Practical guide

AI and GDPR in business

The objective is to assess a concrete AI data flow rather than a generic product question. The review baseline covers purpose, data class, roles, provider, region, retention and control.

WERKVERSTAND / CONNECTING INTELLIGENCE

The essential answer

For AI using personal data, assess purpose, necessary information, lawful basis and the full processing path. Include provider roles, contracts, access, retention and international transfers where applicable. The assessment depends on the specific use and its risk.

01 / FIT

A good fit when

  • A concrete assignment and an accountable domain owner are defined.
  • A documented data-flow overview identifies processing steps, parties, retention and control points. Related documentation and unresolved legal questions are traceably assigned to the responsible review.

02 / LIMITS

Not the first choice when

  • Avoid: using a website claim as final legal review. This draft does not replace final legal review; without confirmed data paths and conditions, a general website statement cannot approve a concrete use.

Determine purpose, data minimisation and lawful basis

GDPR requirements for personal-data processing include purpose limitation, data minimisation and an applicable lawful basis. The assessment is therefore broader than whether a tool offers a business contract. For a customer query, establish which details are necessary and whether special categories are involved. Internal permission to use a tool does not replace these requirements.

Record providers and transfers comprehensively

A data-flow record shows upload, model processing, connectors, storage and recipients. Where processing on behalf of a controller occurs, review the requirements for that relationship. International transfers involve additional rules. Record transparency duties, individual rights and deletion routes as well. Neither a selected server region nor a no-training commitment answers all these questions.

Assess risk and track changes

Assess the need for a data protection impact assessment where the planned processing is likely to create high risk to rights and freedoms. Not every AI use automatically meets that condition. Responsible people consider purpose, scope and circumstances and document the conclusion. New sources, different recipients or additional actions trigger reconsideration of the data path and safeguards.

Decision matrix

Decision pointProceed whenStop when
Data and accountabilityDocumented: purpose, data class, roles, provider, region, retention and control.Scope, data or accountability remains unresolved.
Control evidenceA documented data-flow overview identifies processing steps, parties, retention and control points. Related documentation and unresolved legal questions are traceably assigned to the responsible review.There is only an unevaluated demo without acceptance evidence.
Approval boundaryOwner, approval, fallback and next review date are defined.Avoid: using a website claim as final legal review. This draft does not replace final legal review; without confirmed data paths and conditions, a general website statement cannot approve a concrete use.

Keep it verifiable

Primary sources

The next sensible step

Which AI system fits your business?

Eight steps from a general interest in AI to a clearer decision for your business.

Start AI System Check
FreeProvider-neutralNo credentials