EUEuropean UnionIn forceRGPD

How to make AI compliant with the GDPR

General Data Protection Regulation (EU) 2016/679

Status
In force
Binding
Yes
Object analysed
Data processing
Requirements
10
Next milestone
Jan 2027

In short

Applies to any AI system processing personal data, in training and inference. Governs solely automated decisions (Art. 22) and requires a DPIA for high-risk processing.

Steps to compliance

  1. Qualify each AI systemAxes to decide: Automated decision (Art. 22) and DPIA required (Art. 35).
  2. Determine your roleDuties vary by role: Controller and Processor.
  3. Apply the 10 requirementsThey focus on: Personal data, Explanation & redress, Transparency & notice and Human oversight.
  4. Prove it with checks17 checks to document, 14 of which also serve PL 2338, AI Act and NIST AI RMF.
  5. Track the deadlinesNext milestone: Jan 2027, Possible adoption of the Omnibus amendments (potential).

Scope and penalties

Kind
Regulation
Scope
Controllers and processors.
Territorial reach
EU establishment, or targeting / monitoring people in the EU.
Penalties
Up to €20M or 4% of worldwide turnover.
Jurisdiction
European Union

Timeline

Apr 27, 2016Adoption
May 25, 2018Application date
Dec 17, 2024EDPB Opinion 28/2024 on AI models
Nov 19, 2025Digital Omnibus: legitimate interest for AI training, personal data definition
Release
Jan 2027Possible adoption of the Omnibus amendmentsPotential
PastSet in the textPotentialTo verify

Qualifying a system

Classification axes and possible verdicts

Automated decision (Art. 22)

Solely automated decision with legal effectNo Art. 22 decision

DPIA required (Art. 35)

DPIA mandatoryDPIA not required

Requirements

10 requirements

CodeArticleRequirementApplies toChecks
GDPR-01Art. 5, 6Lawful basis and purpose limitation for training and inference
Controller
GDPR-02Art. 13, 14Information to data subjects, including the logic involved
Controller
GDPR-03Art. 22Safeguards on solely automated decisions
ControllerAutomated decision (Art. 22)
GDPR-04Art. 25Data protection by design and by default
Controller
GDPR-05Art. 30Record of processing activities
ControllerProcessor
GDPR-06Art. 35, 36Impact assessment (DPIA) and prior consultation
ControllerDPIA required (Art. 35)
GDPR-07Art. 32Security of processing
ControllerProcessor
GDPR-08Art. 33, 34Breach notification within 72 hours
ControllerProcessor
GDPR-09Art. 28Contracts with AI vendors acting as processors
Controller
GDPR-10Art. 15Right of access, including information on automated decisions
ControllerAutomated decision (Art. 22)

Checks to document

Evidence collected for a check counts for every regulation that uses it.

CodeCheckScopeThemesAlso used by
NEW-GDPR-01Lawful basis documented per purpose (training, inference) proposedSystem
—
VER-029-D-01Affected persons informed of the use of the AI systemSystem
VER-008-02System designed to allow human oversight (stop button, override)System
VER-033-D-01Decision explanation procedure documentedOrganisation
CHK-BR-CONTESTProcedure to contest a decision and obtain human review publishedOrganisation
VER-004-01Documented data governance (collection process, bias, quality)System
CHK-INVENTORYA mechanism to inventory AI systems is in place and resourcedOrganisation
NEW-GDPR-02AI processing listed in the Art. 30 record proposedSystem
—
VER-019-D-01Need for a DPIA assessedSystem
VER-019-D-02DPIA carried out in accordance with GDPR Art. 35System
VER-009-01Cybersecurity of the hosting environmentOrganisation
VER-009-03Cybersecurity of the AI system verifiedSystem
VER-022-D-01Serious incident reporting procedureOrganisation
NEW-GDPR-0372-hour notification procedure to the DPA proposedSystem
—
VER-026-F-01Contractual responsibilities documented between provider and third partiesProvider
CHK-THIRDPARTY-POLPolicies address third-party AI/data risks, incl. IP, transparency and testingOrganisation
VER-033-D-03Explanations provided on request within a reasonable timeframeSystem

Themes covered

Frequently asked questions

Who is in scope of RGPD?

Controllers and processors. EU establishment, or targeting / monitoring people in the EU.

What penalties does RGPD carry?

Up to €20M or 4% of worldwide turnover.

When do the RGPD obligations apply?

Dec 17, 2024: EDPB Opinion 28/2024 on AI models; Nov 19, 2025: Digital Omnibus: legitimate interest for AI training, personal data definition; Jan 2027: Possible adoption of the Omnibus amendments.

Is RGPD binding?

Yes. Kind: regulation. Status: in force.

How does RGPD relate to other regulations?

The same checks serve several texts. Shared checks: PL 2338 (11), AI Act (9) and NIST AI RMF (5).

Related regulations

Official sources

Data checked on Sep 25, 2026. General information, not legal advice. Check the official texts and get advice for your situation.

Run these requirements across all your AI systems

TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.

Request a demo