Skip to content
Free diagnostic

BlogFramework and control

AI and the GDPR: what to check before deploying an agent

Necessary data, legal basis, retention periods, people’s rights, processors: the GDPR checklist to go through before entrusting data to an AI agent.

By Stéphane Barrio Published on 3 min readFor SMEsMid-sized companies

As soon as an AI agent touches personal data — that of your customers, your employees, your suppliers —, the GDPR applies. The good news: it is not an obstacle, provided you deal with it at the right time. Here is the checklist.

The principle: data protection by design

The regulation requires data to be protected from the design of a processing operation (Article 25). It is also the most economical option: compliance thought through at scoping costs almost nothing; added at the end of a project, it is expensive and fragile.

The ten points to check

  1. Process only the data that is needed. An agent that chases invoices does not need a customer’s medical history — nor, often, their home address.
  2. A legal basis for each processing operation: contract, legal obligation, legitimate interest, consent.
  3. Defined retention periods, including for the records the agent keeps.
  4. People’s rights respected: access, rectification, erasure, objection.
  5. Providers covered by contract (Article 28), including as soon as a third-party AI model is involved: who processes what, where, for how long.
  6. No reuse of your data to train an AI model, in writing.
  7. Records kept, to know what was done, and by whom or by what.
  8. An impact assessment, when the processing presents a high risk.
  9. Human approval of irreversible actions, and of decisions that significantly affect a person.
  10. The ability to take everything back: your data belongs to you, and must be retrievable.

The recurring question: where does the data go?

The GDPR does not require your data to stay in France, or even in Europe: it allows transfers outside the Union, provided they are governed by safeguards laid down by the regulation. Staying in Europe, or in France, is therefore a choice — or a customer’s requirement. See Where does your data go when you use AI?

What a provider’s proposal should contain

A page that states, in black and white:

  • where each processing operation takes place;
  • who processes the data, providers included;
  • how long it is kept;
  • what never leaves.

You know before signing; you can check afterwards. If a provider cannot give you this page, that is a warning sign.

The limit to be aware of

An integrator handles technical compliance: the way data is processed, kept and protected. The legal assessment — the exact legal basis, whether an impact assessment is needed — is a matter for your data protection officer or your lawyer. And approving the results produced by the agent is your responsibility.

Be wary of any promise of "100%" compliance: compliance is built and checked, it is not bought in one go.

What we do

GDPR compliance is neither an option nor a line in a quote: it is part of every project that processes personal data. The measures always included: GDPR. And if your teams already use AI tools without a framework, the AI Usage Audit takes stock and identifies the gaps.

Sources

  • Regulation (EU) 2016/679 (GDPR), Articles 25 (data protection by design and by default) and 28 (processor).

Frequently asked questions

Does the GDPR prohibit the use of AI?

No. It governs the processing of personal data, whatever the tool. A well-designed AI agent complies with it like any other software: minimal data, legal basis, retention periods, people’s rights, security.

Is my data used to train the AI model?

It depends on the supplier and the contract. It is a point to require in writing: your data must not be reused to train a model. We write it into every one of our projects.

Do we need a data protection impact assessment (DPIA)?

When the processing presents a high risk for people — sensitive data, monitoring, large-scale automated decisions. The question is raised during scoping, with your data protection officer if you have one.

Share on LinkedIn All articles

Read next

In the same category

Framework and control 2 min read

Where does your data go when you use AI?

Europe, France or your own premises: where your data is processed when an AI agent works, what processing in France really costs, and what to require in writing.

SMEsMid-sized companies

Flash Diagnostic · free

Start with a one-hour interview, free of charge.

A questionnaire that takes under 10 minutes, a one-hour interview, then within 72 hours a written report: what you can stop doing by hand, the time saved and the order of magnitude of the budget. If an off-the-shelf tool is enough, we will tell you.