Modulos Named in the Inaugural Gartner® Magic Quadrant™ for AI Governance PlatformsRead the

Press Release

EU regulations · GDPR

The Procedural Regulation applies from 2 April 2027

GDPR Compliance
for AI Systems

Operationalize GDPR for AI systems: obligations mapped to controls, linked evidence, and accountable review history across the AI lifecycle. Eight years of enforcement and billions in fines, and AI is the new front line.

The EU tech law stack:EU AI ActGDPRNIS2DORACyber Resilience Act

What you need to know

  1. Territorial scope is broad: GDPR reaches organisations established in the EU and non-EU organisations offering goods or services to, or monitoring the behaviour of, people in the EU.
  2. For AI systems the load concentrates in three places: Article 22 where a solely automated decision has legal or similarly significant effects, Article 35 DPIAs where processing is likely high-risk, and an Article 6 lawful basis for every purpose, with Article 9 adding conditions for special-category data.
  3. Enforcement is mature: over €7 billion in cumulative reported fines since 2018, and fines reach €20M or 4% of total worldwide annual turnover, whichever is higher.
Owners: privacy, legal, AI product teamsRead the framework docs →
01

What the GDPR is

The General Data Protection Regulation (Regulation (EU) 2016/679) is the EU's comprehensive data-protection law governing how organisations collect, process, store, and share personal data. Applicable since 25 May 2018 (in force since 2016), it applies under Article 3 to organisations established in the Union (Article 3(1)), to non-EU organisations offering goods or services to data subjects in the Union (Article 3(2)(a)), and to non-EU organisations monitoring data-subject behaviour in the Union (Article 3(2)(b)).

For AI systems, GDPR is particularly critical because personal data appears throughout the AI lifecycle: in training datasets, user inputs, operational logs, model outputs, and vendor relationships. Non-compliance under Article 83 carries fines of up to €20 million or 4% of total worldwide annual turnover, whichever is higher.

02

Where things stand

GDPR is mature law with an active enforcement machine behind it. What changes from here is how it is enforced, and how it bends around AI.

Today

  1. 25 May 2018

    now in effect

    GDPR applies; over €7 billion in cumulative fines since

  2. 2 Apr 2027

    in 6 months

    Procedural Regulation (EU) 2025/2518 streamlines cross-border enforcement

  3. 27 Dec 2031

    in 5 years

    UK adequacy sunset; renewed December 2025 with a four-year joint review

Ahead but undated: the Digital Omnibus proposals (a legitimate-interest basis for AI training, Article 22 changes, 96-hour breach notification) remain in negotiation. Recent landmarks: €530 million against TikTok in 2025, and the EU-US Data Privacy Framework upheld in court September 2025, though an appeal is pending.

03

Does GDPR apply to you?

GDPR has broad extraterritorial reach. Article 3 defines three scenarios that bring an organisation in scope. There is no general applicability threshold based on size, though specific duties scale with role, risk, and processing type. Pick the scenario that sounds most like you.

The Article 3 territorial test

Which of these describes your organisation?

In scopeArticle 3(1)

GDPR applies to personal data processed in the context of your EU establishment’s activities, even when the processing itself runs on servers outside the EU.

  • There is no size threshold. One employee or 100,000, Article 3(1) applies the same way.

Treat this as orientation only. Territorial scope can turn on specific facts such as establishment structure and targeting intent, so confirm your position with counsel.

The Article 3 scenarios in detail

Art. 3(1)
EU Establishment

You process personal data in the context of activities of an establishment in the EU, regardless of whether the processing itself takes place in the EU.

A US company with a sales office in Berlin processes customer data on US servers. GDPR applies because the processing is in the context of the Berlin office's activities.

Art. 3(2)(a)
Offering Goods or Services

You offer goods or services to data subjects in the Union, whether paid or free. Indicators include the use of a Member State language or currency alongside other intent factors identified in EDPB Guidelines 3/2018.

A Japanese SaaS tool with an EU pricing page in euros and German-language support is offering services to EU data subjects. GDPR applies even with no EU office.

Art. 3(2)(b)
Monitoring Behaviour

You monitor the behaviour of individuals within the EU, including profiling, tracking, or analytics on EU users.

A US ad-tech company tracking browsing behaviour of EU website visitors to build advertising profiles. GDPR applies to this behavioural monitoring.

No size threshold

Unlike NIS2 or DORA, GDPR has no general applicability threshold based on size. If Article 3 applies, GDPR applies whether you have 1 employee or 100,000, but specific duties scale with role, risk, scale, and processing type. Article 30(5) provides a narrow records-of-processing derogation for organisations with fewer than 250 employees subject to conditions.

The Article 27 EU representative

Where Article 3(2) applies, non-EU controllers or processors must appoint an EU representative under Article 27 unless an Article 27(2) exception applies. The exceptions cover (a) occasional processing that is not large-scale Article 9 special-category data or Article 10 criminal-offence data and is unlikely to result in a risk to data subjects’ rights and freedoms, and (b) public authorities or bodies. The representative is a contact point for data subjects and supervisory authorities; Article 27(5) preserves direct enforcement against the controller or processor.

GDPR enforcement has global reach. EU regulators have imposed billions in fines on companies worldwide, demonstrating that GDPR's extraterritorial scope is actively enforced.
  • €1.2BMeta (Ireland): Unlawful EU-US data transfers (2023)
  • €746MAmazon (Luxembourg): Non-compliant ad targeting practices (2021)
  • €530MTikTok (Ireland): Data transfers to China, children's data (2025)
  • €310MLinkedIn (Ireland): Targeted advertising consent violations (2024)

Which of the five reach you?

Answer for your company, and see the stack you actually manage. Most teams arrive here for one regulation and leave managing three.

Likely on your desk:EU AI ActGDPRNIS2DORACyber Resilience Act

You came for the GDPR. Tick what else is true and watch the stack grow.

A one-question check gives orientation only; actual scope turns on each regime's territorial, entity-size, and product tests.

04

What do you owe?

Article 5 of GDPR establishes seven principles that form the foundation of all data protection obligations. Every AI system that touches personal data inherits all seven.

1Lawfulness, Fairness & Transparency

Data must be processed lawfully, fairly, and in a transparent manner. Individuals must be informed about how their data is used.

2Purpose Limitation

Data must be collected for specified, explicit, and legitimate purposes and not further processed in incompatible ways.

3Data Minimisation

Only data that is adequate, relevant, and limited to what is necessary for the stated purpose should be processed.

4Accuracy

Personal data must be accurate and, where necessary, kept up to date. Inaccurate data must be erased or rectified without delay.

5Storage Limitation

Data must be kept in a form that permits identification of individuals for no longer than is necessary for the processing purposes.

6Integrity & Confidentiality

Data must be processed with appropriate security, including protection against unauthorised access, loss, or destruction.

7Accountability

The data controller is responsible for demonstrating compliance with all GDPR principles and must maintain evidence of compliance.

05

What can people demand?

GDPR grants individuals comprehensive rights over their personal data. For AI systems, Article 22 on automated decision-making is particularly relevant.

Art. 15Right to Access

Individuals can request a copy of their personal data and information about how it is being processed.

Art. 16Right to Rectification

Individuals can request correction of inaccurate personal data without undue delay.

Art. 17Right to Erasure

The "right to be forgotten": individuals can request deletion of their personal data under certain conditions.

Art. 18Right to Restrict Processing

Individuals can request limitation of processing while accuracy or lawfulness is being verified.

Art. 20Right to Data Portability

Where processing is based on Article 6(1)(a) consent or 6(1)(b) contract and carried out by automated means, individuals can receive their data in a structured, machine-readable format and transmit it to another controller.

Art. 21Right to Object

Individuals can object on grounds relating to their particular situation to processing based on Article 6(1)(e) or 6(1)(f), including profiling. Article 21(2) makes objections to direct marketing absolute.

Art. 22Automated Decision-Making

Individuals have the right not to be subject to a decision based solely on automated processing (including profiling) producing legal effects or similarly significantly affecting them, but Article 22(2) to (4) set exceptions, with safeguards and Article 9 restrictions attached.

Art. 13-14Right to be Informed

Individuals must be provided with clear, transparent information about how their data is collected and used.

06

What happens if you get it wrong?

GDPR enforcement is not theoretical. Supervisory authorities have issued billions in fines, and the largest decisions name some of the world's biggest companies.

€20M / 4%

The higher of €20M or 4% of global annual turnover

Article 83(5)

€10M / 2%

The lower tier: up to €10M or 2% of total worldwide annual turnover, whichever is higher, for obligations on controllers, processors, certification bodies, and monitoring bodies

Article 83(4)

Landmark fines on one shared scale

Enforcement drawn to scale

MetaUnlawful EU-US data transfers (2023)
€1.2B
AmazonNon-compliant ad targeting practices (2021)
€746M
TikTokData transfers to China (2025)
€530M
LinkedInTargeted advertising consent violations (2024)
€310M

Your maximum exposure under Article 83(5)

The higher of €20M or 4% of global annual turnover. Pick a revenue and see the statutory ceiling on the same scale as the fines above.

Maximum exposure at €1M turnover
up to €20M

Even at €1M turnover the Article 83(5) maximum is still up to €20M, because the cap is the higher of €20M or 4% of turnover. The cap is only a ceiling: authorities calibrate fines to the case, and real fines at this size are far smaller.

These bars show the statutory ceiling only. In practice fines are discretionary and proportionate; Article 83(2) directs authorities to weigh nature, gravity, duration, intent, and cooperation when setting the amount.

72-hour breach notification: under Article 33, the controller must report a personal-data breach to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to individuals; processors notify the controller without undue delay.

07

How regimes stack on one AI system

GDPR is the regime most AI systems meet first, because personal data is everywhere in the lifecycle. Here is how one system accumulates duties across regimes.

Worked example · SYS-04 · credit-scoring model at an EU-serving bank

EU AI Acthigh-risk duties by 2 Dec 2027

Credit scoring is Annex III point 5(b): the model is a high-risk AI system.

  • Articles 9 to 17 high-risk stack
  • Conformity assessment
  • EU database registration
GDPRThis pageapplicable since 2018

Personal data runs through training, inputs, and outputs, and a solely automated credit denial is an Article 22 decision.

  • Lawful basis for each processing purpose
  • Article 35 DPIA
  • Data-subject rights incl. Article 22
DORAapplicable since Jan 2025

At a financial entity, the model is ICT supporting a critical or important function.

  • Chapter II ICT risk management
  • Major-incident reporting
  • Register of information entry
NIS2transposition passed Oct 2024

For financial entities NIS2 is largely disapplied: DORA is lex specialis under NIS2 Article 4. Run the same model at an energy or health company and the Article 21 measures attach instead.

  • Article 21 cybersecurity measures (where in scope)
  • 24h early warning, 72h notification
Cyber Resilience Actreporting from 11 Sep 2026

If the model ships to the bank as licensed software, it is a product with digital elements and the vendor carries manufacturer duties. Run purely as an internal model or hosted service, it stays outside the CRA and the entity regimes above cover it.

  • Annex I secure-by-design & vulnerability handling
  • Article 14 reporting (24h/72h)
  • Article 12 bridge to AI Act Article 15

The regimes overlap where the controls live. Map controls once, keep one evidence record, and reuse it across every regime that attaches; the Modulos platform is built on that working model.

EU AI ActCBUAE Consumer AISaudi AI Risk (SDAIA)FINMA AIMAS FEATUAE AI EthicsSingapore MGFColorado SB 26-189CCPA ADMTNYC Local Law 144ISO/IEC 42001NIST AI RMFprEN 18282EN 18286prEN 18228IEEE 7003GDPRUAE PDPLISO/IEC 27701ISO/IEC 27001NIS2DORACRAOWASP LLM Top 10OWASP Agentic Top 10Microsoft Supplier DPR

The regimes overlap where the controls live

The governance graph maps every control in the framework library to every regulation it serves. Where regimes map the same control, one implementation and one evidence record can support all of them, subject to each regime's own requirements, and most of GDPR's controls already serve at least one other framework.

39 / 66GDPR controls already serve another framework
120controls shared among the five EU regimes

Framework library v1.0.32

08

How the work gets done

Modulos gives privacy and product teams one workflow for requirements, controls, evidence, reviews, and exports. This helps you convert policy expectations into verifiable execution records.

Convert GDPR duties into assigned work

Translate GDPR obligations into structured requirements and mapped controls so teams can execute with clear ownership and status tracking.

Reuse controls across overlapping requirements

Reuse one control for multiple obligations where requirements overlap, reducing duplicated work while maintaining traceability.

Link evidence to accountability

Attach evidence directly to controls and maintain an auditable trail of updates, reviewers, and decisions tied to accountability duties.

Make reviews and approvals traceable

Use review statuses and approvals to show who validated privacy controls and when governance decisions were made.

Keep a versioned governance history

Keep policy and control documentation versioned so teams can demonstrate exactly what was approved at each point in time.

Export regulator-ready documentation

Generate project and control exports with supporting evidence files to prepare regulator-ready documentation packages.

How GDPR fits with other frameworks

GDPR rarely operates alone. AI builders and deployers run it alongside the EU AI Act and other frameworks across the same data and the same AI systems.

The EU AI Act explicitly preserves GDPR (Article 2(7) and Recital 9 of Regulation (EU) 2024/1689). The two regimes overlap on biometric processing, automated decision-making, bias detection using sensitive data, and individual rights, but compliance with one does not satisfy the other; both apply.

Where a cybersecurity incident is also a personal-data breach, NIS2 incident-reporting and Article 33 GDPR breach notification can both be triggered. For financial entities, DORA incident reporting layers on top, and from September 2026 software vendors add Cyber Resilience Act vulnerability reporting for the affected product.

Operationally, ISO/IEC 42001 provides the AI-management system inside which GDPR-AI controls run. NIST AI RMF supports the risk-analysis underpinning DPIA and Article 22 work. ISO/IEC 27002 controls support Article 32 security obligations.

For US-attestation work, SOC 2 control sets share evidence with GDPR Article 32 security and Article 28 processor obligations.

09

FAQ about GDPR for AI

The General Data Protection Regulation (GDPR), Regulation (EU) 2016/679, is the EU’s binding data-protection regulation. It governs the processing of personal data of individuals in the Union under the territorial-scope rules in Article 3: establishment in the Union under Article 3(1), offering of goods or services to data subjects in the Union under Article 3(2)(a), or monitoring of behaviour in the Union under Article 3(2)(b). GDPR has applied since 25 May 2018. Penalties under Article 83 reach the higher of €20 million or 4% of total worldwide annual turnover.

By industry

How this applies in your sector

See how this plays out in the sectors where it drives the most AI governance work:

Where the GDPR-AI work goes next

Talk to an expert

Walk through your AI systems with someone who has run DPIAs and Article 22 assessments on them.

Book a GDPR demo

Keep exploring on your own

The framework docs cover the GDPR-AI intersection, and the governance graph shows the shared controls with the AI Act.