GDPR-compliant AI: what you should check

No AI tool is GDPR-compliant by itself. It depends on how you use it. These seven points settle most cases.

As of: 24 September 2026

The checkpoints

PointQuestionWhat to look for
Legal basisOn which basis under Art. 6 GDPR do you process the data?Often legitimate interest, with a documented balancing test.
Data processing agreementIs there a DPA with the AI provider?No DPA, no personal data in the tool.
Data locationWhere is the data processed and stored?EU processing, and check whether a third country has access.
TrainingDoes the provider use your data to train its models?Exclude it in the contract.
TransparencyDo data subjects know that AI processes their data?Privacy policy and a note at the point of contact.
Automated decisionsDoes the AI alone decide about people?Art. 22 GDPR: plan a human review.
Impact assessmentIs the risk to data subjects high?Then carry out a DPIA beforehand.

What the regulators say

  • EDPB Opinion 28/2024Whether an AI model is anonymous is assessed case by case. Legitimate interest can be a legal basis, after a three-step balancing test.
  • Austrian data protection authorityGDPR and AI Act apply side by side. Data subjects must be informed. AI output can be plausible and still wrong.

How we run AI

  • Data processing in the EU, no transfer to the USA unless explicitly agreed
  • Knowledge systems (RAG) self-hosted on request, with your documents on your infrastructure
  • No training of third-party models on your data
  • Human approval wherever a decision about people is made
See our services

Frequently asked questions

Is there GDPR-certified AI?

No, not as a seal for an AI tool. Whether an AI use is GDPR-compliant depends on the specific use: which data, which purpose, which legal basis, which provider.

May I use ChatGPT with customer data?

Only with a legal basis, a data processing agreement and a solution for transfers to third countries. With the consumer version and no contract, this is usually not possible.

Is it enough if the servers are in the EU?

Location is an important point, but not the only one. It also matters who has access, whether data is used for training, and whether a provider from a third country is behind it.

Does AI need a data protection impact assessment?

Not always. It is required when processing is likely to pose a high risk to data subjects, for example when people are assessed or large amounts of sensitive data are involved.

Use AI and settle data protection

We look at your use case and tell you which points are still open.

Book a call