GDPR & privacy
GDPR & privacy
The AI Act does not replace data protection law. If an AI system processes personal data, both regimes apply simultaneously, enforced by different authorities with separate penalty regimes. This module covers the GDPR side.
Transcript
The AI Act does not replace data protection law. If an AI system processes personal data, both regimes apply at the same time, enforced by different authorities with separate penalty regimes.
Open the Trust & Privacy Hub. This is the GDPR side of the platform: requests, breaches, processors, and consent in one place.
Privacy Requests handles the Articles 15 to 21 rights: access, rectification, erasure, portability, and objection, each with its own deadline clock.
The Breach Center is the Article 33 register. Log a breach and the seventy-two hour notification clock starts, with the authority target set.
Data & Vendors is the Article 28 processor register: every third party processing data on your behalf, with DPA status and transfer safeguards.
Consent Records covers Article 7. Record the lawful basis and the consent method, and the evidence feeds both GDPR and frameworks like CCPA.
The same obligations engine tracks the GDPR articles alongside the AI Act, so the two regimes run together instead of being managed in two separate systems.
Why this is required
Article 6 requires a lawful basis for every processing activity: consent, contract, legal obligation, vital interests, public task or legitimate interests. Where consent is the basis, Article 7 requires you to be able to demonstrate that it was given, which makes an unevidenced consent no basis at all.
Article 28 governs processors. Where a vendor processes personal data on your behalf, you need a written contract covering the subject matter, duration, nature and purpose of the processing, the type of personal data and categories of data subjects, and you remain accountable for their compliance. Every AI vendor handling your users' data is in scope.
Chapter V governs transfers outside the European Economic Area, requiring an adequacy decision or appropriate safeguards such as standard contractual clauses. This bites hard on AI, where models are frequently hosted outside the EU.
Article 32 requires security appropriate to the risk, including pseudonymisation and encryption where appropriate, and the ability to restore availability after an incident.
The AI Act and the GDPR intersect most sharply at Article 22, which gives people the right not to be subject to a solely automated decision producing legal or similarly significant effects: the exact profile of many high-risk AI systems.
What EuroCompliant does
The GDPR module covers records of processing (Article 30), data subject requests (Articles 15-22), the processor register (Article 28) and breach notification (Articles 33-34), each with its own guide.
The processor register tracks each vendor, what they process, where they are located, and the transfer safeguards relied on.
Consent records capture when consent was obtained, for what purpose, and whether it has since been withdrawn: the evidence Article 7 requires.
GDPR document types generate from this data: records of processing, processor registers, request logs and breach reports.
Walking through it
Record a lawful basis for each processing activity
Do this per activity, not per system. A single system often processes for several purposes on different bases.
Open /privacy-hub →Register your processors
Every vendor processing personal data on your behalf, with the Article 28 contract and any transfer safeguards recorded.
Open /privacy-hub →Check transfers outside the EEA
For each processor, identify where the data actually goes and what Chapter V mechanism covers it.
Maintain consent evidence
Where consent is your basis, keep the record of when and how it was obtained and the mechanism for withdrawal.
The law
Lawfulness of processing
Processing requires at least one of six lawful bases.
Conditions for consent
The controller must be able to demonstrate that the data subject consented.
Processor
Processing by a processor requires a written contract setting out subject matter, duration, nature, purpose, data types and data subject categories.
Security of processing
Technical and organisational measures appropriate to the risk, including pseudonymisation, encryption and resilience.
Automated individual decision-making
The right not to be subject to a solely automated decision producing legal or similarly significant effects.
Penalties for non-compliance
GDPR Article 83 sets fines of up to €20 million or 4% of total worldwide annual turnover, whichever is higher, for breaches of the basic principles, data subject rights and transfer rules. These apply independently of any AI Act penalty for the same system.
Frequently asked
If we comply with the AI Act, are we GDPR compliant?
No. They are separate regimes with separate regulators and separate penalties. The AI Act governs the system; the GDPR governs the personal data it processes. A high-risk system can be fully AI Act compliant and still unlawful for lack of a lawful basis.
Can we use personal data to train a model under legitimate interests?
Sometimes, but it requires a documented balancing test weighing your interest against the data subject's rights and reasonable expectations, and it does not work for special category data without an Article 9 condition. Take advice on the specific case. This is one of the most contested areas in current enforcement.
Related guides
Data subject requests (DSARs)
Tracking Articles 15 to 22 requests against the one-month statutory clock, including the automated-decision right that bites hardest on AI.
Breach notification
The seventy-two hour clock under Article 33, what the notification must contain, and when you must tell individuals directly.
Records of processing (RoPA)
The Article 30 record: the foundational GDPR document, and usually the first thing requested in an investigation.
Try it on your own systems
Everything in this guide runs in the live product. Start a free trial and follow along with your own data.
Start free trial