In 2026, any business operating in the European Union and using artificial intelligence (AI) systems faces a dual mandatory framework: the GDPR (personal data protection) and the AI Act (EU Regulation 2024/1689), which organises AI by risk level. The stakes are not merely legal: compliance designed in from the outset is a competitive advantage.
This operational guide provides a clear roadmap to secure AI projects, anticipate CNIL inspections and limit financial and reputational risks while accelerating deployment.
1) Scope: when do GDPR and the AI Act apply?
- GDPR: applies to any processing of personal data (collection, training, inference, monitoring) related to AI, whether by you or a provider. Refer to CNIL recommendations on AI systems and data protection (CNIL; AI practical guides).
- AI Act: applies irrespective of personal data. It classifies AI uses by risk level (prohibited, high risk, limited risk, minimal) and imposes graduated obligations, including CE marking for high risk. Reference text: EUR-Lex — AI Act.
In practice, many cases combine both frameworks: a customer-scoring engine, HR assistant or fraud-detection tool involves personal data (GDPR) and, depending on use, the AI Act's “high-risk” regime.
2) Key GDPR obligations when AI processes personal data
2.1 Define the legal basis and purpose
- Choose and document one of the legal bases (consent, contract, legitimate interest, legal obligation, etc.).
- Specified, explicit and legitimate purposes; no incompatible reuse.
The CNIL reiterates these fundamentals and proposes practical methods for AI projects (CNIL — New AI & GDPR recommendations).
2.2 Minimisation and privacy by design/by default
- Collect only necessary data, set the highest privacy level “by default”, pseudonymise/aggregate where possible.
- Document technical choices (training a model on synthetic or anonymised datasets where performance permits).
See the CNIL's operational guidance (CNIL — Artificial intelligence).
2.3 Transparency and information for individuals
- Provide clear information notices: purposes, legal basis, data categories, retention period, individuals' rights, general logic of AI processing.
- Explain AI's role in decisions understandably.
2.4 Automated decisions and individuals' rights
- For a solely automated decision producing legal or similar effects, offer: specific information, the right to obtain human intervention, express a view and contest the decision (interaction emphasised by the CNIL: AI practical guides).
2.5 Security, retention and traceability
- Appropriate technical and organisational measures: access control, encryption, logging, vulnerability management, red teaming for critical models.
- Limited retention policy; compliant deletion and archiving.
2.6 DPIA, DPO and processing records
- DPIA mandatory for high risk (e.g. large-scale scoring, surveillance, substantial automated decisions); involve the DPO from design.
- Maintain the record of processing activities and update it with AI flows (CNIL and Service Public Pro reiterate these requirements: Service Public Pro).
2.7 Transfers outside the EU
- Regulate transfers through standard contractual clauses and assess protection levels in the recipient country. Manage processors with specific AI/GDPR clauses.
For an SME/mid-sized business approach, see Bpifrance summaries: Bigmedia Bpifrance and Diag Bpifrance.
3) AI Act: risk classification and obligations
Reference: EUR-Lex — AI Act (EU Regulation 2024/1689).
3.1 Prohibited practices (unacceptable risk)
- Certain uses are prohibited (e.g. manipulation exploiting vulnerabilities, forms of general-purpose “social scoring” by public authorities, real-time biometric recognition in public spaces except under strict exceptions). Check your use cases in advance.
3.2 High-risk AI systems
These fall within AI Act-listed categories (e.g. product safety, employment/HR, credit, access to education, essential services). Key obligations for providers and, in part, deployers:
- Risk management and data governance (quality, representativeness, bias, dataset traceability).
- Detailed technical documentation, records and event logs.
- Transparency and clear instructions for use.
- Effective human oversight; operator training.
- Robustness, accuracy and cybersecurity requirements.
- CE marking, compliance management system, post-market monitoring and serious-incident reporting.
3.3 Limited risk: transparency obligations
- Inform individuals when they interact with AI (chatbots).
- Clearly label generated/synthetic content (e.g. deepfakes).
3.4 General-purpose AI (GPAI) and foundation models
- Specific provider obligations: documentation, information on capabilities/limitations, governance practices and copyright compliance (INPI provides IP guidance: INPI).
4) GDPR–AI Act interaction: building coherent compliance
The two frameworks are complementary. Some guidance to avoid blind spots:
- Auditability: AI Act traceability requirements (logs, documentation) support GDPR obligations (evidence of legal basis, minimisation, DPIA).
- Explainability: GDPR's “understandable” information requirement aligns with AI Act transparency; implement model cards/use sheets.
- Bias and discrimination: the AI Act requires bias management; GDPR exposes you to unlawful-processing risks if bias leads to unjustified decisions. Apply CNIL recommendations (CNIL).
5) A 90-day compliance roadmap
Step 1: Map and classify (weeks 1–3)
- Inventory all AI systems (internal, SaaS, API) and their data flows.
- For each: is there personal data? What is the AI Act risk level?
- Identify the role: provider, integrator or deployer.
Step 2: Establish GDPR foundations (weeks 2–6)
- Define the legal basis, purposes and retention periods.
- Conduct or update the DPIA (with your DPO) and art. 30 record.
- Draft/update: information notices, rights-request procedure, security policy.
Step 3: AI Act alignment (weeks 4–9)
- If high risk: implement risk management, technical documentation, human oversight, post-market monitoring and prepare CE marking.
- If limited risk: organise user information and synthetic-content labelling.
- For GPAI: require provider documentation and IP compliance.
Step 4: Contracts and providers (ongoing)
- Add AI/GDPR clauses: data quality, bias, security, logs, CNIL cooperation, processing, exit assistance, transfers outside the EU.
- Check providers' AI Act warranties (declarations, notices, CE marking where applicable).
To equip your organisation effectively, Explore AI and law resources and Discover the Initial journey applied to audits and contract templates.
6) Inspections, compliance evidence and penalties
- CNIL: recommendations, inspections and administrative penalties for GDPR breaches and, in France, support for AI stakeholders (CNIL — AI recommendations; CNIL — AI).
- AI Act: high administrative penalties for non-compliance, heightened for prohibited practices (see the text on EUR-Lex).
- Civil liability: in France, general tort law may apply (art. 1242 Civil Code: Legifrance).
Good evidence practice: retain DPIAs, test reports, reference datasets, event logs, human-oversight reports and provider notices/certificates. Microbusinesses/SMEs have made substantial progress since GDPR adoption, but gaps remain; see France Num's assessment and action levers (France Num).
7) Quick pre-deployment checklist
- AI Act classification completed; if high risk, CE marking plan and human oversight defined.
- GDPR legal basis and information notices finalised; individuals' rights operational.
- DPIA updated and risk-reduction measures recorded.
- Training-data policy (quality, bias, provenance, IP) and log records in place.
- Provider contracts with AI/GDPR warranties signed; transfers outside the EU regulated.
Further reading
Read our related guides: European AI Act: complete guide for startups, The legal limits of AI in business and Contractual clause on AI use.
Quick FAQ
Does GDPR apply if my AI only infers from already pseudonymised data?
Yes, if re-identification is reasonably possible or inferences concern identifiable individuals. Pseudonymisation does not exclude GDPR (see CNIL — AI guides).
Must I always obtain consent?
No. Other legal bases exist (contract, legitimate interest, legal obligation…). The choice depends on the use case and must be justified and documented (Service Public Pro guides).
What makes a system “high risk” under the AI Act?
Inclusion in a category listed by the Regulation (e.g. employment/HR, credit, essential services). Refer to the consolidated text on EUR-Lex.
How should copyright in training data be handled?
Check licences, implement filters/copyright compliance and retain traceability. IP guidance: INPI.
To explore these issues further, read other AI and law analysis and Explore AI and law resources tailored to your sector.
Further reading
Related resources
Frequently asked questions
FAQ
How can I tell whether my AI system falls under the AI Act's high-risk regime?
Check whether it falls within the Regulation's listed categories (employment/HR, credit, essential services, product safety, etc.). Consult the AI Act on EUR-Lex and account for your role (provider or deployer).
Is a DPIA mandatory for every AI project?
No, only where there is high risk to rights and freedoms (e.g. substantial automated decisions, large-scale surveillance). The CNIL provides criteria and examples to decide.
Can I use general-purpose AI (GPAI) models without reviewing GDPR notices?
No. Even with GPAI, you must clearly explain the purpose, legal basis, individuals' rights and AI's role in your processing.
What evidence should be retained for a CNIL inspection?
DPIAs, processing records, security policies, event logs, provider documentation (notices, CE marking), bias tests, rights-request procedures and incident histories.
What are the risks of non-compliance?
High administrative penalties (GDPR and AI Act), orders and coercive fines, reputational risks and civil liability under the Civil Code.
References
Sources used
- Personal data protection: assessment of GDPR adoption…
- AI and GDPR: CNIL publishes new recommendations — CNIL
- AI practical guides — CNIL
- Bpifrance — AI and GDPR: ensuring data protection in business
- CNIL — Developing AI systems: recommendations for GDPR compliance
- AI and GDPR: issues and legal obligations for businesses
- CNIL — Artificial intelligence
Training · Audit · Support
Put what you read into practice
Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.