We use a few strictly-necessary cookies, no marketing trackers, and cookieless analytics. Read our cookie policy, or pick a preference.
The baseline for personal data, and the regime an AI system meets the moment it touches it. The GDPR governs how personal data is collected, used, and decided upon; it reaches any organisation processing the data of people in the EU or UK; and it runs in parallel with the AI Act, not beneath it.
The GDPR is built on principles, not a checklist. Every processing activity must rest on a lawful basis, honour the data subject's rights, and be something the organisation can demonstrate, not merely assert. For AI, the sharpest edges are training data (which needs a lawful basis like any other processing) and automated decisions.
Article 22 gives a person the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, unless a narrow exception applies with safeguards. Where AI processing is likely to be high-risk, a data protection impact assessment is required before it starts.
Lawfulness, fairness, transparency, purpose limitation, minimisation, accuracy, storage limitation, integrity.
Every use needs one of six bases; special-category data needs an Article 9 condition on top.
Access, rectification, erasure, portability, objection, and the Article 22 automated-decision right.
Demonstrate compliance, and run a DPIA before high-risk processing such as large-scale AI profiling.
Unlike the AI Act, the GDPR is fully in force. The questions now are enforcement and how it interacts with newer AI law.
Regulation 2016/679 adopted, with a two-year run-up to application.
Applies across the EU; supervisory authorities begin enforcement.
UK GDPR takes effect post-Brexit, mirroring the EU text with UK-set fines.
Source: Official Journal of the EU · UK Data Protection Act 2018 / UK GDPR · UK reform is ongoing; confirm the current UK text before relying on it
The GDPR splits responsibility by whether you decide the purpose of the processing or only carry it out for someone else.
The primary duty-bearer. Lawful basis, transparency, rights handling, DPIAs, and the accountability to prove all of it.
Act only on documented instructions, secure the data, assist the controller, and carry direct duties for security and sub-processors.
Where two organisations jointly set the purpose, they must agree and make transparent who answers for which obligation.
A data protection officer where required (Article 37), and an EU or UK representative for organisations established outside the territory (Article 27).
Fines are the higher of a fixed ceiling or a percentage of worldwide annual turnover. The UK applies equivalent sterling ceilings.
| Tier | What triggers it |
|---|---|
| €20M / 4%UK £17.5M / 4% | Breaching the basic principles, lawful basis and consent conditions, data-subject rights, or the rules on international transfers. |
| €10M / 2%UK £8.7M / 2% | Failing the more procedural duties: records, security measures, breach notification, DPO, or DPIA obligations. |
Figures per GDPR Articles 83(4)–(5) and the UK GDPR · confirm current ceilings against the consolidated text
"We're not in the EU, so the GDPR doesn't reach us."
Article 3 reaches any controller or processor offering goods or services to, or monitoring, people in the EU or UK, wherever it is established. A US model serving EU users is in scope.
"We have consent, so we can use the data however we like."
Consent is one of six bases and must be freely given, specific, and revocable. A solely automated decision with significant effect needs an Article 22 basis and safeguards, not just consent.
"The training data is anonymised, so the GDPR is out of scope."
Only truly anonymous data escapes the GDPR. Pseudonymised data, and data that can be re-identified through combination or model memorisation, remains personal data with full duties attached.
It can. Under Article 3, GDPR applies extraterritorially where you offer goods or services to individuals in the EU or monitor their behaviour, regardless of where your organisation is established. Non-EU controllers and processors in scope must also designate an EU representative under Article 27.
Article 83 sets two tiers, each the higher of a fixed sum or a percentage of total worldwide annual turnover: up to EUR 10 million or 2% for lower-tier breaches (such as records or security failings), and up to EUR 20 million or 4% for breaches of core principles, lawful-basis, or data-subject-rights obligations.
A controller must notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach (Article 33). Where the breach is likely to result in a high risk to individuals, affected data subjects must also be informed without undue delay (Article 34).
Article 37 requires a DPO where you are a public authority, or where your core activities involve regular and systematic monitoring of individuals on a large scale, or large-scale processing of special-category or criminal-offence data. Many organisations appoint one voluntarily; some Member States impose wider national requirements.
No. A Data Protection Impact Assessment under Article 35 is required only where processing is likely to result in a high risk to individuals, for example large-scale profiling, systematic monitoring of a public area, or large-scale special-category processing. Supervisory authorities publish lists of operations that always require one.
No, and treating it as the default is a common error. Article 6 provides six lawful bases, including contract, legal obligation, and legitimate interests. Consent is often not the most appropriate basis, and where relied on it must be freely given, specific, informed, and as easy to withdraw as to give.
An AI system processing personal data answers to the GDPR and the AI Act at once, and often NIS2 or DORA as well. We map at the level of the obligation, so a single body of evidence holds across all of them.