10-Step Checklist

GDPR-compliant AI integration: the full process

1

Define purpose and legal basis

Contract, legitimate interest or consent — documented and reviewed before any data touches the model.

2

Classify data, plan minimisation

Which personal data is processed? Which can be excluded or pseudonymised?

3

Assess risks, check DPIA requirement

High-risk processing triggers a mandatory DPIA. We assess together and document the outcome.

4

Data processing agreements + third-country transfers

DPAs with all AI vendors. SCCs or adequacy decisions for non-EU processing.

5

Technical and organisational measures (TOMs)

Encryption, access control, audit logs, incident response plan.

6

Transparency and information obligations

Privacy notices, cookie banners and AI disclosure texts for users and employees.

7

Data subject rights

Access, rectification, erasure, portability and objection — all technically enabled and process-supported.

8

Logging, monitoring, human-in-the-loop

Every significant AI decision is logged. Sensitive actions require human confirmation.

9

Deletion and retention schedules

Automated deletion, documented retention periods, right to erasure enforced at model level.

10

Training, awareness, regular reviews

Staff trained on AI data handling. Annual review of models, data sources and compliance docs.

Legal Framework

GDPR + EU AI Act: what you need to know

Legal Basis

Every AI processing activity needs a legal basis under Art. 6 GDPR. Most business AI use cases rely on contract, legitimate interest or consent. We determine the right basis and document it.

EU AI Act Risk Classes

Minimal risk (content generators, spam filters) — light requirements. Limited risk (chatbots) — transparency obligations. High risk (HR, credit, safety) — full documentation and oversight required.

What We Produce

  • Record of processing activities (ROPA)
  • Data processing agreements (DPAs)
  • DPIA document
  • Technical and organisational measures
  • Privacy notices and AI disclosure texts
  • Acceptance protocols and audit checklists
Engagement Options

How we work together

Compliance Audit

2-day assessment of your existing or planned AI use cases against GDPR and AI Act requirements. Deliverable: written gap analysis and prioritised action list.

DPIA Guidance

Full DPIA process for a specific AI use case: risk assessment, mitigation measures, documentation. Ready for your DPO review.

Continuous Compliance

Ongoing compliance monitoring as new AI features are added: quarterly reviews, updated docs and incident support. Optional retainer model.

Stanislaw Lederhos
Why me?

Technical and legal in one engagement

I bridge the gap between your legal team (who knows GDPR but not AI architecture) and your IT team (who builds the AI but doesn't think about compliance). I translate between both worlds and deliver working solutions with documentation that auditors accept.

Based in Regensburg, Bavaria — working with SMEs, corporates and public-sector organisations across Germany.

Book a free compliance check
FAQ

Common questions about AI & GDPR

Do I need a DPIA before deploying AI?

A DPIA is required when AI processing is likely to result in a high risk to individuals — for example when processing special categories of data, systematic monitoring or automated decisions with significant effects. We assess this together and document the outcome.

Can we use cloud AI models (OpenAI, Google, etc.) under GDPR?

Yes, if the legal basis, Data Processing Agreement and transfer safeguards are in place. For sensitive data, on-premises models are the cleaner option. We help you choose the right architecture.

What does the EU AI Act mean for my business?

Most SME use cases fall into the minimal or limited risk category with light requirements. High-risk systems face stricter documentation and oversight. We assess your use case and prepare required documentation.

Who is responsible when AI makes a wrong decision?

Under GDPR, your company (the data controller) remains responsible for automated decisions. We implement human-in-the-loop checkpoints, audit logs and clear escalation paths so responsibility is always traceable.

Related Services

Build compliant AI systems end to end