GDPR Meets AI – Five Questions Every Business Should Be Asking

GDPR Meets AI – Five Questions Every Business Should Be Asking

From drafting emails and analysing data to recruitment and customer service, Artificial Intelligence (‘AI’) tools are frequently being used by businesses of all sizes. While businesses may focus on the opportunities AI presents, they should also remember that the General Data Protection Regulation (‘GDPR’) continues to apply whenever personal data is processed.

While the EU AI Act has increased scrutiny of how businesses develop, procure and deploy AI systems, against that backdrop, businesses need to ask themselves the following five questions.

1. Do we know what personal data our AI tools are using?

Many AI tools rely on large volumes of data to function effectively. In some cases, this may include customer information, employee data, communications or other personal information. However, before deploying any AI tool, businesses should understand:

  • What personal data is being used;
  • Where that data comes from;
  • Why it is being processed; and
  • Whether the processing is necessary for the intended purpose.

A common mistake is introducing an AI tool into a business without first understanding the data flows involved. Businesses cannot manage privacy risks if they do not know what information is entering the system.

2. Do we have a lawful basis for using the AI tool?

The fact that a business wishes to use AI does not, in itself, provide a lawful basis for processing personal data. As with any other processing activity, businesses must identify an appropriate GDPR legal basis. Depending on the facts, this may include:

  • Performance of a contract;
  • Compliance with a legal obligation;
  • Legitimate interests; or
  • Consent.

Particular care should be taken when special categories of personal data are involved (including health data, biometric data, religious beliefs, genetic data or information revealing racial or ethnic origin). Additional conditions will be required before such data can be lawfully processed.

3. Are we being transparent about our use of AI?

Transparency remains one of the core principles of the GDPR. Data subjects should be informed when their personal data is being processed and, where relevant, how AI is being used as part of that process. This may require updates to:

  • Privacy notices;
  • Employee privacy notices;
  • Recruitment materials;
  • Customer-facing terms and conditions; and
  • Internal policies.

Businesses should not assume that existing notices, materials and terms adequately address AI-related processing because it is likely those documents were drafted before the recent surge in AI adoption. So, they may need to be updated to reflect current practices.

4. Have we assessed the risks?

AI can create significant privacy risks, particularly where it is used to profile individuals, monitor behaviour, evaluate performance or support decision-making. Businesses should assess potential risks before implementing AI tools including:

  • Could the AI produce inaccurate outcomes?
  • Could it introduce bias or discrimination?
  • Could it affect individuals’ rights or opportunities?
  • Is there a risk of unauthorised disclosure of personal data?

In some cases, a Data Protection Impact Assessment (‘DPIA’) may need to be carried out before an AI tool is deployed. Even if a DPIA is not mandatory, carrying out a formal risk assessment can help identify and mitigate issues before they become costly problems.

5. Are employees using AI safely?

One of the most significant AI risks facing businesses is often not the technology itself, but how employees use it. It is becoming increasingly common for staff to upload information to publicly available AI tools to draft documents, summarise information or generate reports. However, doing so without appropriate safeguards may result in confidential, commercially sensitive, legally privileged, or even personal data being disclosed to third-party platforms.

Businesses should:

  • Implement an AI usage policy;
  • Provide staff training;
  • Restrict the types of information that can be uploaded to AI tools;
  • Use enterprise versions of AI platforms where appropriate; and
  • Establish governance procedures for approving new AI solutions.

A well-informed workforce remains one of the most effective safeguards against privacy and cybersecurity breaches.

Looking Ahead

Data protection obligations are not new. However, by understanding how personal data is used, ensuring transparency, assessing risk and implementing appropriate governance measures, businesses can adopt AI with greater confidence and compliance.

 

For further information and support, please contact Maureen Daly at mdaly@reddycharlton.ie or your usual contact in Reddy Charlton LLP

Disclaimer: This article is for general information purposes only and does not constitute legal advice. Specific legal advice should be sought before taking or refraining from any action based on its contents.