GDPR
FRAMEWORK · GDPR

GDPR compliance for AI systems

The General Data Protection Regulation is the EU's data-protection law. It applies to any organisation that processes personal data of people in the EU — as a controller or a processor, inside the EU or from outside it — and an AI system that is trained on, prompted with or makes decisions about personal data is processing. The EU AI Act does not replace it: the two apply together, and the EU AI Act sends you back to the GDPR at several points.

Last reviewed · against the consolidated text and Commission guidance

61
article-level references
19
programme steps, each producing a record
5
phases — 4 gate-locked, one conditional
3
conditional steps, opened by a register fact
Legal basis
Regulation (EU) 2016/679
Published by
European Parliament and Council
Status
Statutory · in force · always on
WHO IT APPLIES TO

Who must comply

The regulation binds by role, not by sector — and the EU AI Act's own roles do not change who is the controller.

Controllers

Anyone deciding why and how personal data is processed — the company that deploys an AI system on customer, employee or applicant data is the controller of that processing.

Processors

Anyone processing on a controller's instructions — a provider that hosts or fine-tunes a model on its customer's data is usually a processor, bound by an Art. 28 contract.

Organisations outside the EU

Art. 3 reaches any organisation offering goods or services to people in the EU or monitoring their behaviour, wherever it is established; Art. 27 then asks for an EU representative.

KEY DATES · STATUS

The dates that matter

No certificate is required. Art. 42 schemes exist, are voluntary, and are never issued by Veritome.

DateEventWhat it means
27.04.2016AdoptedRegulation (EU) 2016/679 adopted by the Parliament and the Council.
24.05.2016In forceEntered into force twenty days after publication in the Official Journal.
25.05.2018AppliesApplicable in every member state since this date — no transition remains.
02.08.2026EU AI Act Art. 50The EU AI Act's transparency duties apply since 02.08.2026; they sit beside, not instead of, the GDPR's own Art. 13 and 14 notices.
02.12.2027EU AI Act Annex IIIFrom this date a deployer of a high-risk system uses the provider's Art. 13 information for its GDPR Art. 35 DPIA (EU AI Act Art. 26(9)).
WHAT IT ASKS

61 requirements, in the shape the regulation gives them

The catalogue behind the programme is the 61 articles and paragraphs the 19 steps close in the owner-verified matrix — not a claim to cover the whole regulation. It runs from the Art. 5 principles and Art. 6 and 9 lawful bases through the Art. 12–22 rights, Art. 24–32 accountability and security, Art. 33–36 breaches and impact assessments, to the Chapter V transfer rules. The titles on the page are the articles' own headings; the GDPR is public law.

61
article-level references
48
distinct articles
The 61 references, with the regulation's own headings
  • Art. 2Material scope
  • Art. 3Territorial scope
  • Art. 5(1)(a)Lawfulness, fairness and transparency
  • Art. 5(1)(b)Purpose limitation
  • Art. 5(1)(c)Data minimisation
  • Art. 5(1)(d)Accuracy
  • Art. 5(1)(e)Storage limitation
  • Art. 5(1)(f)Integrity and confidentiality
  • Art. 5(2)Accountability
  • Art. 24Responsibility of the controller
  • Art. 25Data protection by design and by default
  • Art. 37Designation of the data protection officer
  • Art. 38Position of the data protection officer
  • Art. 39Tasks of the data protection officer
  • Art. 4(7)Definition of controller
  • Art. 4(8)Definition of processor
  • Art. 26Joint controllers
  • Art. 30Records of processing activities
  • Art. 6Lawfulness of processing
  • Art. 9Processing of special categories of personal data
  • Art. 10Processing of personal data relating to criminal convictions and offences
  • Art. 89(1)Safeguards for archiving, research and statistical purposes
  • Art. 35Data protection impact assessment
  • Art. 36Prior consultation
  • Art. 32(1)Security of processing — appropriate technical and organisational measures
  • Art. 32(2)Security of processing — assessing the risks
  • Art. 32(3)Security of processing — approved codes and certification as evidence
  • Art. 33Notification of a personal data breach to the supervisory authority
  • Art. 34Communication of a personal data breach to the data subject
  • Art. 11Processing which does not require identification
  • Art. 12Transparent information, communication and modalities for exercising rights
  • Art. 15Right of access by the data subject
  • Art. 16Right to rectification
  • Art. 17Right to erasure
  • Art. 18Right to restriction of processing
  • Art. 19Notification obligation regarding rectification, erasure or restriction
  • Art. 20Right to data portability
  • Art. 21Right to object
  • Art. 22Automated individual decision-making, including profiling
  • Art. 28Processor
  • Art. 13Information to be provided where data are collected from the data subject
  • Art. 14Information to be provided where data have not been obtained from the data subject
  • Art. 29Processing under the authority of the controller or processor
  • Art. 32(4)Persons acting under authority process only on instructions
  • Art. 39(1)(b)DPO monitoring, awareness-raising and training
  • Art. 24(1)Measures implemented, reviewed and updated
  • Art. 4(11)Definition of consent
  • Art. 7Conditions for consent
  • Art. 8Conditions applicable to child's consent in relation to information society services
  • Art. 27Representatives of controllers or processors not established in the Union
  • Art. 44General principle for transfers
  • Art. 45Transfers on the basis of an adequacy decision
  • Art. 46Transfers subject to appropriate safeguards
  • Art. 47Binding corporate rules
  • Art. 48Transfers or disclosures not authorised by Union law
  • Art. 49Derogations for specific situations
  • Art. 31Cooperation with the supervisory authority
  • Art. 40Codes of conduct
  • Art. 41Monitoring of approved codes of conduct
  • Art. 42Certification
  • Art. 43Certification bodies
HOW VERITOME RUNS IT

19 steps, 5 phases, one record each

GDPR is an accountability programme, not a management system, so the path is Establish · Map · Protect · Operate — 4 gate-locked phases with the same rule the EU AI Act journey uses: a phase opens when the one before it is complete. A fifth bucket, Conditional / specialist, sits outside the line: consent, the EU representative, transfers, authority cooperation, codes and certification. It is never locked and never blocks a later phase, and 3 of its steps start as not applicable until the fact holds on your register — for instance, a transfer step opens only once a system says personal data leaves the EU/EEA.

01

Establish

4 steps
  1. Accountability and privacy governance policy
  2. Data protection officer decision
  3. Controller, processor and joint-controller determination
  4. Records of processing activities
02

Map

3 steps
  1. Lawful basis and special-category conditions
  2. Retention schedule
  3. DPIA methodology and screening
03

Protect

4 steps
  1. Security of processing
  2. Personal data breach procedure
  3. Data subject rights procedure
  4. Processor selection, contracts and oversight
04

Operate

3 steps
  1. Privacy notices
  2. Processing instructions, authorisation and privacy training
  3. Periodic review and audit
··

Conditional / specialist

5 steps · never locked
  1. Consent and children’s online-service consent
    Conditional
  2. EU representative decision and mandate
  3. International transfers and safeguards
    Conditional
  4. Supervisory-authority cooperation
  5. Approved codes and certification (conditional)
    Conditional
Outside the line

Conditional / specialist holds the 5 steps that are never gate-locked and never block a phase. 3 of them open on a fact from your register — until it holds, or a person flips the step, each stays marked not applicable:

  • Consent and children’s online-service consentApplies when processing relies on consent, including children's online services
  • International transfers and safeguardsApplies when personal data leaves the EU/EEA
  • Approved codes and certification (conditional)Applies when the organisation joins an approved code of conduct or certification scheme
GDPRGDPR programme
19 steps · 19 records · 0 shared
01Establish
4 steps · Complete
02Map
3 steps · In progress
03Protect
4 steps · Locked
04Operate
3 steps · Locked
··Conditional / specialist
5 steps · Never locked
Map · the steps
  1. 01Lawful basis and special-category conditionsApproved
  2. 02Retention scheduleIn draft
  3. 03DPIA methodology and screeningTo do
Phases and steps as the product generates them · progress shown is illustrative
WHERE IT OVERLAPS

Credited in both, or only related

Nothing in the GDPR programme is credited against another framework — the owner's verified matrix found no clause it could check as identical. What it carries is related links: steps whose record supports an EU AI Act, ISO or NIST requirement, shown in the drawer as supporting reading and never counted as coverage. The DPIA is the exception in practice — the FRIA and the DPIA share their parts, and Veritome maps one onto the other.

WithRecords credited in bothRelated only — shown, never creditedPage
EU AI Act017EU AI Act
ISO 42001016ISO 42001
ISO 27001011ISO 27001
NIST AI RMF04NIST AI RMF

10 of the 19 steps carry a related link to an EU AI Act article. A related link is a supporting candidate the owner's verified matrix did not check against source text; the product shows it beside the step and never counts it as coverage. The full matrix for all five frameworks is on the frameworks page; the EU AI Act itself, article by article, is at /eu-ai-act.

The coverage matrix in Veritome — one row per requirement, one column per framework, credited cells apart from related ones
QUESTIONS PEOPLE ASK

GDPR, answered plainly

The answers below are the ones the page marks up for search engines and AI assistants — the same text, nothing hidden.

Does the EU AI Act replace the GDPR for AI systems?

No. The EU AI Act applies without prejudice to the GDPR, so an AI system that processes personal data answers to both. The EU AI Act adds duties by role and risk tier; the GDPR keeps its lawful-basis, transparency, rights and security duties whatever the tier. The EU AI Act also points back to the GDPR — Art. 26(9) has a deployer use the provider's instructions for its Art. 35 DPIA.

Do I need a DPIA for an AI system?

When the processing is likely to result in a high risk to people — Art. 35 names systematic and extensive evaluation, decisions with legal or similarly significant effects, and large-scale special-category data. Most AI systems that profile, score or rank people meet that threshold. The FRIA the EU AI Act asks of some deployers shares its parts with the DPIA, and Veritome fills one from the other rather than asking twice.

Does Article 22 ban automated decisions?

Not a ban — a right. A person has the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, unless the decision is necessary for a contract, authorised by law or based on explicit consent, and then with safeguards such as human intervention and the right to contest. Whether a given decision is 'solely' automated is a question the record has to answer honestly.

What lawful basis covers training a model on personal data?

One of the six in Art. 6 — most often legitimate interests, which needs a documented balancing test, or consent, which must be as easy to withdraw as to give. Special-category data needs an additional Art. 9 condition. Veritome's lawful-basis step records the basis and the reasoning per purpose; it does not decide the basis for you.

Is there a GDPR certificate?

No certificate is required, and none makes you compliant. Art. 42 allows voluntary certification schemes approved by supervisory authorities, and a few exist. Veritome is not a certifier and never issues one; the programme produces the records an authority or a customer would ask to see.

Does the GDPR apply to a company outside the EU?

Yes, when it offers goods or services to people in the EU or monitors their behaviour there (Art. 3(2)). Such a controller or processor usually has to designate a representative in the EU under Art. 27 — one of the conditional steps in the programme.

What does the GDPR programme in Veritome contain?

19 steps in 4 gate-locked phases plus the Conditional / specialist bucket, closing 61 article-level references. Every step produces a record, and 3 steps open only when the condition holds on your register. Programmes come with a workspace; the free check shows which EU AI Act and GDPR duties a system carries first.

The other four