Skip to main content

GDPR and AI: What Organisations Need to Know

Using AI systems in organisations is legally complex. Art. 22 GDPR, lawful bases, transparency obligations and data protection impact assessments affect almost every AI use case. OCC explains the key obligations — practice-focused and free.

GDPR meets AI governance
~8 min read Applies now (GDPR since 2018) Linked with EU AI Act (Art. 22 refined)

Why GDPR and AI Are Inseparable

Nearly every AI system processes personal data — whether in training, operation or output. GDPR applies: fully, regardless of whether the AI system is run by a startup or corporation.

Simultaneously, the EU AI Act raises requirements from 2026: high-risk AI (Art. 9 AIA) must demonstrate data governance systems — which effectively requires a DPIA under GDPR. The two regulations interlock.

OCC Note: This page explains legal foundations. It replaces no individual legal advice. OCC provides open-source frameworks — not legal services.

The 5 Most Important GDPR Articles for AI

Art. 5 GDPR Risk: medium

Purpose Limitation & Data Minimization

AI systems may only process data for specified, legitimate purposes. Training on historical data requires purpose compatibility. Data minimization constrains feature engineering.

Art. 6 GDPR Risk: high

Lawful Basis

Every AI processing needs a lawful basis. Common: contract performance, legitimate interests (with LIA), consent (revocable, fragile for ML training).

Art. 22 GDPR Risk: critical

Automated Individual Decisions

Fully automated decisions with significant effects are prohibited — except: consent, contract performance, or legal obligation. Credit scoring, HR selection, content moderation affected.

Art. 35 GDPR Risk: high

Data Protection Impact Assessment (DPIA)

Required for high-risk processing: profiling with significant effects, systematic monitoring of public areas, processing special categories at scale.

Art. 13/14 GDPR Risk: medium

Information Obligations

Data subjects must be informed about AI processing. Transparency on logic, scope and intended effects of automated processing (Art. 13 Abs. 2f).

Art. 22 In Detail: Automated Decisions

Art. 22 is the most critical GDPR article for AI systems. It prohibits decisions that are based solely on automated processing and have significant effects on individuals.

Prohibited (no exceptions)

  • Automated credit rejection without human review
  • AI-based job rejection (no human in loop)
  • Automated termination after behavior scoring
  • Price discrimination via personalized profiling

✓ Permitted (with safeguards)

  • Credit scoring with consent + right to object
  • AI recommendation systems (editorially curated)
  • Spam filters (low impact, no person affected)
  • Fraud detection with human final decision
OCC Recommendation: Human-in-the-Loop (HITL) as architecture principle — not as retrofit. The IIO Framework implements HITL gates systemically. HITL in Glossary →

Data Protection Impact Assessment (DPIA) for AI

A DPIA is mandatory when processing is likely to result in high risk to rights and freedoms of natural persons (Art. 35 GDPR). For AI systems, this covers:

Systematic profiling
e.g.: Customer scoring, behavior analysis, health apps
Special data processing (Art. 9)
e.g.: Biometric data, health data, political opinions
Public area monitoring
e.g.: Video AI, movement pattern analysis, geotracking
Innovative technologies
e.g.: Generative AI, LLMs with personal data for training
Automated decisions with legal effect
e.g.: Credit decisions, HR AI, law enforcement

Practical Compliance Checklist

No legal certainty, but a solid starting point for internal review. Each ✓ should be documented.

Full checklist as download coming (Q3 2026). Ask OCC assistant →

Further OCC Resources