GDPR and AI Tools: What EU Teams Must Know

Photo: Miguel Á. Padriñán / Pexels
Key takeaways
- GDPR and AI tools interact through your prompts, the vendor's processing, and the AI's output.
- A Data Processing Agreement is required whenever personal data passes through an AI tool.
- Legitimate interests usually covers internal AI use, but log the basis in your RoPA.
- US-based AI vendors need Standard Contractual Clauses or an equivalent transfer mechanism.
- Data subject access and erasure requests can require deleting data from your AI vendor's systems too.
GDPR and AI tools collide in three places most teams don't expect at first: your prompts can contain personal data, the AI vendor processes that data on your behalf, and whatever the AI generates about a person carries its own obligations too. If you're already managing GDPR for your usual software stack, adding AI tools to that isn't a separate project, it's an extension of the same one, with a few extra questions attached. This is what changes, in practical terms: which contracts you need, what lawful basis covers the processing, and what happens when someone asks you to delete their data.
Three ways GDPR and AI tools interact
First, your prompts: anyone typing a colleague's name, a customer's email or a candidate's CV into an AI tool is putting personal data into it, whether or not that was the intention. Second, the vendor: once that data leaves your systems, the AI company is processing it on your behalf, which brings GDPR's processor obligations into play in exactly the same way they'd apply to any other outsourced system. Third, the output: if an AI tool generates a profile, summary or decision about a real person, that output is personal data too, and it inherits its own set of obligations around accuracy and fairness.
Do you need a Data Processing Agreement for an AI tool?
If personal data passes through it, yes, even if that data only appears in a prompt rather than a structured field. The AI vendor is processing on your behalf and GDPR requires a Data Processing Agreement covering that relationship. OpenAI, Anthropic, Google and Microsoft all offer DPAs on their business and enterprise tiers. Consumer tiers typically don't include one, which by itself should rule them out for anything involving EU personal data, no matter how useful the free tier looks for the same task.
What's your lawful basis?
Under GDPR Article 6, you need a lawful basis before processing personal data through an AI tool, the same as for any other system. Legitimate interests covers most internal uses: drafting, summarising, analysing. Consent is rarely practical at the scale AI tools operate at, and it's revocable at any time, which makes it a poor fit for routine workflows that a whole team relies on. Whichever basis applies, write it down in your Records of Processing Activities (RoPA); an unwritten lawful basis isn't much of a defence if a regulator asks you to justify it after the fact.
What about transfers outside the EU?
Most major AI vendors process data in the US, which means an international transfer under GDPR the moment a prompt leaves EU infrastructure. That's not automatically a problem, but it needs a legal mechanism behind it, typically Standard Contractual Clauses (SCCs) built into the vendor's DPA. Check that the DPA you're signing actually includes SCCs or an equivalent adequacy mechanism, rather than assuming a well-known US-based vendor has it covered by default just because they're a large company.
Can someone ask you to delete their data from an AI vendor's system?
Yes, and this is the part teams forget. A data subject access request or an erasure request under GDPR can require you to retrieve or delete personal data from any system that holds it, including your AI vendor's, not just your own databases. If the tool retains conversations for 30, 60 or 90 days, that data is in scope for the request during that window. Check your vendor's retention settings and confirm their enterprise tier actually supports deletion on request before you rely on it, rather than discovering the gap when a request lands. Build a short internal process for this now, even a one-line entry in your RoPA saying who to contact at each AI vendor, so a DSAR doesn't turn into a scramble.
Do AI chatbots on your website need their own GDPR notice?
If you run an AI chatbot for customer support on your site, yes, on top of everything already covering back-office AI tools. Visitors interacting with it are having their personal data processed the moment they type a message, so your privacy notice needs to say an AI system is involved, what data it collects, and how long the vendor keeps the transcript. This sits alongside, but is separate from, the EU AI Act's transparency requirement that people should know when they're talking to AI rather than a human. A short addition to your existing privacy notice usually covers it; you don't need a whole new document for a single feature.
A RoPA update worth noting
A data protection lead at a sixty-person SaaS company once ran an annual RoPA review and realised the AI meeting-notes tool the whole company had been using for eight months wasn't listed anywhere in it, despite transcribing calls with EU customers on it weekly. The tool did have a DPA available on its business tier; nobody had signed it, because nobody had flagged the tool as processing personal data in the first place, it had simply spread team by team as a productivity habit. The fix was a signature and a RoPA entry, both quick, but only once someone actually looked closely enough to notice.
Where the EU AI Act adds another layer
GDPR isn't the only rule stacked on top of AI use. Since February 2025, the EU AI Act's AI-literacy duty has required organisations to ensure staff using AI tools understand the basics, and transparency rules mean people should know when they're interacting with AI or AI-generated content. The ICO's guidance on AI and data protection is a good next stop if you want the regulator's own framing of how the two interact in practice.
Put it in the policy, not just your head
Your AI usage policy should say plainly which AI tools are approved for personal data, what lawful basis covers that use, and who owns DSAR requests that touch AI systems. If you handle health data alongside EU personal data, read our HIPAA AI compliance guide too, since both sets of obligations can apply to the same tool at once. See our GDPR compliance hub for the fuller picture and the wider regulatory context.
| AI use case | Key GDPR obligation | Where to check it |
|---|---|---|
| Drafting/summarising with personal data in the prompt | DPA with the vendor; lawful basis logged in your RoPA | Vendor's DPA page; your RoPA |
| AI meeting notes/transcription of EU customers | DPA; retention window checked against DSAR risk | Vendor's data retention settings |
| AI-generated profile or summary about a person | Accuracy and fairness of the output; explainability if used in a decision | Your AI usage policy |
| International transfer to a US-based AI vendor | SCCs or an equivalent transfer mechanism in the DPA | The DPA's transfer clause |
“Organisations must be able to explain how they use AI and personal data as clearly as they would any other processing activity.”