ModelCharter
ModelCharter Team

GDPR and AI Tools: What EU Teams Must Know

GDPR data protection concept representing EU privacy requirements for AI tools

Photo: Miguel Á. Padriñán / Pexels

Key takeaways

  • GDPR and AI tools interact through your prompts, the vendor's processing, and the AI's output.
  • A Data Processing Agreement is required whenever personal data passes through an AI tool.
  • Legitimate interests usually covers internal AI use, but log the basis in your RoPA.
  • US-based AI vendors need Standard Contractual Clauses or an equivalent transfer mechanism.
  • Data subject access and erasure requests can require deleting data from your AI vendor's systems too.

GDPR and AI tools collide in three places most teams don't expect at first: your prompts can contain personal data, the AI vendor processes that data on your behalf, and whatever the AI generates about a person carries its own obligations too. If you're already managing GDPR for your usual software stack, adding AI tools to that isn't a separate project, it's an extension of the same one, with a few extra questions attached. This is what changes, in practical terms: which contracts you need, what lawful basis covers the processing, and what happens when someone asks you to delete their data.

Three ways GDPR and AI tools interact

First, your prompts: anyone typing a colleague's name, a customer's email or a candidate's CV into an AI tool is putting personal data into it, whether or not that was the intention. Second, the vendor: once that data leaves your systems, the AI company is processing it on your behalf, which brings GDPR's processor obligations into play in exactly the same way they'd apply to any other outsourced system. Third, the output: if an AI tool generates a profile, summary or decision about a real person, that output is personal data too, and it inherits its own set of obligations around accuracy and fairness.

Do you need a Data Processing Agreement for an AI tool?

If personal data passes through it, yes, even if that data only appears in a prompt rather than a structured field. The AI vendor is processing on your behalf and GDPR requires a Data Processing Agreement covering that relationship. OpenAI, Anthropic, Google and Microsoft all offer DPAs on their business and enterprise tiers. Consumer tiers typically don't include one, which by itself should rule them out for anything involving EU personal data, no matter how useful the free tier looks for the same task.

What's your lawful basis?

Under GDPR Article 6, you need a lawful basis before processing personal data through an AI tool, the same as for any other system. Legitimate interests covers most internal uses: drafting, summarising, analysing. Consent is rarely practical at the scale AI tools operate at, and it's revocable at any time, which makes it a poor fit for routine workflows that a whole team relies on. Whichever basis applies, write it down in your Records of Processing Activities (RoPA); an unwritten lawful basis isn't much of a defence if a regulator asks you to justify it after the fact.

What about transfers outside the EU?

Most major AI vendors process data in the US, which means an international transfer under GDPR the moment a prompt leaves EU infrastructure. That's not automatically a problem, but it needs a legal mechanism behind it, typically Standard Contractual Clauses (SCCs) built into the vendor's DPA. Check that the DPA you're signing actually includes SCCs or an equivalent adequacy mechanism, rather than assuming a well-known US-based vendor has it covered by default just because they're a large company.

Can someone ask you to delete their data from an AI vendor's system?

Yes, and this is the part teams forget. A data subject access request or an erasure request under GDPR can require you to retrieve or delete personal data from any system that holds it, including your AI vendor's, not just your own databases. If the tool retains conversations for 30, 60 or 90 days, that data is in scope for the request during that window. Check your vendor's retention settings and confirm their enterprise tier actually supports deletion on request before you rely on it, rather than discovering the gap when a request lands. Build a short internal process for this now, even a one-line entry in your RoPA saying who to contact at each AI vendor, so a DSAR doesn't turn into a scramble.

Do AI chatbots on your website need their own GDPR notice?

If you run an AI chatbot for customer support on your site, yes, on top of everything already covering back-office AI tools. Visitors interacting with it are having their personal data processed the moment they type a message, so your privacy notice needs to say an AI system is involved, what data it collects, and how long the vendor keeps the transcript. This sits alongside, but is separate from, the EU AI Act's transparency requirement that people should know when they're talking to AI rather than a human. A short addition to your existing privacy notice usually covers it; you don't need a whole new document for a single feature.

A RoPA update worth noting

A data protection lead at a sixty-person SaaS company once ran an annual RoPA review and realised the AI meeting-notes tool the whole company had been using for eight months wasn't listed anywhere in it, despite transcribing calls with EU customers on it weekly. The tool did have a DPA available on its business tier; nobody had signed it, because nobody had flagged the tool as processing personal data in the first place, it had simply spread team by team as a productivity habit. The fix was a signature and a RoPA entry, both quick, but only once someone actually looked closely enough to notice.

Where the EU AI Act adds another layer

GDPR isn't the only rule stacked on top of AI use. Since February 2025, the EU AI Act's AI-literacy duty has required organisations to ensure staff using AI tools understand the basics, and transparency rules mean people should know when they're interacting with AI or AI-generated content. The ICO's guidance on AI and data protection is a good next stop if you want the regulator's own framing of how the two interact in practice.

Put it in the policy, not just your head

Your AI usage policy should say plainly which AI tools are approved for personal data, what lawful basis covers that use, and who owns DSAR requests that touch AI systems. If you handle health data alongside EU personal data, read our HIPAA AI compliance guide too, since both sets of obligations can apply to the same tool at once. See our GDPR compliance hub for the fuller picture and the wider regulatory context.

AI use caseKey GDPR obligationWhere to check it
Drafting/summarising with personal data in the promptDPA with the vendor; lawful basis logged in your RoPAVendor's DPA page; your RoPA
AI meeting notes/transcription of EU customersDPA; retention window checked against DSAR riskVendor's data retention settings
AI-generated profile or summary about a personAccuracy and fairness of the output; explainability if used in a decisionYour AI usage policy
International transfer to a US-based AI vendorSCCs or an equivalent transfer mechanism in the DPAThe DPA's transfer clause
GDPR obligations by AI use case
Organisations must be able to explain how they use AI and personal data as clearly as they would any other processing activity.
paraphrased from ICO guidance on AI and data protection

Frequently asked questions

Does GDPR apply if we're a US company with EU customers?
Yes. GDPR applies based on whose personal data is processed, not where your company is based. If you have EU customers, employees or site visitors, and an AI tool touches their data, GDPR applies to that processing regardless of your own location or where your servers physically sit.
Is legitimate interests always the right lawful basis for AI use?
Not always, but it covers most internal productivity uses. It requires a documented balancing test showing the processing doesn't override the individual's rights, so write that assessment down rather than assuming legitimate interests applies automatically to every AI use case you introduce.
Do free AI tools ever offer a DPA?
Rarely. DPAs are typically reserved for paid business or enterprise tiers, which is one of the clearest signals that a free consumer account isn't the right place for EU personal data, regardless of how good the tool is otherwise for non-sensitive tasks.
What's the difference between a DPA and Standard Contractual Clauses?
A DPA governs the overall processing relationship between you and the vendor. SCCs are a specific legal mechanism, often included as an annex to the DPA, that legitimises transferring the data outside the EU. You typically need both if your AI vendor is US-based and processes any EU personal data.
Do we need a Data Protection Impact Assessment (DPIA) before using an AI tool?
It depends on the scale and risk of the processing, but it's worth doing for anything involving profiling, scoring or decisions about individuals. A short DPIA takes far less time than defending the processing after the fact, and it gives you a documented record of the risks you considered and the mitigations you put in place.

Put this into practice

Generate a free AI usage policy for your team, then see which of your tools are safe to use.

Open the generator