Term

GDPR and AI

When deploying AI, the usual GDPR requirements apply — in particular regarding legal basis, purpose limitation and data processing agreements.

As soon as personal data is processed, a legal basis and clear purpose limitation are required. With cloud-based AI services, the question of data processing agreements is added, including where data is processed and whether it is used for training.

In practice, many concerns can be defused through the choice of operating model: EU-hosted services or operation in your own data centre keep processing within the desired legal jurisdiction.

A robust implementation also means respecting existing access rights. An assistant must not become a detour through which staff can view content they are not normally authorised to see.

In depth in our knowledge hub

Hit by ransomware: what to do now, from assessing the damage to restarting the business

What to do after a ransomware attack, in four steps: establish the damage, check what can be restored, keep the business running, and plan the restart — including reporting duties and the ransom question.

Read the article →

Let's talk about your project.

Free initial consultation, 30–45 minutes, remote. An honest assessment — even if the answer is that you don't actually need it.