All guides
AISaaSGDPR

Data Protection & GDPR for AI

Your lawful basis for using personal data in training and inference, and how you handle automated decisions — where most AI products are exposed.

6 min read

A privacy policy is one piece. The harder questions — your lawful basis for using personal data in training and inference, and how you handle automated decisions — are where most AI products are exposed. This guide works through them.

Dossier

For
AI and SaaS companies handling personal data, especially those training on user data, making automated decisions, or selling to enterprise customers with data-protection requirements.
Covers
Lawful basis & data flows · training-data governance · automated decisions · DPAs · DPIAs.
The overlap
The EU AI Act governs the system; the GDPR governs the personal data it uses — AI products usually need both, kept consistent.
Reference points
GDPR (Regulation (EU) 2016/679) and the EDPB’s Opinion 28/2024 on AI models.

Establish your lawful basis and map your data flows

Under the GDPR, every use of personal data needs a lawful basis. Article 6 sets out six: consent, performance of a contract, a legal obligation, vital interests, a public-interest task, and legitimate interests. The exposure for AI products is usually not "do we have a policy" but "what is our basis for each use of personal data — collection, training, inference — and can we evidence it."

  • Map how personal data moves through your product and model, and attach a lawful basis to each distinct use.
  • Where you process special-category data (Article 9) — health, biometrics, and similar — you need an Article 9 condition on top of your Article 6 basis.
  • The basis you rely on for training can differ from the one for inference or deployment; treat them separately.

Get training-data governance right

The data behind your models needs sourcing, consent where relevant, and documentation you can stand behind. This has become one of the most scrutinised areas in AI data protection.

In December 2024 the European Data Protection Board (EDPB) issued Opinion 28/2024 on processing personal data in the context of AI models. Three points from it are worth building around:

  • Model anonymity isn’t automatic. Whether a trained model is “anonymous” is assessed case by case, and the threshold is high — you’d need to show the likelihood of extracting personal data about individuals from the model (directly or through queries) is insignificant.
  • Legitimate interest can be a valid basis for development and deployment, but only via a structured three-step test: a genuine legitimate interest, the necessity of the processing for it, and a balancing against the rights and reasonable expectations of the people whose data is used.
  • Mitigations strengthen the balance — measures like pseudonymisation, genuine transparency about data sources, and an opt-out all weigh in your favour in that assessment.

Handle automated decisions and profiling

Where your product makes or supports decisions about people, additional GDPR obligations attach. Article 22 gives individuals the right not to be subject to a decision based solely on automated processing — including profiling — that produces legal effects or similarly significantly affects them, save in defined circumstances and with safeguards.

  • Identify where your system makes or materially drives decisions about individuals (credit, eligibility, employment-related screening, and the like).
  • Where Article 22 is engaged, build in the transparency, the meaningful information about the logic involved, and the safeguards — such as human review — that the GDPR requires.
  • Tie this to your transparency notices under Articles 13–14, which are where individuals learn that such processing happens.

Write notices and DPAs built for an AI product

Two sets of documents do real work here, and neither should be lifted from a generic SaaS template:

  • Privacy notices (Articles 13–14) — user-facing information written for how your AI product actually uses data, including, where you rely on it, the enhanced transparency the EDPB associates with a legitimate-interest basis for AI models.
  • Data-processing agreements (Article 28) — the contracts your enterprise customers and vendors will require, governing processing carried out on their behalf. Enterprise buyers increasingly won’t sign without a DPA that fits an AI use case.

Run a DPIA and keep GDPR and the AI Act consistent

Where processing is likely to result in a high risk to individuals — often the case for AI involving large-scale or sensitive data, or automated decisions — the GDPR requires a Data Protection Impact Assessment (Article 35) before you start. It’s both an obligation and a useful forcing function for the analysis in steps 01–03.

Finally, keep the two regimes aligned. The EU AI Act governs the AI system; the GDPR governs the personal data that system uses. They overlap but aren’t the same, and AI products usually need both — so the smart move is to make your AI-governance and data-protection workstreams consistent rather than running them in separate silos that contradict each other.

Get your data protection in order

Want it done for you? See our Data Protection & GDPR for AI solution.

Book a consultation

Sources checked

GDPR — Regulation (EU) 2016/679, in particular Articles 5, 6, 9, 13–14, 22, 28 and 35; EDPB Opinion 28/2024 on certain data-protection aspects related to the processing of personal data in the context of AI models (adopted 17 December 2024), and EDPB Guidelines 1/2024 on Article 6(1)(f) legitimate interest referenced within it; interaction with the EU AI Act, Regulation (EU) 2024/1689. Application of Article 22 continues to be shaped by case law and supervisory guidance; confirm current interpretation for your facts.

guideAISaaSGDPR

More from the journal

See all

FATF Publishes Targeted Report on DeFi Regulatory Challenges, 21 July 2026

On 21 July 2026, the Financial Action Task Force published its Targeted Report on Regulatory Challenges from Decentralised Finance. The report finds that 93% of surveyed jurisdictions have not implemented FATF Recommendation 15 as it applies to qualifying DeFi arrangements, and only two jurisdictions have licensed or registered a DeFi arrangement. The FATF issues recommendations to jurisdictions and DeFi operators to close identified regulatory gaps and reduce illicit finance risk.

EU Digital Omnibus Regulation 2026/1744 Enters Into Force, Extending AI Act Compliance Timelines

Regulation (EU) 2026/1744 (the AI Digital Omnibus) entered into force on 27 July 2026, amending the EU AI Act to extend compliance timelines for high-risk AI systems. Operators covering Annex III sectors have until 2 December 2027 to meet Chapter III obligations. AI systems embedded in Annex I products have until 2 August 2028. The Omnibus cites CEN and CENELEC standardisation delays as justification for both extensions.

EU AI Act Article 50 Transparency Obligations Apply from 2 August 2026

Article 50 of Regulation (EU) 2024/1689 (the EU AI Act) takes general application on 2 August 2026. Providers of interactive AI systems must notify users they are communicating with an AI and embed machine-readable marks in AI-generated content. Deployers must inform individuals exposed to deep fakes and AI-generated public-interest content published without human review. The European Commission published final implementation guidelines on 20 July 2026.