General Data Protection Regulation (Regulation (EU) 2016/679)
Last reviewed Sep 25, 2026.
In short
The GDPR is the EU's general privacy law and the one most often enforced against AI so far. Personal data needs a legal basis, transparency and purpose limits, whether it feeds model training, prompts or outputs. Article 22 gives people the right not to be subject to solely automated decisions with legal or similarly significant effects, and Article 35 requires a data protection impact assessment (DPIA) before high-risk processing such as profiling or large-scale monitoring.
Who it applies to
- Organisations that build or use AI systems in European Union.
- Any use case — it is not limited to specific applications.
- Size: everyone, including solo operators.
- Applies to anyone processing personal data of people in the EU, wherever the organisation is based. Any AI that trains on, takes in or produces data about identifiable people is in scope.
Key dates
- Apr 27, 2016✓Adopted by the European Parliament and Council
- May 25, 2018✓Applies across the EU and EEA
What you have to do
- Identify a legal basis (consent, contract, legitimate interests, etc.) for every use of personal data, including model training on scraped or customer data.
- Tell people, in a privacy notice, that their data is used for AI and what for; explain the logic of automated decisions that affect them.
- Run a DPIA (Art. 35) before profiling, automated decision-making or other high-risk processing, and keep it updated.
- Do not make solely automated decisions with legal or similarly significant effects (hiring, credit, insurance) without a valid exception and a human review route (Art. 22).
- Honour access, correction, erasure and objection requests, including for data inside training sets and outputs.
- Keep personal data accurate, minimise what you collect, set retention periods and secure it; report qualifying breaches within 72 hours.
- Appoint an EU representative if you are outside the EU but process EU residents' data, and a DPO where required.
Penalties
Up to EUR 20 million or 4% of global annual turnover, whichever is higher, for the most serious breaches (legal basis, data-subject rights, international transfers); up to EUR 10 million or 2% for others. Enforced by national data protection authorities, with the lead-authority 'one-stop-shop' for cross-border processing.
Real cases
- Fine2024 · EUItalian Garante v. OpenAI — EUR 15 million ChatGPT fine (later annulled on appeal)
OpenAI appealed, calling the fine disproportionate. The Rome Tribunal suspended the fine in March 2025 and then, in judgment no. 4153/2026 filed 18 March 2026, annulled it, reported as finding that once OpenAI had an Irish establishment the GDPR 'one-stop-shop' made Ireland's DPC the lead authority, so the Garante lacked competence. The substantive findings were not endorsed; the corrective orders and campaign had already been carried out.
- Fine2024 · EUClearview AI — EUR 90 million-plus in GDPR fines across Europe
Fines totalling more than EUR 95 million across four countries (plus a UK ICO fine on separate grounds). Clearview has no EU establishment and is reported as having neither paid nor changed its practices, which is why the Dutch DPA is pursuing directors and warning customers that using the service is itself unlawful.
Sources
Last reviewed Sep 25, 2026.