Trustgent
Regulatory readiness · European Union

GDPR for AI procurement, what to verify

GDPR requires a lawful basis for every AI processing operation, a signed data-processing agreement, and defined deletion paths. Here is what to verify.

Trustgent Research DeskPublished Updated Methodology
Editorial guidance, not legal advice. For advice specific to your situation, consult a qualified legal practitioner.

The General Data Protection Regulation (Regulation (EU) 2016/679) has been enforceable across the European Union since 25 May 2018. It governs how personal data about EU residents is collected, processed, and stored, and it applies to any organisation handling that data, regardless of where that organisation is based. For AI procurement, GDPR is not a background consideration: most AI systems process personal data, and many do so in ways that require a defined lawful basis, a written contract with any provider handling the data on your behalf, and in some cases a formal impact assessment before the system goes into use.

What GDPR is and how it structures data protection

GDPR establishes a set of principles for processing personal data, any information relating to an identified or identifiable natural person. It requires that personal data be processed lawfully, fairly, and transparently; collected for specified and explicit purposes; kept accurate; stored no longer than necessary; and protected with appropriate technical and organisational security measures.

Every processing operation needs a lawful basis under Article 6. The six available bases are: consent; performance of a contract; compliance with a legal obligation; protection of vital interests; performance of a task in the public interest; and legitimate interests of the controller or a third party. For AI systems, the most commonly relevant bases are legitimate interests and, where the system makes decisions about individuals, sometimes consent. Relying on legitimate interests requires a documented balancing test demonstrating that the interests are not overridden by the individual's rights.

Special category data, covering health data, biometric data, racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, sex life and sexual orientation, is subject to stricter requirements under Article 9. Processing is prohibited unless one of a defined set of exceptions applies. AI systems that process any of these categories face a higher threshold of justification.

Data subjects hold a set of enforceable rights under Articles 15-22: the right to access their data, the right to rectification, the right to erasure (the 'right to be forgotten' under Article 17), the right to restrict processing, the right to data portability, and in certain cases the right to object to automated decision-making. An AI system that holds personal data in a retrieval index, an embedding store, a training set, or model weights must be able to satisfy a deletion or access request, and a provider who has not worked through how this is done in their architecture has not shipped GDPR-compliant AI.

What it means for buyers commissioning AI builds

When you engage a provider to build or operate an AI system that processes personal data on your behalf, that provider is a data processor under Article 4(8). Before any personal data can be disclosed, you must have a Data Processing Agreement (DPA) in place under Article 28, signed by both parties. The DPA must specify the subject matter, duration, nature and purpose of the processing, the type of personal data and categories of data subjects, and the obligations and rights of the controller.

If the processing is likely to result in a high risk to individuals, which includes systematic and extensive automated processing with significant effects, and large-scale processing of special category data, you are required to conduct a Data Protection Impact Assessment (DPIA) under Article 35 before processing begins. Most AI systems that make or inform significant decisions about individuals, or that process health, financial, or behavioural data at scale, will require one.

Cross-border data transfers present a particular structural question for AI builds. If the provider processes data in a country outside the European Economic Area, or if the AI system uses a third-party model or API provider headquartered outside the EEA, an appropriate transfer mechanism under Article 46 must be in place, such as Standard Contractual Clauses. A pipeline that routes personal data to a US-based LLM API without an adequate transfer mechanism in place is not GDPR-compliant, regardless of the parties' intentions.

The questions that surface GDPR experience

GDPR has no AI-specific certification to wave. What reveals whether a team has actually shipped under GDPR is the specificity of their answers about data flows. A team that can describe the lawful basis for each processing operation, explain how deletion is honoured across each component of the pipeline, and produce a draft DPA without prompting has done this before. A team that describes GDPR as 'handled' without being able to name the lawful basis has not.

How Trustgent's verification relates

Trustgent's provider profiles include a GDPR readiness attribute that is checked against cross-referenced evidence at L2 and above. Self-declaration earns nothing beyond the claim. Providers who have shipped GDPR-relevant AI builds and had those builds cross-referenced against independent documentation are identifiable in the index. We do not verify legal compliance (that is the role of supervisory authorities) but we do make the difference between claimed and evidenced experience visible to buyers.

Procurement checklist

Before engaging a provider for any AI build that handles personal data of EU residents, confirm in writing:

  1. Lawful basis for processing

    Ask the provider to name the lawful basis for each processing operation the AI system will perform. If the answer is 'legitimate interests', ask for the documented balancing test. If the answer is 'consent', ask how consent is captured, recorded, and withdrawn.

  2. Data Processing Agreement

    A DPA under Article 28 must be signed before any personal data is handed over. Ask for the provider's standard DPA and review it against Article 28(3)'s requirements, including provisions on sub-processors, audit rights, and data deletion at the end of the engagement.

  3. Data-flow map

    Ask for a component-level map of where personal data flows: into the model, into any retrieval index, through any third-party API, and into logs. Each hop that crosses an EEA border needs a transfer mechanism; each hop that touches a sub-processor needs a sub-processing agreement.

  4. Deletion and retention behaviour

    The right to erasure under Article 17 applies to personal data held anywhere in the system, including embedding stores, caches, and logs. Ask the provider how they honour a deletion request across every component, and how long residual copies persist.

  5. DPIA readiness

    If your use case involves large-scale processing of personal data, automated decisions with significant effects on individuals, or special category data, a DPIA is required before processing. Ask whether the provider has supported DPIAs for comparable builds and what documentation they can produce.

How Trustgent's verification relates

Trustgent does not assess regulatory compliance. What our verification model does is distinguish between a provider who asserts GDPR experience and one whose experience is corroborated by sources outside their control. At L2 cross-reference level and above, GDPR readiness reflects checked evidence (documentation, case studies, client-side references) not a self-declared badge.

Buyer questions

What is GDPR?
The General Data Protection Regulation (Regulation (EU) 2016/679) is the European Union's primary data protection law, enforceable since 25 May 2018. It governs how personal data about EU residents is collected, processed, and stored, and applies to any organisation handling that data regardless of where it is based.
Why does GDPR apply to AI procurement?
Most AI systems process personal data, through training sets, inference inputs, retrieval stores, or logs. Each processing operation needs a lawful basis under Article 6, and an AI provider handling personal data on your behalf is a data processor who must sign a Data Processing Agreement before any data is shared.
What is a Data Protection Impact Assessment (DPIA)?
A DPIA is a structured assessment required under Article 35 before processing operations that are likely to result in high risk to individuals. AI systems involving systematic automated decision-making with significant effects, large-scale processing of special category data, or large-scale profiling almost certainly require one.
How does GDPR handle deletion requests in AI systems?
The right to erasure under Article 17 applies to personal data wherever it is held, including vector databases, embedding stores, training sets, caches, and logs. A provider must be able to describe concretely how a deletion request is honoured across every component of the pipeline; a vague answer indicates the question has not been worked through.
Does GDPR require a DPA with every AI provider?
Yes. Any provider processing personal data on your behalf is a data processor under Article 4(8), and Article 28 requires a written Data Processing Agreement signed by both parties before any personal data is disclosed to the processor.
What are the transfer rules for cross-border data flows?
Personal data transferred outside the European Economic Area requires a legal transfer mechanism under Article 46, such as Standard Contractual Clauses. This applies to any AI pipeline that routes personal data through a service provider, model API, or infrastructure component based outside the EEA.

Editorial guidance, not legal advice. Trustgent is a verified reference index, not a legal adviser. Consult a qualified practitioner for advice specific to your circumstances. Official source: Regulation (EU) 2016/679 (EUR-Lex).