AI Sentri
    GDPR & AI

    GDPR compliance for AI, recorded per system.

    AI Sentri helps you understand and manage how AI systems use personal data — with transparency, control, and accountability.

    AI and GDPR — What's the Link?

    When AI systems process personal data, GDPR applies. Understanding this intersection is critical for responsible AI deployment and data protection compliance.

    GDPR applies whenever AI systems collect, process, or use personal data
    It covers how data is gathered, what it's used for, and how decisions are made
    Automated decision-making and profiling have specific requirements under GDPR

    Why It Matters

    AI often processes sensitive or personal data
    Increased scrutiny on automated decisions
    Strong requirements for transparency and accountability
    Significant penalties for misuse

    How AI Sentri Supports GDPR Alignment

    Mapping GDPR expectations to practical outcomes.

    ExpectationPersonal Data Identification
    What It RequiresKnow where personal data is used
    How AI Sentri DeliversExplicit identification of AI systems using personal data
    What This Means for YouClear visibility of where personal data is involved
    ExpectationLawful Basis for Processing
    What It RequiresJustify why data is used
    How AI Sentri DeliversCapture of legal basis within each AI system
    What This Means for YouConfidence that data usage is intentional and justifiable
    ExpectationData Minimisation
    What It RequiresOnly use necessary data
    How AI Sentri DeliversDocumentation of data types and justification
    What This Means for YouAvoid unnecessary data exposure and reduce risk
    ExpectationTransparency & Explainability
    What It RequiresBe clear about how data is used
    How AI Sentri DeliversIntended use, limitations, and explainability fields
    What This Means for YouAbility to clearly explain how decisions are made
    ExpectationAutomated Decision-Making Safeguards
    What It RequiresProtect individuals from automated decisions
    How AI Sentri DeliversHuman oversight tracking within systems
    What This Means for YouSafeguards in place for high-impact decisions
    ExpectationData Retention
    What It RequiresDefine how long data is stored
    How AI Sentri DeliversRetention policies captured per system
    What This Means for YouAvoid keeping data longer than necessary
    ExpectationData Subject Rights
    What It RequiresSupport access, correction, and deletion
    How AI Sentri DeliversClear mapping of how systems handle personal data
    What This Means for YouBe prepared to respond to data subject requests
    ExpectationAccountability
    What It RequiresDemonstrate compliance
    How AI Sentri DeliversCentralised, structured governance records
    What This Means for YouShow how your organisation manages data responsibly
    ExpectationRisk & Impact Awareness
    What It RequiresUnderstand impact on individuals
    How AI Sentri DeliversRisk capture including privacy, bias, and misuse
    What This Means for YouUnderstand and reduce potential harm to individuals
    ExpectationAuditability
    What It RequiresBe able to evidence compliance
    How AI Sentri DeliversConsistent, auditable system-level records
    What This Means for YouEvidence your approach without manual effort

    Key Capabilities

    Clear visibility of where personal data is used
    Structured capture of legal basis and data handling
    Explainability and transparency built into every system
    Human oversight for automated decisions
    Centralised, auditable governance

    Important Note

    AI Sentri supports organisations in managing AI systems that involve personal data, but does not provide legal advice or guarantee GDPR compliance. Organisations should seek appropriate professional guidance.

    AI Sentri helps you bring structure and visibility to how AI interacts with personal data.

    AI Sentri is an aid, not an assurance. It helps you structure your thinking, record what you have done and see where the gaps are. It does not make you compliant, and nothing it produces is legal advice or a regulatory opinion. Scores are indicative. Responsibility for compliance stays with your organisation, and decisions with legal consequences should be taken with a qualified adviser.

    Before you start

    Questions about GDPR and AI

    What is the lawful basis for AI under GDPR?

    There is no AI-specific basis — you use the same six, most often legitimate interests, contract or consent. Legitimate interests is the most common for AI and the most often asserted without the balancing test that makes it valid. Whichever you rely on must be identified before processing starts and recorded per system, because it determines what rights people have against you.

    Do we need a DPIA for every AI system?

    Not every one, but more than most organisations assume. The ICO treats innovative technology, large-scale profiling and automated decision-making with significant effects as triggers, and AI usually hits at least one. Where you conclude a DPIA is not needed, record why — an undocumented decision not to assess is harder to defend than the assessment itself.

    What does Article 22 mean for automated decisions?

    People have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects — credit, employment, access to services. If you rely on one of the narrow exceptions you must still provide meaningful information about the logic and a route to human intervention. A human rubber-stamping the output does not make the decision non-automated.

    How does GDPR apply to AI training data?

    Purpose limitation is the pinch point: personal data collected for one purpose cannot simply be reused to train a model. You need a basis for the training itself, and to consider whether the model memorises personal data. Accuracy applies to inferences too, not only stored fields — an inaccurate prediction about someone is inaccurate personal data.

    How does GDPR apply to AI systems specifically?

    The same principles apply, but AI stresses them harder. Lawful basis is more difficult where data is reused for training, purpose limitation conflicts with model reuse, accuracy applies to inferences and not just stored fields, and transparency is harder where the logic is opaque. Article 22 adds specific protection around solely automated decisions with legal or similarly significant effects.

    When do we need a DPIA for an AI system?

    Whenever processing is likely to result in a high risk to people's rights and freedoms, which covers most AI involving personal data at scale, profiling, or automated decisions with real consequences. In practice, assume one is needed and record the reasoning if you conclude otherwise. AI Sentri tracks DPIA status per system so gaps are visible rather than assumed closed.

    What is our lawful basis for training on customer data?

    That is a decision for your DPO or legal adviser, not a setting in a tool — but it must be recorded per system, and it is where AI projects most often come unstuck. AI Sentri requires a lawful basis per system and treats its absence as a hard gap, because a system processing personal data without one is not a scoring nuance.

    Does using a vendor's AI tool make them the processor?

    Usually, but not always, and the answer determines who carries which obligations. Where a vendor determines purposes and means of processing they may be a controller in their own right. AI Sentri records the vendor and the data involved per system so the question is at least asked for each one.

    More in the full FAQ, or ask us directly.

    Your Privacy Matters

    We use cookies to provide essential functionality, analyse usage, and improve your experience. Under GDPR, you have the right to choose which cookies you allow. Strictly necessary cookies cannot be disabled. Privacy Policy