---
title: "GDPR and AI: privacy-compliant AI in companies"
description: "57 percent of companies see data protection as an AI brake. Learn how GDPR-compliant AI deployment succeeds in 2026—with a practical checklist and concrete action steps."
canonical: "https://simo-online.com/en/blog/dsgvo-ki-datenschutz-unternehmen-2026"
---

# GDPR and AI: privacy-compliant AI in companies

57 percent of companies see data protection as an AI brake. Learn how GDPR-compliant AI deployment succeeds in 2026—with a practical checklist and concrete action steps.

- Author: SIMO GmbH
- Published: 2026-03-08
- Updated: 2026-10-07
- Topic: [Compliance & Regulation](https://simo-online.com/en/blog/topic/compliance-regulation)

57 percent of German companies say, according to the latest Bitkom study, that data protection restricts the application of AI in the EU. At the same time, AI adoption has nearly doubled within a year: 36 percent of companies use artificial intelligence—almost twice as many as in 2024. The tension between innovation pressure and data protection obligations has never been greater than now. Because 2026 is the year in which three regulatory frameworks are enforced simultaneously at full strength: the GDPR, the EU AI Act, and the NIS2 Directive. Those deploying AI without a data protection strategy risk not only fines—but the trust of customers, partners, and employees.

## Why GDPR-compliant AI is now business-critical

The year 2026 marks a regulatory turning point. The German Data Protection Conference (DSK) has significantly tightened enforcement against AI projects under its chairman Prof. Dr. Tobias Keber. The message to the business community is unmistakable: 2026 will be the year of documentation and accountability.

## Three regulations hit simultaneously

The GDPR remains the foundation. But supervisory authorities have changed the assessment standard. Data Protection Impact Assessments (DPIAs) are no longer viewed as one-time documents but as ongoing instruments for evaluating and managing risks. The DSK explicitly emphasizes that most corporate AI projects now fall under the mandatory criteria for a DPIA pursuant to Article 35 GDPR. Those operating AI systems that process personal data must be able to demonstrate a fully documented impact assessment—otherwise fines and, in extreme cases, operational bans are at stake.

For high-risk AI systems under Annex III of the EU AI Act, for example in recruiting, credit scoring, education, and critical infrastructure, the obligations apply from December 2, 2027, following the amendment by Regulation (EU) 2026/1744; for systems under Annex I, they apply from August 2, 2028 (as of October 2026 · not legal advice). By then, companies must complete conformity assessments, finalize technical documentation, and register their systems in the EU database. The penalties: up to €15 million or 3 percent of global annual revenue for violations in the high-risk area, and up to €35 million or 7 percent for prohibited AI practices. The AI literacy rule under Article 4 has applied since February 2025; since July 2026, it requires measures that support staff AI literacy.

The NIS2 Directive was transposed into German law in December 2025. The registration deadline with the BSI expired on March 6, 2026—and the result is alarming: only 4,856 entities have registered, although approximately 30,000 companies are affected. Those who missed the deadline risk fines of up to €10 million or 2 percent of global annual revenue. Particularly critical: the personal liability of management.

## The tension: innovation versus data protection

The Bitkom Study 2026 paints a differentiated picture. 81 percent of surveyed companies say the GDPR makes business processes more complicated. 54 percent see data protection as a direct obstacle to AI deployment in their own company. At the same time, 58 percent acknowledge that data protection creates legal certainty for AI. The problem is therefore not data protection itself—but the lack of clarity on how it is compatible with AI systems in practice.

The Mittelstand (privately held midsize companies) particularly suffers from redundant reporting obligations under GDPR, AI Act, and Data Act. Bitkom president Dr. Ralf Wintergerst puts it bluntly: data protection has become the number one brake on digitalization. The solution lies in a structured approach that combines compliance and innovation.

## The legal foundations: what you specifically need to observe

## Legal bases for data processing by AI

Every processing of personal data by an AI system requires a legal basis under Article 6 GDPR. The three most relevant options for companies are:

Consent (Art. 6(1)(a) GDPR): Fundamentally possible, but often difficult in practice. Consent must be voluntary, informed, and specific. The EDPB clarified in its Opinion 28/2024: if personal data was unlawfully processed during the development of an AI model, supervisory authorities can impose fines or order the deletion of the data.

Legitimate interest (Art. 6(1)(f) GDPR): The EDPB confirmed in December 2024 that legitimate interest can fundamentally serve as a legal basis for the development and deployment of AI models. However, a three-step test is required: identification of a legitimate interest, demonstration of the necessity of the processing, and a balancing test ensuring that the controller’s interests do not override the rights of the data subjects.

Contract performance (Art. 6(1)(b) GDPR): Applicable when AI processing is necessary for the performance of a contract with the data subject—for example, with AI-powered customer service for existing customers.

## The data protection impact assessment: mandatory for almost all AI projects

The DSK has updated its so-called must-list. It names processing operations for which a DPIA is mandatory. According to current regulatory guidance, most AI projects fall under these mandatory criteria, particularly when they:

- process personal data on a large scale
- perform automated decisions or profiling
- deploy new technologies
- involve sensitive data under Article 9 GDPR

With the high-risk obligations, deployers of high-risk AI systems face an additional duty from December 2, 2027: the fundamental rights impact assessment under Article 27 of the EU AI Act. The DPIA and the fundamental rights impact assessment do not replace each other; they complement each other.

## The data processing agreement: no AI deployment without a DPA

As soon as personal data is transferred to an AI provider, a data processing agreement (DPA) pursuant to Article 28 GDPR is mandatory. The free version of ChatGPT, DeepSeek, or comparable tools is practically not GDPR-compliant for companies processing personal data. Only the business or enterprise plans from OpenAI, Anthropic, and Google offer DPAs.

The data location is also decisive. Most leading AI providers are based in the United States. Data transfers are possible via the EU-US Data Privacy Framework, but the CLOUD Act obliges US companies to disclose data to American authorities—regardless of server location. For sensitive company data, a European or German hosting solution is therefore the safest option.

## Practical guide: GDPR-compliant AI in seven steps

## Step 1: create an AI inventory

Record all AI systems used in your company—whether official or as shadow AI. Document for each system: provider, data location, type of data processed, purpose, user group, and risk classification. This inventory simultaneously fulfills the requirements of the EU AI Act and forms the basis for your DPIA.

## Step 2: review and document legal bases

For each AI system in the inventory: which legal basis under Article 6 GDPR applies? Has a DPA been concluded with the provider? Does consent or a legitimate interest exist? Document the review—even if the result is that no valid legal basis exists. Then you know where action is needed.

## Step 3: conduct a data protection impact assessment

Conduct a DPIA for every AI system that processes personal data. Describe the processing operations, realistically assess the risks, define protective measures, and assign responsibilities. Treat the DPIA as a living document: update it with every technical or organizational change.

## Step 4: implement technical and organizational measures

Data protection by design is not optional but mandatory under Article 25 GDPR. Specifically, this means for AI systems:

- Access controls: who may enter which data into which AI system?
- Data minimization: only process data necessary for the purpose
- Pseudonymization: anonymize or pseudonymize personal data before inputting it into AI systems
- Logging: document all AI interactions traceably
- Deletion concept: clear rules for when and how data is removed from AI systems

## Step 5: create and train on an AI usage policy

Create a clear, understandable AI usage policy of no more than five pages, with concrete examples, that defines which data may go into which tools, which use cases are permitted, and what is prohibited. Train all employees and document the training; this also covers the AI literacy measures required by Article 4 of the EU AI Act.

## Step 6: provide an approved AI platform

If you do not offer your employees an official, high-performance AI solution, they will find their own. The result is shadow AI—uncontrolled and not GDPR-compliant. Provide an approved platform that is hosted on German or European servers, has a DPA in place, and is at least as user-friendly as the freely available alternatives.

## Step 7: monitoring and continuous improvement

Establish AI usage monitoring with clear KPIs: adoption rate of the approved platform, shadow AI ratio, number of AI-related security incidents. Conduct quarterly internal audits. Update your AI inventory and DPIAs with every change.

## Checklist: GDPR-compliant AI usage in the company

- Checkpoint: AI inventory of all deployed systems created | Status: Open / Done | Responsible: IT / Data Protection Officer
- Checkpoint: Legal basis documented for each AI system | Status: Open / Done | Responsible: Data Protection Officer
- Checkpoint: DPA concluded with all AI providers | Status: Open / Done | Responsible: Data Protection Officer / Procurement
- Checkpoint: DPIA conducted for all relevant AI systems | Status: Open / Done | Responsible: Data Protection Officer
- Checkpoint: Technical protective measures implemented (access, pseudonymization, logging) | Status: Open / Done | Responsible: IT
- Checkpoint: AI usage policy created and communicated | Status: Open / Done | Responsible: Management / IT
- Checkpoint: Employee training conducted and documented (Art. 4 EU AI Act) | Status: Open / Done | Responsible: HR / IT
- Checkpoint: Approved AI platform provided | Status: Open / Done | Responsible: IT / Management
- Checkpoint: Monitoring and reporting established | Status: Open / Done | Responsible: IT
- Checkpoint: Quarterly audits scheduled | Status: Open / Done | Responsible: Data Protection Officer
- Checkpoint: NIS2 registration with BSI completed | Status: Open / Done | Responsible: IT / Management
- Checkpoint: Risk classification per EU AI Act documented | Status: Open / Done | Responsible: Data Protection Officer / IT

## Practical example: staffing agency with 85 employees

A midsize staffing agency in North Rhine-Westphalia with annual revenue of €14 million. The recruiting team has been using three different AI tools since fall 2025: a resume screening tool, an AI assistant for creating job postings, and an analysis tool for candidate profiles. None of these tools were reviewed from a data protection perspective. There is neither a DPIA nor a DPA with the providers. Candidate data—name, address, qualifications, salary expectations—flows unlawfully to external servers.

The risk exposure in numbers:

- GDPR fine (personal candidate data processed without legal basis): up to €560,000 (4 percent of €14 million revenue)
- EU AI Act penalty (high-risk AI in HR without a conformity assessment from December 2, 2027): up to €420,000 (3 percent of revenue)
- Damages claims from rejected candidates under Article 82 GDPR: typically €1,000 to €5,000 per affected person—with 2,000 candidates per year, a risk in the millions
- Reputational damage: loss of client contracts if it becomes known that candidate data flowed uncontrolled to external AI providers
- Forensics and legal counsel: typically €100,000 to €250,000

The total exposure conservatively exceeds €1.5 million, more than 10 percent of annual revenue. In addition, AI in human resources falls under Annex III of the EU AI Act, and the high-risk obligations apply to it from December 2, 2027. The company would then need not only GDPR compliance but also a risk management system, complete technical documentation, transparency toward candidates, and human oversight.

The solution: within six weeks, the company introduced a GDPR-compliant AI platform, concluded DPAs, created a DPIA, and trained all employees. Cost: approximately €18,000. Risk reduction: over €1.5 million.

## Frequently asked questions

## Do I need a data protection impact assessment for every AI tool?

Not for every one, but for most. The DSK has clarified that AI systems processing personal data generally fall under the mandatory criteria for a DPIA. This applies especially to automated decisions, profiling, the processing of sensitive data, and the large-scale deployment of new technologies. If you are unsure: conduct a threshold analysis. In case of doubt, it is safer and more cost-effective to create a DPIA than to risk a fine after the fact.

## May my employees use ChatGPT or other AI tools?

In principle yes—but only under certain conditions. First: do not enter personal data into free AI tools. Second: only use business or enterprise versions for which a DPA exists. Third: a clear AI usage policy must exist that shows employees what is permitted and what is prohibited. Fourth: usage must be recorded in the AI inventory and considered in the DPIA. Without these safeguards, use is not GDPR-compliant.

## What happens if an AI provider uses my company’s data for its training?

This is a real risk with free AI services. Many providers reserve the right to use entered data for training their models. Your company data—including personal data and trade secrets—could flow into a publicly accessible model. Review the terms of use carefully and prefer providers that guarantee opt-out from training or offer hosting on dedicated instances.

## How does the fundamental rights impact assessment differ from the established DPIA process?

The fundamental rights impact assessment (FRIA) under Article 27 of the EU AI Act complements the DPIA but does not replace it. The DPIA protects personal data; the FRIA assesses an AI system’s impact on further fundamental rights, such as non-discrimination, freedom of expression, or access to public services. From December 2, 2027, deployers of high-risk AI systems under Annex III must carry out both assessments. Many aspects overlap, so both processes can run in parallel.

## My company has fewer than 50 employees. do the same obligations apply?

Yes, the GDPR applies from the first employee and the first piece of personal data. The EU AI Act does provide reduced fine brackets for SMEs, but the fundamental obligations—AI inventory, AI competence, transparency, DPIA—apply to everyone. The conformity assessment for high-risk AI systems has no lower limit based on company size. Smaller companies in particular have fewer reserves to financially survive a data protection incident. A pragmatic, lean approach is therefore all the more important.

## References

- Bitkom e.V. (February 2026): Datenschutz in der deutschen Wirtschaft [in German]. Study report on how 603 companies assess the GDPR. [https://www.bitkom.org/Bitkom/Publikationen/Datenschutz-in-der-deutschen-Wirtschaft](https://www.bitkom.org/Bitkom/Publikationen/Datenschutz-in-der-deutschen-Wirtschaft)
- Bitkom e.V. (February 2026): Künstliche Intelligenz in Deutschland [in German]. Study on AI use, barriers, and investment. [https://www.bitkom.org/Bitkom/Publikationen/Kuenstliche-Intelligenz-in-Deutschland](https://www.bitkom.org/Bitkom/Publikationen/Kuenstliche-Intelligenz-in-Deutschland)
- Datenschutzkonferenz, Germany’s conference of data protection authorities (December 12, 2025): Entschließung zur Regulierung von Künstlicher Intelligenz [in German]. Calls for AI-specific amendments to the GDPR. [https://www.datenschutzkonferenz-online.de/entschliessungen.html](https://www.datenschutzkonferenz-online.de/entschliessungen.html)
- European Data Protection Board (December 18, 2024): Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models. [https://www.edpb.europa.eu/our-work-tools/our-documents/opinion-board-art-64/opinion-282024-certain-data-protection-aspects_en](https://www.edpb.europa.eu/our-work-tools/our-documents/opinion-board-art-64/opinion-282024-certain-data-protection-aspects_en)
- EDPB (February 11, 2026): Work Programme 2026–2027. Planned guidelines on generative AI, data scraping, and the interplay between the GDPR and the EU AI Act. [https://www.edpb.europa.eu/system/files/2026-02/edpb_work-programme_2026-2027_en.pdf](https://www.edpb.europa.eu/system/files/2026-02/edpb_work-programme_2026-2027_en.pdf)
- Ad-hoc-news.de (March 6, 2026): Datenschützer verschärfen 2026 den Druck auf KI-Projekte [in German]. DSK strategy and DPIA obligations. [https://www.ad-hoc-news.de/boerse/news/ueberblick/datenschuetzer-verschaerfen-2026-den-druck-auf-ki-projekte/68454427](https://www.ad-hoc-news.de/boerse/news/ueberblick/datenschuetzer-verschaerfen-2026-den-druck-auf-ki-projekte/68454427)
- ADVISORI (March 2026): EU AI Act Hochrisiko—Pflichten bis August 2026 für Unternehmen [in German]. [https://www.advisori.de/blog/eu-ai-act-hochrisiko-pflichten-august-2026](https://www.advisori.de/blog/eu-ai-act-hochrisiko-pflichten-august-2026)

Rendered version: https://simo-online.com/en/blog/dsgvo-ki-datenschutz-unternehmen-2026
