Published: September 29, 2026
Data Protection & SecurityGDPR and AI automation: what to check before you start
What should your business check for GDPR compliance before introducing AI and automation? A practical checklist for SMEs and data controllers.
AI automation pays for itself quickly, but only if customer data stays protected along the way. This article walks through what to clarify from a GDPR perspective before you roll anything out.
Why are AI and data protection a sensitive combination?
AI tools typically handle personal data: names, email addresses, phone numbers, order histories, sometimes invoices or contracts. As soon as an external service (a language model or an automation platform, for example) processes that data, questions arise: who is the controller, who is the processor, where is the data stored, and what may it be used for?
The good news is that for most SMEs this is entirely manageable. A few deliberate decisions can bring AI automation in line with the GDPR.
1. Map which data is involved
Start with a simple list: which process would you automate, and what personal data flows through it? For a customer service chatbot that is contact details and the conversation itself; for invoice processing, supplier and customer data; for quote generation, the client's name and address.
Pay special attention to special category data (health data, religious or political beliefs, and so on). It can only be processed under strict conditions and is usually best kept out of automated workflows.
2. Clarify roles and sign a data processing agreement
If an external provider processes personal data on your behalf, they are a processor and you remain the controller. In that case the GDPR requires a data processing agreement (DPA). Most serious vendors offer a standard one, but read it and make sure the AI provider does not use your data to train its own models.
3. Check where data is stored
Transfers outside the EU are subject to specific rules. Ask the provider whether an EU data centre is available and what legal basis applies to any transfer to a third country. Where there is a choice, prefer EU storage.
4. Data minimisation: share only what is needed
The AI rarely needs the full customer record. Categorising an email does not require a billing address, and a report does not need individual names. Design the workflow so the model receives only the fields it needs, and filter out or pseudonymise the rest.
5. Inform the people concerned
Your privacy notice should state the purposes for which you process data and which providers you use. For chatbots, visitors should also be able to tell they are talking to a machine. Where a decision is made solely by automated means and significantly affects a person, further safeguards such as human review are required.
6. Keep a human in the loop for important decisions
The safest setup is one where the AI prepares, suggests and summarises, and a team member approves the final step, especially for contracts, quotes and complaint handling. This helps with GDPR and also reduces the risk of errors.
7. Logging and access control
Set permissions: who can see the data the automation processes? Keep a log of what happened and define a retention period. Anything no longer needed should be deleted. This also makes it easier to handle data subject requests such as access and erasure.
A quick checklist
- Is there a data processing agreement with every provider involved?
- Do you know where the data is stored?
- Is use of your data for model training ruled out?
- Have you updated your privacy notice?
- Does the AI only receive the data it needs?
- Is there human approval for important decisions?
This article is general information and not legal advice. For your specific case, consult a lawyer or data protection officer.
Frequently Asked Questions
Do I need a data protection impact assessment to introduce AI?
Not always, but large-scale or high-risk processing (special category data, automated profiling) may require one. It has to be assessed case by case.
Can I use ChatGPT or similar tools with customer data?
Only if the business version's processor terms are adequate and your data is not used for model training. Never paste customer data into a free consumer version.
Does AI Done help with the data protection side?
Yes. During the free audit we review which data is involved and design the automation so that data processing stays as narrow as possible. Legal review is still done by a lawyer.
Summary
AI and the GDPR are not mutually exclusive — if you clarify the data, the roles and the approval points up front, automation can run safely. Request a free AI Audit and we'll go through it together.