Data Protection & GDPR
🖱️ Interaktiv: Ziehen zum Drehen · Lektion 5
Learning objectives
After this lesson you will be able to:
- Apply GDPR principles to AI applications
- Recognize when a DPIA (data protection impact assessment) is required
- Evaluate data processing agreements for AI tools
- Name the relevant legal bases for AI data processing
GDPR principles for AI
The GDPR (General Data Protection Regulation) applies independently of the EU AI Act. AI systems must comply with both. The key principles:
1. Data minimization
Process only the data that is strictly necessary for the purpose. An AI tool doesn't need access to all available data — access should be limited to what is necessary.
2. Purpose limitation
Data may only be processed for the purpose for which it was collected. AI training data requires its own legal basis.
3. Transparency
Data subjects must be able to understand how their data is processed in AI systems.
4. Accuracy
AI decisions affecting people must be correct. Data subjects have the right to have incorrect data corrected.
💡 GDPR vs. EU AI Act
GDPR and EU AI Act complement each other. While the EU AI Act regulates the safety of AI systems, the GDPR protects the fundamental rights of data subjects. An AI system can comply with the EU AI Act but violate the GDPR — and vice versa.
Data protection impact assessment (DPIA)
A DPIA is required when AI systems are likely to pose a high risk to the rights and freedoms of natural persons. This is almost always the case for high-risk AI systems under the EU AI Act.
When is a DPIA required?
- AI-based evaluation of people (creditworthiness, insurance)
- Automated decisions with legal effect
- Extensive profiling
- Processing of special categories of data
- Biometric surveillance
- AI in healthcare
📝 Schnellprüfung
When is a data protection impact assessment (DPIA) required for an AI system?
Data processing agreement (DPA)
When you use a third-party AI tool (e.g. ChatGPT Enterprise, Copilot), you need a DPA with the provider. It must regulate:
- Which data is processed
- Where the data is stored (server location)
- Whether data may be used to train the model
- Which technical and organizational measures are in place
- Deletion periods and data portability
Key questions for the DPA
- Is my data used for AI training? (Check the opt-out!)
- Where are the servers? (EU/US/other)
- Is there a data processing agreement (DPA)?
- Was the model trained on my data? (Retention policy)
🏢 Praxis-Szenario: Data protection with ChatGPT Enterprise
Your company wants to introduce ChatGPT Enterprise. The contract states that your data will not be used for model training. However, OpenAI stores your conversations for 30 days for security review. An employee accidentally enters patient data into ChatGPT.
Legal bases for AI data processing
Processing personal data in AI systems requires a legal basis:
| Legal basis | Application in AI |
|---|---|
| Consent (Art. 6(1)(a)) | Voluntary, revocable at any time — rarely practical |
| Contract performance (Art. 6(1)(b)) | AI as a tool for fulfilling a contract |
| Legitimate interest (Art. 6(1)(f)) | Balancing of interests required, documented |
| Legal obligation (Art. 6(1)(c)) | When AI is mandated by law |
💡 Important: no AI training data without a legal basis
Existing data may not automatically be used for AI training. Without an explicit legal basis (and informing those affected), this violates the GDPR. Check the terms of service of your AI tools — many reserve the right to use your data for training!
Rights of data subjects
Data subjects have special rights regarding AI decisions:
- Right of access: which AI was used? Which data was used?
- Right to rectification: incorrect data must be corrected
- Right to erasure: data must be deleted (with restrictions)
- Right regarding automated decisions: for high-risk decisions, data subjects have the right to human review
✅ Wichtige Erkenntnisse
Haken setzen, um deinen Lernfortschritt zu markieren:
→ Go deeper: Liability & compliance — fines and liability risks for GDPR violations · Transparency obligations — AI inventory and documentation
Weiterführende Inhalte
Relevante Rechtsgrundlagen: Art. 10 · DSGVO Art. 35