How to make AI compliant with the GDPR
General Data Protection Regulation (EU) 2016/679
- Status
- In force
- Binding
- Yes
- Object analysed
- Data processing
- Requirements
- 10
- Next milestone
- Jan 2027
In short
Applies to any AI system processing personal data, in training and inference. Governs solely automated decisions (Art. 22) and requires a DPIA for high-risk processing.
Steps to compliance
- Qualify each AI systemAxes to decide: Automated decision (Art. 22) and DPIA required (Art. 35).
- Determine your roleDuties vary by role: Controller and Processor.
- Apply the 10 requirementsThey focus on: Personal data, Explanation & redress, Transparency & notice and Human oversight.
- Prove it with checks17 checks to document, 14 of which also serve PL 2338, AI Act and NIST AI RMF.
- Track the deadlinesNext milestone: Jan 2027, Possible adoption of the Omnibus amendments (potential).
Scope and penalties
- Kind
- Regulation
- Scope
- Controllers and processors.
- Territorial reach
- EU establishment, or targeting / monitoring people in the EU.
- Penalties
- Up to €20M or 4% of worldwide turnover.
- Jurisdiction
- European Union
Timeline
Qualifying a system
Classification axes and possible verdicts
Automated decision (Art. 22)
DPIA required (Art. 35)
Requirements
10 requirements
| Code | Article | Requirement | Applies to | Checks |
|---|---|---|---|---|
| GDPR-01 | Art. 5, 6 | Lawful basis and purpose limitation for training and inference | ||
| GDPR-02 | Art. 13, 14 | Information to data subjects, including the logic involved | ||
| GDPR-03 | Art. 22 | Safeguards on solely automated decisions | ||
| GDPR-04 | Art. 25 | Data protection by design and by default | ||
| GDPR-05 | Art. 30 | Record of processing activities | ||
| GDPR-06 | Art. 35, 36 | Impact assessment (DPIA) and prior consultation | ||
| GDPR-07 | Art. 32 | Security of processing | ||
| GDPR-08 | Art. 33, 34 | Breach notification within 72 hours | ||
| GDPR-09 | Art. 28 | Contracts with AI vendors acting as processors | ||
| GDPR-10 | Art. 15 | Right of access, including information on automated decisions |
Checks to document
Evidence collected for a check counts for every regulation that uses it.
| Code | Check | Scope | Themes | Also used by |
|---|---|---|---|---|
| NEW-GDPR-01 | Lawful basis documented per purpose (training, inference) proposed | System | ||
| VER-029-D-01 | Affected persons informed of the use of the AI system | System | ||
| VER-008-02 | System designed to allow human oversight (stop button, override) | System | ||
| VER-033-D-01 | Decision explanation procedure documented | Organisation | ||
| CHK-BR-CONTEST | Procedure to contest a decision and obtain human review published | Organisation | ||
| VER-004-01 | Documented data governance (collection process, bias, quality) | System | ||
| CHK-INVENTORY | A mechanism to inventory AI systems is in place and resourced | Organisation | ||
| NEW-GDPR-02 | AI processing listed in the Art. 30 record proposed | System | ||
| VER-019-D-01 | Need for a DPIA assessed | System | ||
| VER-019-D-02 | DPIA carried out in accordance with GDPR Art. 35 | System | ||
| VER-009-01 | Cybersecurity of the hosting environment | Organisation | ||
| VER-009-03 | Cybersecurity of the AI system verified | System | ||
| VER-022-D-01 | Serious incident reporting procedure | Organisation | ||
| NEW-GDPR-03 | 72-hour notification procedure to the DPA proposed | System | ||
| VER-026-F-01 | Contractual responsibilities documented between provider and third parties | Provider | ||
| CHK-THIRDPARTY-POL | Policies address third-party AI/data risks, incl. IP, transparency and testing | Organisation | ||
| VER-033-D-03 | Explanations provided on request within a reasonable timeframe | System |
Themes covered
Frequently asked questions
Who is in scope of RGPD?
Controllers and processors. EU establishment, or targeting / monitoring people in the EU.
What penalties does RGPD carry?
Up to €20M or 4% of worldwide turnover.
When do the RGPD obligations apply?
Dec 17, 2024: EDPB Opinion 28/2024 on AI models; Nov 19, 2025: Digital Omnibus: legitimate interest for AI training, personal data definition; Jan 2027: Possible adoption of the Omnibus amendments.
Is RGPD binding?
Yes. Kind: regulation. Status: in force.
How does RGPD relate to other regulations?
The same checks serve several texts. Shared checks: PL 2338 (11), AI Act (9) and NIST AI RMF (5).
Related regulations
Official sources
Data checked on Sep 25, 2026. General information, not legal advice. Check the official texts and get advice for your situation.
Run these requirements across all your AI systems
TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.