GDPR and AI: What Organisations Need to Know
Using AI systems in organisations is legally complex. Art. 22 GDPR, lawful bases, transparency obligations and data protection impact assessments affect almost every AI use case. OCC explains the key obligations — practice-focused and free.
Why GDPR and AI Are Inseparable
Nearly every AI system processes personal data — whether in training, operation or output. GDPR applies: fully, regardless of whether the AI system is run by a startup or corporation.
Simultaneously, the EU AI Act raises requirements from 2026: high-risk AI (Art. 9 AIA) must demonstrate data governance systems — which effectively requires a DPIA under GDPR. The two regulations interlock.
The 5 Most Important GDPR Articles for AI
Purpose Limitation & Data Minimization
AI systems may only process data for specified, legitimate purposes. Training on historical data requires purpose compatibility. Data minimization constrains feature engineering.
Lawful Basis
Every AI processing needs a lawful basis. Common: contract performance, legitimate interests (with LIA), consent (revocable, fragile for ML training).
Automated Individual Decisions
Fully automated decisions with significant effects are prohibited — except: consent, contract performance, or legal obligation. Credit scoring, HR selection, content moderation affected.
Data Protection Impact Assessment (DPIA)
Required for high-risk processing: profiling with significant effects, systematic monitoring of public areas, processing special categories at scale.
Information Obligations
Data subjects must be informed about AI processing. Transparency on logic, scope and intended effects of automated processing (Art. 13 Abs. 2f).
Art. 22 In Detail: Automated Decisions
Art. 22 is the most critical GDPR article for AI systems. It prohibits decisions that are based solely on automated processing and have significant effects on individuals.
Prohibited (no exceptions)
- Automated credit rejection without human review
- AI-based job rejection (no human in loop)
- Automated termination after behavior scoring
- Price discrimination via personalized profiling
✓ Permitted (with safeguards)
- Credit scoring with consent + right to object
- AI recommendation systems (editorially curated)
- Spam filters (low impact, no person affected)
- Fraud detection with human final decision
Data Protection Impact Assessment (DPIA) for AI
A DPIA is mandatory when processing is likely to result in high risk to rights and freedoms of natural persons (Art. 35 GDPR). For AI systems, this covers:
Practical Compliance Checklist
No legal certainty, but a solid starting point for internal review. Each ✓ should be documented.