For privacy, legal, and AI product teams
GDPR Compliance
for AI Systems
Operationalize GDPR for AI systems: obligations mapped to controls, linked evidence, and accountable review history across the AI lifecycle. Eight years of enforcement and billions in fines, and AI is the new front line.
What is the GDPR?
The General Data Protection Regulation (Regulation (EU) 2016/679) is the EU's comprehensive data-protection law governing how organisations collect, process, store, and share personal data. In force since 25 May 2018, it applies under Article 3 to organisations established in the Union (Article 3(1)), to non-EU organisations offering goods or services to data subjects in the Union (Article 3(2)(a)), and to non-EU organisations monitoring data-subject behaviour in the Union (Article 3(2)(b)).
For AI systems, GDPR is particularly critical because personal data appears throughout the AI lifecycle: in training datasets, user inputs, operational logs, model outputs, and vendor relationships. Non-compliance under Article 83 carries fines of up to €20 million or 4% of total worldwide annual turnover, whichever is higher.
Where things stand
GDPR is mature law with an active enforcement machine behind it. The question is no longer when it applies, but how it is enforced and what changes next.
In force
Since 25 May 2018
GDPR has applied across every EU Member State for over eight years. There is no transition period left to wait for; the obligations are current-state law.
Enforcement
Billions in cumulative fines
Enforcement has matured into billions in cumulative fines, with recent landmark actions against LinkedIn in 2024 and TikTok in 2025.
What changes next
Cross-border enforcement, streamlined
The GDPR Procedural Regulation (Regulation (EU) 2025/2518), adopted in November 2025 and applicable from 2 April 2027, streamlines how supervisory authorities handle cross-border enforcement cases.
Earlier landmarks in brief: Schrems II invalidated the EU-US Privacy Shield in 2020, and the EU-US Data Privacy Framework restored an adequacy route for certified US organisations in 2023.
Does GDPR apply to you?
GDPR has broad extraterritorial reach. Article 3 defines three scenarios that bring an organisation in scope. There is no general applicability threshold based on size, though specific duties scale with role, risk, and processing type. Pick the scenario that sounds most like you.
The Article 3 territorial test
Which of these describes your organisation?
GDPR applies to personal data processed in the context of your EU establishment’s activities, even when the processing itself runs on servers outside the EU.
- There is no size threshold. One employee or 100,000, Article 3(1) applies the same way.
Offering goods or services to people in the EU, paid or free, brings you into scope with no EU office at all. EU pricing, a Member State language, or EU delivery are classic indicators of intent.
- There is no size threshold. Scope turns on the offering, not on headcount or revenue.
- Non-EU organisations in scope this way generally need to appoint an EU representative under Article 27.
Tracking, profiling, or running analytics on the behaviour of people in the EU counts as monitoring, and most ad tech, product analytics, and personalization does exactly this.
- There is no size threshold. A two-person startup profiling EU users is in scope.
- Non-EU organisations in scope this way generally need to appoint an EU representative under Article 27.
If none of the three Article 3 hooks applies to your processing, GDPR likely does not reach you today.
- One caveat for AI teams: EU personal data has a way of appearing in training data, user inputs, and logs. If it does, one of the hooks above is usually not far behind.
Orientation, not legal advice. Territorial scope can turn on specific facts such as establishment structure and targeting intent, so confirm your position with counsel.
EU Establishment
You process personal data in the context of activities of an establishment in the EU, regardless of whether the processing itself takes place in the EU.
A US company with a sales office in Berlin processes customer data on US servers. GDPR applies because the processing is in the context of the Berlin office's activities.
Offering Goods or Services
You offer goods or services to data subjects in the Union, whether paid or free. Indicators include the use of a Member State language or currency alongside other intent factors identified in EDPB Guidelines 3/2018.
A Japanese SaaS tool with an EU pricing page in euros and German-language support is offering services to EU data subjects. GDPR applies even with no EU office.
Monitoring Behaviour
You monitor the behaviour of individuals within the EU, including profiling, tracking, or analytics on EU users.
A US ad-tech company tracking browsing behaviour of EU website visitors to build advertising profiles. GDPR applies to this behavioural monitoring.
No Size Threshold
Unlike NIS2 or DORA, GDPR has no general applicability threshold based on size. If Article 3 applies, GDPR applies whether you have 1 employee or 100,000. Specific duties scale with role, risk, scale, and processing type; Article 30(5) provides a narrow records-of-processing derogation for organisations with fewer than 250 employees subject to conditions.
EU Representative (Article 27)
Where Article 3(2) applies, non-EU controllers or processors must appoint an EU representative under Article 27 unless an Article 27(2) exception applies. The exceptions cover (a) occasional processing that is not large-scale Article 9 special-category data or Article 10 criminal-offence data and is unlikely to result in a risk to data subjects’ rights and freedoms, and (b) public authorities or bodies. The representative is a contact point for data subjects and supervisory authorities; Article 27(5) preserves direct enforcement against the controller or processor.
GDPR Enforcement Has Global Reach
EU regulators have imposed billions in fines on companies worldwide, demonstrating that GDPR's extraterritorial scope is actively enforced.
Unlawful EU-US data transfers (2023)
Non-compliant ad targeting practices (2021)
Data transfers to China, children's data (2025)
Targeted advertising consent violations (2024)
What do you owe?
Article 5 of GDPR establishes seven principles that form the foundation of all data protection obligations. Every AI system that touches personal data inherits all seven.
Lawfulness, Fairness & Transparency
Data must be processed lawfully, fairly, and in a transparent manner. Individuals must be informed about how their data is used.
Purpose Limitation
Data must be collected for specified, explicit, and legitimate purposes and not further processed in incompatible ways.
Data Minimisation
Only data that is adequate, relevant, and limited to what is necessary for the stated purpose should be processed.
Accuracy
Personal data must be accurate and, where necessary, kept up to date. Inaccurate data must be erased or rectified without delay.
Storage Limitation
Data must be kept in a form that permits identification of individuals for no longer than is necessary for the processing purposes.
Integrity & Confidentiality
Data must be processed with appropriate security, including protection against unauthorised access, loss, or destruction.
Accountability
The data controller is responsible for demonstrating compliance with all GDPR principles and must maintain evidence of compliance.
What can people demand?
GDPR grants individuals comprehensive rights over their personal data. For AI systems, Article 22 on automated decision-making is particularly relevant.
Right to Access
Individuals can request a copy of their personal data and information about how it is being processed.
Right to Rectification
Individuals can request correction of inaccurate personal data without undue delay.
Right to Erasure
The "right to be forgotten": individuals can request deletion of their personal data under certain conditions.
Right to Restrict Processing
Individuals can request limitation of processing while accuracy or lawfulness is being verified.
Right to Data Portability
Where processing is based on Article 6(1)(a) consent or 6(1)(b) contract and carried out by automated means, individuals can receive their data in a structured, machine-readable format and transmit it to another controller.
Right to Object
Individuals can object on grounds relating to their particular situation to processing based on Article 6(1)(e) or 6(1)(f), including profiling. Article 21(2) makes objections to direct marketing absolute.
Automated Decision-Making
Individuals have the right not to be subject to a decision based solely on automated processing (including profiling) producing legal effects or similarly significantly affecting them. Article 22(2) to (4) set the exceptions, safeguards, and Article 9 restrictions.
Right to be Informed
Individuals must be provided with clear, transparent information about how their data is collected and used.
What happens if you get it wrong?
GDPR enforcement is not theoretical. Supervisory authorities have issued billions in fines, and the largest decisions name some of the world's biggest companies.
Landmark fines on one shared scale
What enforcement actually looks like, drawn to scale
Your maximum exposure under Article 83(5)
The higher of €20M or 4% of global annual turnover. Pick a revenue and see the statutory ceiling on the same scale as the fines above.
Even at €1M turnover the Article 83(5) maximum is still up to €20M, because the cap is the higher of €20M or 4% of turnover. The cap is a ceiling, not a prediction: authorities calibrate fines to the case, and real fines at this size are far smaller.
These bars show the statutory ceiling, not a likely outcome. In practice fines are discretionary and proportionate; Article 83(2) directs authorities to weigh nature, gravity, duration, intent, and cooperation when setting the amount.
Article 83(4) lower tier: up to €10M or 2% of total worldwide annual turnover, whichever is higher, for obligations on controllers, processors, certification bodies, and monitoring bodies.
72-hour breach notification: under Article 33, personal-data breaches must be reported to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware.
One AI system, four regimes
GDPR is the regime most AI systems meet first, because personal data is everywhere in the lifecycle. Here is how one system accumulates duties across regimes.
One system, every regime · SYS-04 · credit-scoring model at an EU-serving bank
Credit scoring is Annex III point 5(b): the model is a high-risk AI system.
- Articles 9 to 17 high-risk stack
- Conformity assessment
- EU database registration
Personal data runs through training, inputs, and outputs, and a solely automated credit denial is an Article 22 decision.
- Lawful basis for each processing purpose
- Article 35 DPIA
- Data-subject rights incl. Article 22
At a financial entity, the model is ICT supporting a critical or important function.
- Chapter II ICT risk management
- Major-incident reporting
- Register of information entry
For financial entities NIS2 is largely disapplied: DORA is lex specialis under NIS2 Article 4. Run the same model at an energy or health company and the Article 21 measures attach instead.
- Article 21 cybersecurity measures (where in scope)
- 24h early warning, 72h notification
Four regimes, one system, overlapping controls. Map controls once, keep one evidence record, and reuse it across every regime that attaches. That is the working model behind the Modulos platform.
How the work gets done
Modulos gives privacy and product teams one workflow for requirements, controls, evidence, reviews, and exports. This helps you convert policy expectations into verifiable execution records.
Book a GDPR DemoTranslate GDPR obligations into structured requirements and mapped controls so teams can execute with clear ownership and status tracking.
FAQ about GDPR for AI
The General Data Protection Regulation (GDPR), Regulation (EU) 2016/679, is the EU’s binding data-protection regulation. It governs the processing of personal data of individuals in the Union under the territorial-scope rules in Article 3: establishment in the Union under Article 3(1), offering of goods or services to data subjects in the Union under Article 3(2)(a), or monitoring of behaviour in the Union under Article 3(2)(b). GDPR has been in force since 25 May 2018. Penalties under Article 83 reach the higher of €20 million or 4% of total worldwide annual turnover.
GDPR applies to AI systems that process personal data falling within the territorial scope of Article 3 (Article 3(1) establishment in the Union, Article 3(2)(a) goods or services to data subjects in the Union, or Article 3(2)(b) monitoring of behaviour in the Union). Three groups of articles drive most AI obligations: Article 22 (automated decision-making with significant effects), Article 35 (Data Protection Impact Assessments for high-risk processing), and the lawful-basis requirements of Articles 6 and 9. AI systems also trigger transparency requirements under Articles 13 and 14 when personal data is collected.
Article 22 grants individuals the right not to be subject to a decision based solely on automated processing (including profiling) that produces legal effects or similarly significantly affects them. Article 22(2) sets narrow exceptions: contractual necessity (a), EU or Member State law (b), and explicit consent (c). For decisions taken under (a) or (c), Article 22(3) requires safeguards including human intervention, the right to express a view, and the right to contest. Article 22(4) restricts use of Article 9 special-category data unless Article 9(2)(a) or (g) applies.
Article 35 requires a DPIA when processing is likely to result in a high risk to individuals’ rights and freedoms. The EDPB-endorsed WP248 guidelines from the Article 29 Working Party identify nine criteria, including evaluation or scoring, automated decision-making with significant effects, systematic monitoring, large-scale processing, and innovative-technology applications. Many high-risk AI systems under the EU AI Act will also trigger a GDPR DPIA where personal-data processing is likely high-risk.
GDPR governs personal data processing; the EU AI Act governs AI system safety and fundamental rights. They overlap on biometric processing, automated decision-making, bias detection using sensitive data, and individual rights. Compliance with one does not satisfy the other; both apply simultaneously. The EU AI Act explicitly preserves GDPR (see Article 2(7) and Recital 9 of Regulation (EU) 2024/1689).
This is unsettled and case-specific. Common Article 6(1) bases for AI training: (a) consent under Article 6(1)(a), used for sensitive applications but operationally fragile; (b) legitimate interests under Article 6(1)(f), the most common basis for non-sensitive training, with a documented balancing test; (c) public interest under Article 6(1)(e), only where grounded in applicable EU or Member State law; (d) contract performance under Article 6(1)(b) where narrowly applicable. Special-category data requires an explicit Article 9(2) ground in addition to the Article 6 basis.
Article 35(7) sets the minimum DPIA contents: a systematic description of the envisaged processing operations and purposes; an assessment of the necessity and proportionality; an assessment of the risks to data subjects’ rights and freedoms; and the measures envisaged to address those risks. For AI systems, add data-quality and bias assessment, automated-decision-making analysis, model behaviour assessment, and post-deployment monitoring. The DPIA must precede high-risk processing; refer to the EDPB-endorsed WP248 DPIA guidelines.
Under Articles 22, 13, 14, and 15: the right to know that automated decision-making is taking place; the right to information about the logic involved and the significance of the decision (Articles 13(2)(f) and 14(2)(g)); the right under Article 22(3) to obtain human intervention, express one’s view, and contest the decision; the right of access under Article 15; and rights to rectification (Article 16) and erasure (Article 17) where applicable. National laws may extend these rights further.
Identify the Article 6 lawful basis: typically Article 6(1)(f) legitimate interests with a documented balancing test, not consent (candidates cannot freely refuse, so consent is operationally fragile). Run an Article 35 DPIA before deploying. Provide transparent information to candidates under Articles 13 and 14, and where Article 22 applies, implement the Article 22(3) safeguards (human intervention, right to express a view, right to contest). In Germany, additional analysis under Article 88 GDPR and the BDSG employment provisions is typically required. Many AI hiring tools also trigger high-risk obligations under EU AI Act Annex III, point 4.
GDPR compliance is not a property of an AI tool; it is a property of how a controller uses the tool with personal data. Compliance depends on the concrete role, purpose, data, safeguards, and Article 6 lawful basis, plus Article 28 processor agreements, Article 35 DPIA where required, and Articles 13 and 14 transparency. Some tools or uses may not be deployable lawfully at all (for example, AI Act prohibited practices or Article 22(4) restrictions on special-category data). Focus on your controller obligations, not on the tool’s marketing claims.
Modulos automates the governance workflow at the GDPR-AI intersection: Article 35 DPIA documentation, Article 22 automated-decision-making records, Article 6 lawful-basis tracking, data-subject-rights workflows, Article 28 processor due diligence, model documentation, and monitoring records. Controls map across GDPR, the EU AI Act, ISO/IEC 42001, NIST AI RMF, and SOC 2 simultaneously, so one evidence pipeline serves multiple frameworks.
The European Data Protection Board (EDPB) publishes guidelines and opinions at edpb.europa.eu. National Data Protection Authorities (DPAs) issue country-specific guidance: for AI, the French CNIL, the Spanish AEPD, and the UK ICO have particularly substantive guidance. The EU AI Act’s interaction with GDPR is addressed in joint EDPB and European Commission communications, and the published Regulation (EU) 2016/679 is on EUR-Lex.
How GDPR fits with other frameworks
GDPR rarely operates alone. AI builders and deployers run it alongside the EU AI Act and other frameworks across the same data and the same AI systems.
The EU AI Act explicitly preserves GDPR (Article 2(7) and Recital 9 of Regulation (EU) 2024/1689). The two regimes overlap on biometric processing, automated decision-making, bias detection using sensitive data, and individual rights. Compliance with one does not satisfy the other; both apply.
Where a cybersecurity incident is also a personal-data breach, NIS2 incident-reporting and Article 33 GDPR breach notification can both be triggered. For financial entities, DORA incident reporting layers on top.
Operationally, ISO/IEC 42001 provides the AI-management system inside which GDPR-AI controls run. NIST AI RMF supports the risk-analysis underpinning DPIA and Article 22 work. ISO/IEC 27002 controls support Article 32 security obligations.
For US-attestation work, SOC 2 control sets share evidence with GDPR Article 32 security and Article 28 processor obligations.
By industry
How this applies in your sector
See how this plays out in the sectors where it drives the most AI governance work:
Need Stronger GDPR Governance for AI?
In a live walkthrough, see how to move from policy intent to verifiable execution with structured controls, evidence, and approvals.
