General Data Protection Regulation
The EU’s data protection law. It applies whenever AI processes personal data — in prompts, uploaded documents, training data or outputs.
What it means for AI
For most companies GDPR matters more than the AI Act: it decides whether you may put customer or employee data into an AI tool at all. In Slovenia it is supplemented by ZVOP-2 and supervised by the Information Commissioner.
What you must do
- A legal basis for each processing with AI (contract, legitimate interest, consent, legal obligation).
- A data processing agreement (DPA) with the AI provider; check where data is stored and whether it is used for training.
- A data protection impact assessment (DPIA) before high-risk processing — e.g. AI that evaluates employees or customers.
- Art. 22: no decision with legal or similarly significant effect based solely on automated processing, unless an exception applies — and then a right to human intervention.
- Transparency: tell people in your privacy notice that AI is used and how.
- Data minimisation: remove or pseudonymise personal data before using AI where possible.
- Transfers outside the EU (e.g. US providers): the EU–US Data Privacy Framework or standard contractual clauses.
Examples
Risky: no processing agreement and the data may be used for training. Use a business plan with a DPA or remove personal data first (e.g. with Clean before AI).
Art. 22 applies: the client has the right to human review and a meaningful explanation. The EU Court of Justice confirmed this for credit scoring (SCHUFA, C-634/21) and for explaining the logic (C-203/22).
Inform participants, check where recordings are stored and delete them when no longer needed.
Key dates
GDPR applies.
EDPB Opinion 28/2024 on AI models and personal data.
Information Commissioner of Slovenia (IP).
Up to €20 million or 4% of worldwide annual turnover.
General information, not legal advice — consult a lawyer for borderline cases. Regulations reviewed on 29 Sep 2026.