AI Sentri helps you understand and manage how AI systems use personal data — with transparency, control, and accountability.
When AI systems process personal data, GDPR applies. Understanding this intersection is critical for responsible AI deployment and data protection compliance.
Mapping GDPR expectations to practical outcomes.
AI Sentri supports organisations in managing AI systems that involve personal data, but does not provide legal advice or guarantee GDPR compliance. Organisations should seek appropriate professional guidance.
AI Sentri helps you bring structure and visibility to how AI interacts with personal data.
AI Sentri is an aid, not an assurance. It helps you structure your thinking, record what you have done and see where the gaps are. It does not make you compliant, and nothing it produces is legal advice or a regulatory opinion. Scores are indicative. Responsibility for compliance stays with your organisation, and decisions with legal consequences should be taken with a qualified adviser.
Before you start
There is no AI-specific basis — you use the same six, most often legitimate interests, contract or consent. Legitimate interests is the most common for AI and the most often asserted without the balancing test that makes it valid. Whichever you rely on must be identified before processing starts and recorded per system, because it determines what rights people have against you.
Not every one, but more than most organisations assume. The ICO treats innovative technology, large-scale profiling and automated decision-making with significant effects as triggers, and AI usually hits at least one. Where you conclude a DPIA is not needed, record why — an undocumented decision not to assess is harder to defend than the assessment itself.
People have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects — credit, employment, access to services. If you rely on one of the narrow exceptions you must still provide meaningful information about the logic and a route to human intervention. A human rubber-stamping the output does not make the decision non-automated.
Purpose limitation is the pinch point: personal data collected for one purpose cannot simply be reused to train a model. You need a basis for the training itself, and to consider whether the model memorises personal data. Accuracy applies to inferences too, not only stored fields — an inaccurate prediction about someone is inaccurate personal data.
The same principles apply, but AI stresses them harder. Lawful basis is more difficult where data is reused for training, purpose limitation conflicts with model reuse, accuracy applies to inferences and not just stored fields, and transparency is harder where the logic is opaque. Article 22 adds specific protection around solely automated decisions with legal or similarly significant effects.
Whenever processing is likely to result in a high risk to people's rights and freedoms, which covers most AI involving personal data at scale, profiling, or automated decisions with real consequences. In practice, assume one is needed and record the reasoning if you conclude otherwise. AI Sentri tracks DPIA status per system so gaps are visible rather than assumed closed.
That is a decision for your DPO or legal adviser, not a setting in a tool — but it must be recorded per system, and it is where AI projects most often come unstuck. AI Sentri requires a lawful basis per system and treats its absence as a hard gap, because a system processing personal data without one is not a scoring nuance.
Usually, but not always, and the answer determines who carries which obligations. Where a vendor determines purposes and means of processing they may be a controller in their own right. AI Sentri records the vendor and the data involved per system so the question is at least asked for each one.
More in the full FAQ, or ask us directly.