Governance & compliance

How does GDPR apply to AI?

Compliance is not optional and the fines are material. For AI, the hard parts are consent, the right to an explanation, and knowing exactly what data a model was exposed to.

In plain terms

GDPR is the European Union regulation governing how personal data is collected and used, and it applies to any organization handling the data of EU residents, wherever that organization is based.

Also called GDPR.

If you use personal data of people in Europe, GDPR applies even when the AI vendor sits somewhere else. You need a lawful reason to use the data, a way for people to access or delete it, and a contract with anyone who processes it for you. Automated decisions that significantly affect a person can require a human review.

This is not only a form for the legal team. A chatbot trained on EU customer email, or a scoring model that declines an application, is in scope. Map where personal data enters the AI system, which vendor receives it, and how you would delete it if someone asked. If you cannot do that map, you are not ready to launch that feature.

Think of it this way: GDPR follows the person, not the office. If a customer lives in the EU, the rules travel with their data, even if your company is based somewhere else.

A US SaaS company discovers its EU user base subjects it to GDPR. Their AI feature auto-processes profile data. Legal requires a data processing agreement with the AI provider, a documented lawful basis, and deletion procedures.

A US company launches a support bot for its EU customers and stores transcripts with a US vendor that trains on them by default. A deletion request arrives. They cannot remove one person's chats from the vendor's training. They switch the vendor setting, sign the right contract, and stop sending EU transcripts until the deletion path works.

Check GDPR applicability before any AI feature that processes personal data. It is not a post-launch consideration. Baking in compliance from the start is far cheaper than retrofitting it. There is no use case where GDPR compliance can be skipped if you process the data of EU residents. The size of the project is not a factor in whether the regulation applies.

RaftLabs writes the control into the system: which data can enter, who approves the result, and how you explain it later. The rule and the product stay the same story. The related work on our side is AI governance.

This sits with the other governance & compliance terms on the glossary. The rules that keep AI legal, and keep customer data out of the wrong tool. Worth reading next: Data Privacy / PII, Model Governance, and Shadow AI.

Common questions

Yes, if you offer goods or services to people in Europe or monitor their behavior. The vendor's location does not exempt you. Your customers' location pulls the law in. Confirm this with counsel for your specific product. Do not assume a US company is out of scope.
Decisions based only on automation that have a legal or similarly significant effect, such as a credit decline. Those need a way for the person to get human review. A spam filter does not. A hiring screen might. Classify the decision before you automate it, and keep the review real.

Work with us

Tell us what's broken.

Tell us what's not working in your business. We'll find the real problem and tell you exactly what it would take to fix it.

  • Scope and cost agreed before work starts. No surprises. No obligation.
  • Working prototype within 3 weeks of kickoff.
  • Pay by milestone. You see progress before each invoice.
  • 60-day post-launch warranty. Bug fixes, UI tweaks, and deployment support. No retainer.
  • All conversations are NDA-protected.