. Typically: de-identification or pseudonymisation where possible, filtering of training data, output filtering, retention limits, access controls, human review in the decision path, and a workable route to object.
Where Article 22 applies, the specific safeguards it requires: human intervention, ability to express a view, right to contest.
Stage 5: Transparency and rights
Privacy information that genuinely describes the AI processing, in language the reader can act on. Where data was obtained indirectly, the Article 14 obligations apply and the exemptions are narrower than people assume.
A working route for access, objection, erasure and rectification, with a documented position on what is technically possible for a trained model and what is not.
Stage 6: Ongoing review
Models get retrained. Purposes shift. New systems arrive. Suppliers change what they do with your data.
The DPIA has to be revisited when processing changes materially, and the lawful basis analysis has to be revisited when purposes do. Add a data protection gate to procurement and to your AI launch process so new systems arrive assessed. That is our continuous governance and assurance service.
What it costs
| Component | Typical range |
|---|---|
| Inventory and purpose mapping | £4,000 to £12,000 |
| Lawful basis and legitimate interests assessments | £3,000 to £10,000 |
| DPIA, per system | £4,000 to £15,000 |
| Safeguard design and implementation | £5,000 to £20,000 |
| Transparency and rights process | £3,000 to £8,000 |
| Full first programme | £12,000 to £40,000 |
| Outsourced DPO | Retainer, scope dependent |
Cost scales with the number of AI systems, how much personal data is in training sets, and whether special category data is involved.
Where programmes go wrong
One lawful basis for everything. Training and production treated as a single purpose, so the training basis has never actually been reasoned.
A DPIA written after deployment. The obligation is to assess before processing begins. A retrospective DPIA is better than none and is visibly retrospective.
No objection route for legitimate interests. The safeguard regulators have treated as central, absent.
Training data provenance unknown. Common where a model was built quickly or inherited, and unanswerable later without real effort.
Vendor AI features unassessed. Personal data processed by a supplier's model with no processor terms and no assessment.
Special category data treated as ordinary. An Article 9 condition is required and the options are narrow.
Human review that is not review. Someone approving outputs without the time, information or authority to disagree does not take the decision out of Article 22.
What is changing
Nothing yet. The Digital Omnibus data regulation, which would create an explicit legitimate interest basis for AI development and operation and a route for processing special category data to detect and correct bias, remains a proposal under negotiation. The EDPB and EDPS objected to parts of it in February 2026.
The AI Act portion of the Omnibus was adopted on 29 June 2026 and is in force. The two are frequently confused, including by advisers.
Build against current law. Track the proposal. Do not restructure around a provision that may change.
What to do next
Do the inventory and the purpose mapping. Together they resolve most of the uncertainty, and they are the input every other stage needs.
Our free AI impact assessment gives an immediate first view, and the GDPR for AI service page sets out how we run the programme.
References
FAQ
How long does a GDPR for AI programme take?
Two to four weeks for inventory and purpose mapping, six to twelve weeks for a first full programme covering a modest estate.
How much does it cost?
Commonly £12,000 to £40,000, driven by system count, how much personal data is in training sets, and whether special category data is involved.
Do training and production need separate lawful bases?
Yes. They are separate purposes and each needs its own basis and reasoning.
What if we do not know where our training data came from?
That is a finding rather than a blocker. Document what is known, assess the risk it creates, and put provenance capture in place for future training.
Has the law changed for AI training?
No. The provision that would ease it is in the Digital Omnibus data regulation, which has not been adopted.
About Hael
Hael is an advisory firm specialising in AI governance and security compliance. We do the work, hold the deadline and stand behind the evidence, across data protection for AI, the EU AI Act, ISO/IEC 42001, SOC 2 and ISO 27001. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.
This guide is general information and is not legal advice on your particular circumstances.