GDPR & AI: complete definition in AI for SMEs
GDPR & AI
The intersection of GDPR and AI encompasses all legal obligations and best practices that apply when a company uses Artificial Intelligence on personal data. GDPR imposes strict rules (consent, minimization, right of access, right to erasure) and AI adds complexity layers: are data injected into an LLM stored? Do AI responses contain personal data? Can the model be trained on your data?
What it changes for an SME
GDPR directly impacts every AI use case involving personal data:
- a customer chatbot processing names, emails and purchase history → obligation to inform users and document the processing;
- a prospecting agent enriching profiles → verify the legal basis (legitimate interest or consent);
- an HR copilot processing performance data → strengthened guardrails required.
Common pitfalls
Pasting personal data into an LLM without checking the provider's retention policy. Using a model trained on customer data without a legal basis. Forgetting the right to erasure: if a customer requests data deletion, you must also remove it from the RAG. In fractional AI leadership, we integrate compliance into the initial audit and every deployment.
GDPR questions to ask before deploying an AI tool
- Which personal data goes into the tool (customers, employees, prospects)?
- Which legal basis justifies the processing (contract, legitimate interest, consent)?
- Where is the data processed, and does the vendor reuse it to train its models?
- Is a data processing agreement (article 28) signed with the vendor?
- Is a data protection impact assessment (DPIA) needed, notably when the processing presents a high risk?
- Are individuals informed and able to exercise their rights?
Good reflexes
- minimise: send the model only the data it needs, anonymise or pseudonymise when possible;
- record the processing in your register of activities;
- prefer EU hosting options for sensitive data;
- rely on the recommendations the French regulator CNIL publishes on AI.
Frequently asked questions
Does GDPR apply to an AI agent? Yes, as soon as it processes personal data, like any other processing.
Is this legal advice? No. For a specific case, consult your DPO or a lawyer. We can include these points in scoping during an AI audit.
Related terms
Go further
Ready to apply this to your SME ?
Free Express AI Audit (45 min) — targeted analysis, concrete action plan.