GDPR for AI systems — where the Act meets data protection
Personal data through a running AI system brings the GDPR into the same register: lawful basis, transparency, DPIA, Art. 22, processor terms, transfers — per system from five questions, plus an organisation-wide programme.
The GDPR — Regulation (EU) 2016/679 — is statutory and, for any AI system that processes personal data, inseparable from the EU AI Act. Veritome does not try to be your whole data-protection function; it models where the two regimes meet so that one record serves both, and gives the organisation-wide work a programme of its own.
Per system: five questions, seven duties
When you register a system you answer five data questions: does personal data flow through it; are you controller, processor or joint controller; does it involve special categories; does data leave the EU/EEA; and does it make solely automated decisions. The engine reads those answers and adds the GDPR rows that follow, beside the EU AI Act rows on the same system:
- Art. 6 lawful basis — for a controller or joint controller.
- Art. 9 special-category conditions — when the data includes them.
- Arts. 12–14 transparency and information to the data subject — for a controller or joint controller.
- Art. 22 automated individual decision-making — a controller or joint controller making solely automated decisions with legal or similarly significant effect.
- Art. 28 processor terms — whenever personal data is in play and you hold any data role; a processor owes this and the transfer rules, never a lawful basis, a notice or a DPIA of its own.
- Art. 35 data protection impact assessment — for a controller or joint controller whose system carries a DPIA trigger: solely automated decisions, special categories, AI used on workers, emotion recognition or biometric categorisation. Not a blanket: a controller with none of those triggers gets no DPIA row.
- Arts. 44–49 transfer safeguards — when data leaves the EU/EEA.
Those seven article groups are engine obligations, generated and scored like any other. The rest of the GDPR — the principles, the individual rights, records of processing, security, breach notification, the DPO — sits in the Requirements catalogue and is worked through the programme below.
The organisation-wide programme
The GDPR programme runs on Establish · Map · Protect · Operate — governance policy, DPO decision, data-role determination and the record of processing activities; lawful-basis inventory, retention and DPIA methodology; security measures, the breach procedure (the supervisory authority within 72 hours of awareness under Art. 33), the data-subject-rights procedure and processor and transfer records; then privacy notices, training and the periodic review. Outside the path sits a Conditional / specialist bucket — consent, the EU representative, international transfers, supervisory-authority cooperation, codes and certification — that is never gate-locked and never a gate. See Phases and gates.
Because the GDPR is binding law, the programme is generated only while every step's guidance carries a named reviewer's stamp. It comes with the Govern plan and above, and it is live now — it is not part of the cross-mapping that waits for the launch date.
DPIA or FRIA? Both, once
A high-risk system used on people usually needs an Art. 35 DPIA and an EU AI Act Art. 27 fundamental-rights impact assessment. They overlap heavily, and the Act says so itself: Art. 27(4) lets the FRIA draw on a DPIA already carried out, and Art. 26(9) says a deployer uses the provider's instructions for use when doing that DPIA. Veritome shows both routes on the obligation and maps the FRIA's answers onto the DPIA's four pillars — see DPIA overlap. Neither route counts as coverage or changes a status; one assessment does not discharge the other.
Incidents run on two clocks
A data breach involving an AI system can be both a GDPR breach and an EU AI Act serious incident. The incident register lets you say which law's clock an incident runs on — GDPR, EU AI Act, or both — so the 72-hour breach notification and the Art. 73 reporting deadlines are tracked side by side.
In Veritome
GDPR rows appear in the Obligations register in the GDPR hue. The programme's records — the RoPA, the DPIA methodology, the breach procedure, the privacy notices — are rows in Documents and Policies, each opening in the step drawer.