The General Data Protection Regulation (GDPR) is the European Union's foundational data protection law, and it applies in full to artificial intelligence whenever an AI system processes the personal data of people in the EU, whether that data trains a model, feeds a chatbot, or drives an automated scoring or recommendation engine. Two provisions matter most for AI governance: Article 22, which gives individuals a qualified right not to be subject to a decision based solely on automated processing (including profiling) that produces legal or similarly significant effects on them, and Article 35, which requires a Data Protection Impact Assessment (DPIA) before deploying processing likely to result in a high risk to people's rights, a category that explicitly includes large-scale profiling and automated decision-making. GDPR does not switch off when the EU AI Act switches on: the two regimes are cumulative, not alternative, so an AI system that is classified as "high-risk" under the AI Act must still separately satisfy GDPR's legal-basis, transparency, and DPIA obligations. For governance teams, this is not theoretical, European regulators have already banned, investigated, and fined AI products over GDPR violations, and the Court of Justice of the EU has ruled on how Article 22 applies to algorithmic credit scoring.
Run the free AI Health CheckGDPR and AI, the EU's data protection law (Regulation (EU) 2016/679), which applies in full to any AI system that processes the personal data of people in the EU, covering training data, model inputs and outputs, and automated decisions alike.
An AI system is not exempt from data protection law just because it involves machine learning: it still needs a lawful basis for processing personal data, must respect transparency and data-minimization duties, and, where it makes solely automated decisions with legal or similarly significant effects on someone, such as an automated loan denial or hiring rejection, must satisfy Article 22's extra safeguards. Governance teams increasingly run GDPR compliance (lawful-basis analysis, Data Protection Impact Assessments) and EU AI Act compliance (risk classification, fundamental rights impact assessments) side by side on the same system, because the two regimes overlap in subject matter but neither substitutes for the other.
Source: Regulation (EU) 2016/679 (GDPR), eur-lex.europa.eu
Article 22, automated decision-making
Gives individuals the right not to be subject to a decision "based solely on automated processing, including profiling" that produces legal effects or similarly significantly affects them. It applies unless the decision is necessary for a contract, authorised by EU/member-state law with safeguards, or based on explicit consent, and even then, people retain the right to human intervention, to express their view, and to contest the outcome. Decisions built on special-category data (health, biometric, etc.) face extra restrictions under Article 22(4).
Article 35, Data Protection Impact Assessment (DPIA)
Requires a DPIA before processing that is "likely to result in a high risk" to people's rights. Article 35(3)(a) names systematic, extensive automated evaluation or profiling with legal/significant effects as an explicit trigger, squarely covering many AI scoring, hiring, and eligibility systems. The EDPB's endorsed nine-criteria test (from the former Article 29 Working Party's WP248 guidelines) treats two or more criteria present, e.g. large-scale profiling plus sensitive data, as a strong signal a DPIA is required.
Articles 5, 6 and 9, lawful basis and minimization
Every personal-data input to an AI system, including training data, needs a lawful basis under Article 6 (and Article 9 for special-category data), plus adherence to purpose limitation and data minimization. The EDPB's Opinion 28/2024 confirmed that "legitimate interest" can serve as that basis for developing and deploying AI models, but only after a documented three-part test (legitimate interest, necessity, and balancing against the individual's rights), it is not an automatic pass.
Articles 13-15, transparency about the logic involved
Where Article 22 decision-making applies, controllers must give people "meaningful information about the logic involved," as well as the significance and envisaged consequences of the processing, a direct, longstanding legal hook for AI explainability requirements that predates the EU AI Act by years.
GDPR and the EU AI Act (Regulation (EU) 2024/1689) are layered, not competing, regimes. GDPR is fundamental-rights data protection law enforced by national data protection authorities and applies the moment personal data is processed, regardless of an AI system's risk tier. The AI Act is product-safety and market-access legislation, enforced by market surveillance authorities, that imposes tiered obligations based on how an AI system is classified (prohibited, high-risk, limited-risk, minimal-risk). A system can be simultaneously in scope of both, and compliance with one does not automatically satisfy the other.
The clearest overlap is between the GDPR's Article 35 DPIA and the AI Act's Article 27 Fundamental Rights Impact Assessment (FRIA), which certain deployers of high-risk AI systems (notably public bodies and private operators delivering public services, or assessing credit or insurance risk) must complete before use. Article 27(4) of the AI Act allows a deployer that has already carried out a GDPR DPIA to use it to help meet the FRIA obligation, and in practice the two assessments are often prepared together, but they are not the same instrument: a DPIA is about the data (lawfulness, necessity, security), while a FRIA is about the person (fairness, discrimination risk, and the ability to contest an outcome). Separately, Article 26(9) of the AI Act requires deployers to use the information the AI provider supplies to help them meet their own GDPR DPIA duties.
Timing matters here too. The AI Act entered into force on 1 August 2024, with obligations phasing in over several years: prohibited-practice rules applied from 2 February 2025, and general-purpose AI model obligations from 2 August 2025. The bulk of the high-risk obligations under Annex III were originally set to apply from 2 August 2026. Regulation (EU) 2026/1744, the Digital Omnibus on AI amending the AI Act, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, deferring standalone Annex III high-risk obligations to 2 December 2027 and obligations for AI embedded in already-regulated products (Annex I) to 2 August 2028. This deferral applies only to the Annex III/Annex I high-risk obligations, it does not affect the AI Act's Article 50 transparency duties (e.g., chatbot-disclosure and AI-generated-content labelling), which remain due from 2 August 2026 as originally scheduled. None of this affects GDPR, which has applied to AI processing personal data since 25 May 2018 regardless of the AI Act's timeline.
CJEU, SCHUFA (Case C-634/21, 7 December 2023)
The Court of Justice of the EU ruled that a credit reference agency's creation of a repayment-probability "score," relied on heavily by a lender to reject a loan, itself constitutes automated decision-making under Article 22, meaning Article 22 obligations can attach to the party generating the score, not only the party making the final contractual decision. It was the CJEU's first substantive ruling interpreting Article 22's scope.
Italian Garante v. OpenAI / ChatGPT (2023-2026)
Italy's data protection authority imposed a temporary processing ban on ChatGPT in March-April 2023 over lawful basis, transparency, and age-verification failures, then closed a broader investigation in December 2024 with a €15 million fine covering unlawful training-data collection and inadequate age verification. The Tribunal of Rome suspended the fine on appeal in March 2025 and annulled it in March 2026, though the Rome court's ruling turned on jurisdiction (Italy's Garante lost competence once OpenAI's EU lead establishment moved to Ireland, triggering the GDPR one-stop-shop mechanism), not a finding that the underlying lawful-basis or age-verification practices complied with GDPR, so the substantive questions remain unresolved, an illustration that GDPR enforcement against generative AI is real, but its legal boundaries are still being tested in court.
General GDPR penalty exposure
Any confirmed GDPR infringement by an AI system, unlawful training-data processing, missing DPIA, unlawful automated decisions, is subject to the same Article 83 fining framework as any other processing: corrective orders, processing bans, and administrative fines of up to €20 million or 4% of global annual turnover, whichever is higher.
Does GDPR apply to an AI system that doesn't use personal data?
No, GDPR only applies where personal data is processed. In practice, though, a large share of commercially deployed AI (chatbots, recommendation engines, credit and hiring scoring, biometric and facial-recognition tools, and most models fine-tuned or trained on user or customer data) does process personal data, so the exemption is narrower than it looks.
Does Article 22 GDPR ban all automated decision-making by AI?
No. Article 22 creates a qualified right, not a blanket ban: it applies only to decisions based solely on automated processing that produce legal or similarly significant effects, and it does not apply if the decision is necessary for a contract, authorised by law with safeguards, or based on explicit consent. Even where an exception applies, the person keeps the right to obtain human intervention, express their view, and contest the decision.
When is a Data Protection Impact Assessment mandatory for an AI project?
A DPIA is required under Article 35 when processing is likely to result in a high risk to individuals' rights. Article 35(3)(a) explicitly names systematic profiling or automated evaluation with legal or similarly significant effects as a trigger, and EU data protection authorities apply a nine-criteria test (from the former Article 29 Working Party's WP248 guidance) under which meeting two or more criteria is treated as a strong signal a DPIA is needed.
Can a company rely on "legitimate interest" to train an AI model on personal data?
The European Data Protection Board's Opinion 28/2024 confirmed legitimate interest can be a valid legal basis for developing and deploying AI models, but only after passing a documented three-part test, a genuine legitimate interest, necessity of the processing, and a balancing exercise that doesn't override the individual's rights and freedoms. It is not an automatic or default justification.
If my AI system isn't "high-risk" under the EU AI Act, do I still need to comply with GDPR?
Yes. GDPR obligations attach based on whether personal data is processed, not on an AI system's EU AI Act risk classification. A minimal-risk chatbot or recommendation engine under the AI Act can still require a lawful basis, transparency notices, and even a DPIA under GDPR.
What happens if an AI system violates GDPR?
Data protection authorities can issue corrective orders (including processing bans, as Italy did to ChatGPT in 2023), and impose administrative fines of up to €20 million or 4% of global annual turnover. Enforcement outcomes are still being tested in court, Italy's €15 million fine against OpenAI was suspended in 2025 and annulled by the Tribunal of Rome in March 2026, though on jurisdictional grounds (Italy's Garante had lost lead-authority status under the GDPR one-stop-shop mechanism once OpenAI's EU establishment moved to Ireland), not as a substantive ruling on the merits of the training-data or age-verification violations, so this remains an actively litigated area.
Last reviewed July 2026
This page is general information about GDPR and AI: How EU Data Protection Law Applies to AI Systems, not legal, regulatory, or professional advice, and does not capture every nuance or exception. Requirements change and can be fact-specific. Always verify against primary sources and your own qualified legal counsel before relying on it.