Artificial intelligence and data protection

Data protection glossary · 1 minute read

When artificial intelligence is used, the GDPR applies whenever personal data is processed in training, in the input or in the output.

Data protection issues when using AI

Each phase requires a legal basis, which for the training of large models is often legitimate interest. In addition, there are transparency obligations, the need to safeguard data subject rights and appropriate security measures.

Where AI is used to take decisions with significant effects on individuals, the limits on automated individual decisions must be observed. A data protection impact assessment is often required.

Relationship with the EU AI Act

The EU AI Act, Regulation (EU) 2024/1689, entered into force on 1 August 2024 and applies in stages. It regulates AI systems according to risk classes, but leaves the GDPR unaffected. Companies must comply with both sets of rules in parallel.

When using external AI services, it must be clarified whether the provider acts as a processor and whether inputs are used for the provider's own purposes, such as training.

Art. 6 GDPR
Legal bases for training and use.
Art. 22 GDPR
Automated individual decision-making.
Art. 35 GDPR
Data protection impact assessment for new technologies involving a high risk.
Regulation (EU) 2024/1689
EU AI Act.

Last updated: September 2026

Questions about this topic?

Dr. Georg Schröder, LL.M. · Managing Director, Lawyer, Data Protection Officer

Book a consultation

In 20 minutes you will know where you stand.

We clarify where action is needed on data protection, AI and information security - and what you should do next.