Skip to content
AI Literacy
Lektion 5 von 170/17 abgeschlossen
Datenschutz, Haftung & Governance

Data Protection & GDPR

DSGVO

🖱️ Interaktiv: Ziehen zum Drehen · Lektion 5

Learning objectives

After this lesson you will be able to:

  • Apply GDPR principles to AI applications
  • Recognize when a DPIA (data protection impact assessment) is required
  • Evaluate data processing agreements for AI tools
  • Name the relevant legal bases for AI data processing

GDPR principles for AI

The GDPR (General Data Protection Regulation) applies independently of the EU AI Act. AI systems must comply with both. The key principles:

1. Data minimization

Process only the data that is strictly necessary for the purpose. An AI tool doesn't need access to all available data — access should be limited to what is necessary.

2. Purpose limitation

Data may only be processed for the purpose for which it was collected. AI training data requires its own legal basis.

3. Transparency

Data subjects must be able to understand how their data is processed in AI systems.

4. Accuracy

AI decisions affecting people must be correct. Data subjects have the right to have incorrect data corrected.

💡 GDPR vs. EU AI Act

GDPR and EU AI Act complement each other. While the EU AI Act regulates the safety of AI systems, the GDPR protects the fundamental rights of data subjects. An AI system can comply with the EU AI Act but violate the GDPR — and vice versa.

Data protection impact assessment (DPIA)

A DPIA is required when AI systems are likely to pose a high risk to the rights and freedoms of natural persons. This is almost always the case for high-risk AI systems under the EU AI Act.

When is a DPIA required?

  • AI-based evaluation of people (creditworthiness, insurance)
  • Automated decisions with legal effect
  • Extensive profiling
  • Processing of special categories of data
  • Biometric surveillance
  • AI in healthcare

📝 Schnellprüfung

When is a data protection impact assessment (DPIA) required for an AI system?

Data processing agreement (DPA)

When you use a third-party AI tool (e.g. ChatGPT Enterprise, Copilot), you need a DPA with the provider. It must regulate:

  • Which data is processed
  • Where the data is stored (server location)
  • Whether data may be used to train the model
  • Which technical and organizational measures are in place
  • Deletion periods and data portability

Key questions for the DPA

  1. Is my data used for AI training? (Check the opt-out!)
  2. Where are the servers? (EU/US/other)
  3. Is there a data processing agreement (DPA)?
  4. Was the model trained on my data? (Retention policy)

🏢 Praxis-Szenario: Data protection with ChatGPT Enterprise

Your company wants to introduce ChatGPT Enterprise. The contract states that your data will not be used for model training. However, OpenAI stores your conversations for 30 days for security review. An employee accidentally enters patient data into ChatGPT.

Legal bases for AI data processing

Processing personal data in AI systems requires a legal basis:

Legal basisApplication in AI
Consent (Art. 6(1)(a))Voluntary, revocable at any time — rarely practical
Contract performance (Art. 6(1)(b))AI as a tool for fulfilling a contract
Legitimate interest (Art. 6(1)(f))Balancing of interests required, documented
Legal obligation (Art. 6(1)(c))When AI is mandated by law

💡 Important: no AI training data without a legal basis

Existing data may not automatically be used for AI training. Without an explicit legal basis (and informing those affected), this violates the GDPR. Check the terms of service of your AI tools — many reserve the right to use your data for training!

Rights of data subjects

Data subjects have special rights regarding AI decisions:

  • Right of access: which AI was used? Which data was used?
  • Right to rectification: incorrect data must be corrected
  • Right to erasure: data must be deleted (with restrictions)
  • Right regarding automated decisions: for high-risk decisions, data subjects have the right to human review

✅ Wichtige Erkenntnisse

Haken setzen, um deinen Lernfortschritt zu markieren:

→ Go deeper: Liability & compliance — fines and liability risks for GDPR violations · Transparency obligations — AI inventory and documentation

Weiterführende Inhalte

Datenschutz im Schnellstart

Relevante Rechtsgrundlagen: Art. 10 · DSGVO Art. 35

Im Modul "Datenschutz, Haftung & Governance" — weiter lernen