GDPR and AI: personal data in AI tools

What the GDPR asks when you use personal data with AI tools, in the cloud or locally, with the articles and what is still unsettled.

Can I put customer data into ChatGPT or another cloud AI?

Only with three things in place: a legal basis (GDPR Article 6), in practice a processor contract that meets Article 28 so the provider processes the data only on your behalf and, if the data leaves the European Economic Area, a transfer mechanism under Chapter V. If any is missing, do not enter personal data; and health data and the other special categories in Article 9 are prohibited unless one of its exceptions applies.

If the provider processes the data on your behalf, you are the controller and it is your processor (Article 4, points 7 and 8). Article 28(1) requires you to use only providers with sufficient guarantees, and Article 28(3) requires a contract that, among other things, binds it to process the data only on your documented instructions and to delete or return it at the end. Check which terms you are accepting: the consumer version and the business or API version of the same provider can have different terms. If the data goes to the United States, Implementing Decision (EU) 2023/1795 of 10 July 2023 finds an adequate level of protection only for organisations on the EU-US Data Privacy Framework List. The General Court upheld it on 3 September 2025 (Case T-553/23), but that judgment is under appeal before the Court of Justice (Case C-703/25 P), so it is worth following. For destinations without an adequacy decision you need Article 46 safeguards, such as standard contractual clauses. And even with all of that in place, the data minimisation principle (Article 5(1)(c)) asks you to send only what is needed: remove or pseudonymise names when the task does not require them.

Reviewed: Read the full guide →

Do I need a DPIA to use AI?

Not always: GDPR Article 35 requires an impact assessment when processing, in particular using new technologies, is likely to result in a high risk to people. Using AI does not trigger it on its own, but the Spanish AEPD's list says that processing meeting two or more of its criteria requires one in most cases, and the use of new technologies is one of those criteria.

Article 35(3) always requires one in three cases: a systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions with legal or similarly significant effects are based; large-scale processing of special categories or criminal-offence data; and large-scale systematic monitoring of a publicly accessible area. The AEPD's Article 35(4) list, based on the Article 29 Working Party's WP248 guidelines, adds eleven criteria, including profiling, automated decisions, special categories, large-scale processing, data on vulnerable people and the use of new technologies or an innovative use of established technologies. The AEPD itself says the list is not exhaustive: if your own analysis finds a high risk, the DPIA is mandatory even if you do not match the list. Drafting generic text with an assistant, with no personal data, does not require one; scoring candidates or customers with a model meets several criteria (profiling, automated decisions, new technologies) and normally does. The assessment is done before processing starts, with the minimum content in Article 35(7), and if it indicates a high risk you do not mitigate with your measures, Article 36 requires you to consult the AEPD before processing.

Reviewed: Read the full guide →

Does local AI comply with the GDPR automatically?

No. Running the model on your own hardware removes the processor contract and the international transfers with the model provider, but the rest of the GDPR stays the same: you need a legal basis, to inform people, to secure the data, to limit how long you keep it and to handle their rights.

What goes away is specific: if no third party processes the data on your behalf during inference, there is no model processor for Article 28 to apply to and no Chapter V transfer. What remains: the Article 6 legal basis (and an Article 9 exception if special categories are involved), the information duties in Articles 13 and 14, the Article 5 principles (purpose limitation, minimisation, accuracy, storage limitation), Article 32 security, which now depends entirely on you, the rights in Articles 15 to 22 and, where the risk is high, the Article 35 DPIA. Two caveats: if a company maintains the equipment for you and processes the data on your behalf, it is your processor and you need a contract with it; and if the model produces inaccurate statements about specific people and you use them, the accuracy principle in Article 5(1)(d) applies all the same. Local reduces the risk surface; it does not replace compliance.

Reviewed: Read the full guide →

Do I have to tell people that I use AI with their data?

The GDPR does not ask for a line saying "we use AI", but it does require you to say why you process the data, on what legal basis, who receives it (the AI provider included) and whether it is transferred outside the European Economic Area (Articles 13 and 14). And if you take decisions based solely on automated processing with legal or similarly significant effects (Article 22), you must say so and give meaningful information about the logic involved.

If you collect the data from the person, the information is given when you obtain it (Article 13); if you obtain it from another source, within a reasonable period and at the latest within one month, or at the first communication with them (Article 14(3)). A provider that processes the data counts as a recipient even when it is your processor (Article 4(9)). If you are going to use data you already hold for a new purpose, such as analysing it with a model for something other than what you told people, Articles 13(3) and 14(4) require you to inform them before you do. For Article 22 decisions, Articles 13(2)(f) and 14(2)(g) require you to disclose their existence, the logic involved and the envisaged consequences, and where the decision is based on a contract or explicit consent, Article 22(3) requires at least that the person can obtain human intervention, express their point of view and contest the decision. Beyond the GDPR, the AI Act adds its own notices from 2 August 2026, such as telling someone they are talking to a chatbot (Article 50).

Reviewed: Read the full guide →

Can I use personal data to train or fine-tune a model?

It can be lawful, but it is not automatic: training or fine-tuning is processing with its own purpose, which needs a legal basis and, if you reuse data collected for something else, must pass the compatibility test in GDPR Article 6(4). Legitimate interest can work in some cases, according to the European Data Protection Board's Opinion 28/2024, provided you pass its three-step test.

The purpose limitation principle (Article 5(1)(b)) prevents processing data in a way that is incompatible with the purposes you collected it for. If you rely neither on consent nor on a law, Article 6(4) requires you to weigh, among other factors, the link between the two purposes, the context of collection and your relationship with the people, the nature of the data, the possible consequences and the safeguards, such as encryption or pseudonymisation. EDPB Opinion 28/2024, adopted on 17 December 2024, recalls that there is no hierarchy between legal bases and sets out the Article 6(1)(f) legitimate-interest test: a lawful, clearly articulated and real interest; processing that is necessary, with no less intrusive way; and people's rights not overriding it, where their reasonable expectations weigh in. It also warns that a model trained on personal data cannot in all cases be considered anonymous, and it leaves special categories outside its analysis; processing them remains prohibited unless an Article 9(2) exception applies. Under legitimate interest, people keep the Article 21 right to object. One open point: the proposed "Digital Omnibus" Regulation (COM(2025) 837) would change the GDPR on legitimate interest for AI and on the definition of personal data, but according to the European Parliament it is still going through the legislative process and changes nothing above today.

Reviewed: Read the full guide →

What do I do if someone asks for their data to be erased from a model?

Reply within one month (GDPR Article 12(3)) and, if one of the grounds in Article 17(1) applies, erase the data wherever you hold it: conversation logs, knowledge bases and documents the assistant consults, and fine-tuning datasets. Removing data from the weights of a model that is already trained is technically hard, and there is not yet a settled view on how far that obligation reaches.

Erasure is not absolute: Article 17(1) grants it, among other cases, when the data is no longer needed, when consent is withdrawn, when the person successfully objects (Article 21) or when the processing was unlawful, and Article 17(3) sets out exceptions, such as the defence of legal claims. The one month can be extended by two further months for complex requests, if you say so within the first month. If you use a third-party model you have not trained on your data, the request concerns what you process, and if the provider is your processor, Article 28(3)(e) requires it to help you respond. If you have fine-tuned a model on personal data, EDPB Opinion 28/2024 recalls that such a model is not anonymous in all cases, so the rights can reach it; it cites output filters and post-training techniques that attempt to remove or suppress personal data as measures, and notes that authorities can order the erasure of the dataset or of the model itself if it was trained unlawfully. The AEPD's AI guidance asks for training data to be erased once no longer needed, or for a justification of why it cannot be, and recalls that in Spain erasure goes together with the blocking of data under Article 32 of the LOPDGDD (the Spanish data protection act). If you will not act on the request, Article 12(4) requires you to explain why within the month and to mention the right to complain to the AEPD.

Reviewed: Read the full guide →

Who is controller and who is processor when I use an AI provider?

Normally you are the controller, because you decide why and how the data is processed (GDPR Article 4(7)), and the provider is your processor when it processes the data on your behalf (Article 4(8)). If the provider uses that data for its own purposes, such as training its models, it becomes a controller for that use.

As controller, you are responsible for the processing and must be able to demonstrate compliance (Article 5(2)). With a processor, Article 28 requires one with sufficient guarantees, a written contract with the minimum content in Article 28(3) (documented instructions, confidentiality, Article 32 security, help with rights and with the DPIA, deletion or return at the end, audits) and your prior authorisation before it engages other processors (Article 28(2)). Article 28(10) provides that a processor that determines the purposes and means of processing is considered a controller for that processing, and the AEPD's AI guidance applies this to providers: any additional processing they carry out for their own purposes makes them controllers for it. If you and the provider jointly decide purposes and means, you are joint controllers (Article 26): you need an arrangement that allocates the obligations, and the person can exercise their rights against either of you. What counts is who decides the purposes and means, so read the contract together with the provider's data-use policy before entering personal data.

Reviewed: Read the full guide →

Full guide: GDPR and AI: personal data in AI tools · All FAQs