Hael
Book a meeting
GDPR for AI · Introduction

GDPR for AI Explained

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 8 min read
Key takeaways
  • The GDPR applies to AI in full. There is no AI exemption and no separate AI chapter.
  • Six areas do the work: lawful basis, transparency, purpose limitation, data minimisation, automated decision rules, and the DPIA.
  • A data protection impact assessment is mandatory for most AI that affects people, and it is the single most examined document.
  • The Digital Omnibus would add an explicit legitimate interest basis for AI training. It is a proposal, not law.
  • The EDPB and EDPS objected formally to several of those proposals in February 2026, so the final text may look different.

The six areas that do the work

The GDPR applies to artificial intelligence exactly as it applies to anything else that processes personal data. There is no AI exemption, no separate chapter, and no threshold below which it stops mattering.

What makes AI harder is not that different rules apply, but that the same rules become difficult to satisfy. Training data is collected at scale, often from sources the people concerned never anticipated. Purposes shift as models get repurposed. Explaining a decision is harder when the system is statistical. And the people affected are frequently not your customers at all.

AreaWhat it requires for AI
Lawful basisA valid basis for each processing purpose: collecting training data, training the model, and running it in production are separate purposes needing separate analysis
TransparencyTelling people their data is used, which is difficult where data was scraped or obtained indirectly
Purpose limitationData collected for one purpose cannot be freely reused to train a model for another
Data minimisation and accuracyOnly what is necessary, and kept accurate, which sits awkwardly with "more data is better"
Automated decisionsArticle 22 restricts solely automated decisions with legal or similarly significant effects
AccountabilityRecords of processing, a DPIA where risk is high, and evidence that the analysis was actually done

Lawful basis is the hardest part

Most disputes about AI and the GDPR come down to this.

For training a model on personal data, the realistic options are consent or legitimate interests. Consent is difficult at scale, has to be specific and freely given, and can be withdrawn. Legitimate interests requires a three-part assessment: a legitimate purpose, necessity, and a balancing test against the rights and expectations of the people concerned.

European regulators have accepted that legitimate interests can support training on publicly available data, but only with substantial safeguards. The pattern that has emerged from regulator decisions on large platforms includes a clear and workable route to object, de-identification measures, filtering of training data, output filtering, and documented risk assessment. Those are not optional extras; they are what made the balancing test survive scrutiny.

For running a model in production, the basis is usually easier because it attaches to a defined service relationship. It still has to be identified and recorded separately from the training basis.

The DPIA

A data protection impact assessment is required where processing is likely to result in high risk to people. Most AI that makes or supports decisions about individuals falls into that category, particularly where it involves profiling, systematic evaluation, large-scale processing, or vulnerable groups.

The DPIA is the document regulators ask for first, and the one most often found thin. It is covered in GDPR for AI - DPIA Consultants.

Automated decisions under Article 22

Article 22 gives people a right not to be subject to a decision based solely on automated processing which produces legal effects or similarly significantly affects them, subject to exceptions where the decision is necessary for a contract, authorised by law, or based on explicit consent. Where an exception applies, safeguards are still required, including human intervention, the ability to express a view, and the right to contest.

Two practical points. "Solely" is narrower than it sounds: a human who rubber-stamps an output does not make the decision non-automated. And "similarly significantly affects" has been read broadly by European courts, reaching beyond obvious cases like credit refusal.

Note that the UK position now differs. The Data (Use and Access) Act 2025 replaced Article 22 in UK GDPR with new Articles 22A to 22D, in force from 5 February 2026, permitting solely automated decisions in more circumstances where documented safeguards are in place. This is covered in UK GDPR for AI consultants.

What the Digital Omnibus would change

The European Commission published the Digital Omnibus on 19 November 2025. It is two separate regulations, and the distinction matters.

The AI one, amending the EU AI Act, was adopted by the Council on 29 June 2026 and is in force.

The data one, which would amend the GDPR, is still a proposal under negotiation. Its main AI-relevant provisions would create an explicit legitimate interest basis for processing personal data to develop and operate AI models, with enhanced safeguards and an unconditional right to object; create an exemption allowing special-category data to be processed for detecting and correcting bias, subject to safeguards; narrow the definition of personal data in some pseudonymisation scenarios; raise the records-of-processing exemption threshold; and change breach notification.

On 11 February 2026 the EDPB and the EDPS issued a joint opinion supporting some simplification but objecting strongly to others, particularly the narrowing of the personal data definition. Member states have also pushed back.

The practical instruction is straightforward. Build against the rules as they are today. Track the proposal. Do not restructure your lawful basis analysis around a provision that has not been adopted and may not survive in its current form.

How this sits with the EU AI Act

They are separate regimes that overlap heavily and neither satisfies the other.

The AI Act is product safety law: it asks whether the system is safe and properly governed. The GDPR is data protection law: it asks whether the personal data was handled lawfully and fairly.

Where an AI system is high risk under the Act and processes personal data, you will need both a DPIA and, in certain deployer situations, a fundamental rights impact assessment. They share much of their content and should be done together rather than twice. See our EU AI Act service page.

What to do next

Identify every AI system that touches personal data, and for each one record the purposes and the lawful basis for each purpose. That single exercise resolves most of the uncertainty.

Our free AI impact assessment gives a first view, and the GDPR for AI service page sets out how we run the work.

References

FAQ

Does the GDPR apply to AI?

Yes, in full. There is no AI exemption. The same rules apply and are simply harder to satisfy.

Can we train a model on personal data using legitimate interests?

Potentially, with substantial safeguards including a workable objection route, de-identification, training data filtering and documented assessment. It is a balancing test, not a default.

Has the GDPR changed for AI?

No. The Digital Omnibus provision creating an explicit legitimate interest basis for AI training is a proposal that has not been adopted. The AI Act portion of the Omnibus was adopted; the GDPR portion was not.

Do we need a DPIA for AI?

Almost always, where the system makes or supports decisions about people, involves profiling, or processes at scale.

Does the GDPR cover the same ground as the EU AI Act?

No. They overlap on documentation and risk assessment but ask different questions, and neither discharges the other.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. We take companies through data protection for AI, the EU AI Act, ISO/IEC 42001, SOC 2 and ISO 27001, and maintain the position afterwards. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.

This guide is general information and is not legal advice on your particular circumstances.

Free check

See where you stand on GDPR for AI, free.

Answer a short set of questions and see what GDPR for AI expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether GDPR for AI applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to GDPR for AI.

Or speak to us about your deadline. Book a meeting.