VeritomeHelp Centre
/
Browse documentation
Frameworks explained

GDPR for AI systems — where the Act meets data protection

Personal data through a running AI system brings the GDPR into the same register: lawful basis, transparency, DPIA, Art. 22, processor terms, transfers — per system from five questions, plus an organisation-wide programme.

Updated Veritome documentation

The GDPR — Regulation (EU) 2016/679 — is statutory and, for any AI system that processes personal data, inseparable from the EU AI Act. Veritome does not try to be your whole data-protection function; it models where the two regimes meet so that one record serves both, and gives the organisation-wide work a programme of its own.

Per system: five questions, seven duties

When you register a system you answer five data questions: does personal data flow through it; are you controller, processor or joint controller; does it involve special categories; does data leave the EU/EEA; and does it make solely automated decisions. The engine reads those answers and adds the GDPR rows that follow, beside the EU AI Act rows on the same system:

  • Art. 6 lawful basis — for a controller or joint controller.
  • Art. 9 special-category conditions — when the data includes them.
  • Arts. 12–14 transparency and information to the data subject — for a controller or joint controller.
  • Art. 22 automated individual decision-making — a controller or joint controller making solely automated decisions with legal or similarly significant effect.
  • Art. 28 processor terms — whenever personal data is in play and you hold any data role; a processor owes this and the transfer rules, never a lawful basis, a notice or a DPIA of its own.
  • Art. 35 data protection impact assessment — for a controller or joint controller whose system carries a DPIA trigger: solely automated decisions, special categories, AI used on workers, emotion recognition or biometric categorisation. Not a blanket: a controller with none of those triggers gets no DPIA row.
  • Arts. 44–49 transfer safeguards — when data leaves the EU/EEA.

Those seven article groups are engine obligations, generated and scored like any other. The rest of the GDPR — the principles, the individual rights, records of processing, security, breach notification, the DPO — sits in the Requirements catalogue and is worked through the programme below.

The organisation-wide programme

The GDPR programme runs on Establish · Map · Protect · Operate — governance policy, DPO decision, data-role determination and the record of processing activities; lawful-basis inventory, retention and DPIA methodology; security measures, the breach procedure (the supervisory authority within 72 hours of awareness under Art. 33), the data-subject-rights procedure and processor and transfer records; then privacy notices, training and the periodic review. Outside the path sits a Conditional / specialist bucket — consent, the EU representative, international transfers, supervisory-authority cooperation, codes and certification — that is never gate-locked and never a gate. See Phases and gates.

Because the GDPR is binding law, the programme is generated only while every step's guidance carries a named reviewer's stamp. It comes with the Govern plan and above, and it is live now — it is not part of the cross-mapping that waits for the launch date.

DPIA or FRIA? Both, once

A high-risk system used on people usually needs an Art. 35 DPIA and an EU AI Act Art. 27 fundamental-rights impact assessment. They overlap heavily, and the Act says so itself: Art. 27(4) lets the FRIA draw on a DPIA already carried out, and Art. 26(9) says a deployer uses the provider's instructions for use when doing that DPIA. Veritome shows both routes on the obligation and maps the FRIA's answers onto the DPIA's four pillars — see DPIA overlap. Neither route counts as coverage or changes a status; one assessment does not discharge the other.

Incidents run on two clocks

A data breach involving an AI system can be both a GDPR breach and an EU AI Act serious incident. The incident register lets you say which law's clock an incident runs on — GDPR, EU AI Act, or both — so the 72-hour breach notification and the Art. 73 reporting deadlines are tracked side by side.

In Veritome

GDPR rows appear in the Obligations register in the GDPR hue. The programme's records — the RoPA, the DPIA methodology, the breach procedure, the privacy notices — are rows in Documents and Policies, each opening in the step drawer.