← All articles · Partners
PLENDE

AI in compliance: how to build a data protection program compliant with GDPR and the AI Act

30.06.2026 AIcomplianceGDPRAI Actdata protection
This content was prepared with the help of AI.

The growing use of AI in companies means that compliance stops being an abstract “security policy” and becomes a concrete set of decisions: which tools to allow, what data to entrust to them, and how to document compliance with the GDPR and the AI Act. For compliance teams this is a practical transformation project, not just a legal obligation.

1. From an AI tools catalogue to a risk map

The first practical step is to create a complete register of AI tools used in the organization - both officially deployed systems and “shadow AI” used informally by employees.

1. Collect information about all systems: CRMs with AI features, recruitment platforms, chatbots, content-generation tools, AI agents supporting back-office processes.

2. For each tool, determine the company’s role under the AI Act: provider, user (operator), importer, distributor, or manufacturer of a product containing an AI component.

3. Initially classify the risk level: high-risk systems (e.g. AI in recruitment, employee evaluation, customer scoring), systems subject to transparency obligations (chatbots, generative content), and low-risk tools.

Such a map is a starting point for further compliance work: it helps identify where GDPR risks (processing of personal data) and AI Act risks (system risk, transparency duties, human oversight) intersect.

2. Data layer: practical rules for entering information into AI

AI security in practice happens at the level of data entered by employees into models.

1. Define which categories of personal data may be entered into a given tool and which are prohibited (e.g. special categories of data, customers’ data outside the EEA, trade-secret information).

2. Pay attention to processing location: regulators increasingly require that EU customer data not leave the European Economic Area at the extraction and transformation stages, especially in tools that automate documents and use AI.

3. For automated decision-making (ADM) solutions with significant legal or business effects, ensure transparency, the ability to explain decisions, and data accuracy as a minimum compliance standard.

The compliance team should translate these rules into short, clear operational guidelines for teams: what can be copied into ChatGPT or AI agents, how to anonymize data, how to label AI-generated content.

3. Procedures and documentation: how to prove compliance

The AI Act and the GDPR require not only compliant use of AI but also proof that the organization takes appropriate measures.

1. Create a register of AI systems describing the use case, types of personal data processed, risk class, and responsible business owners.

2. Develop an AI risk assessment procedure: from impact analysis on individuals’ rights, through transparency tests, to human oversight requirements for high-risk decisions.

3. Review contracts with AI vendors for liability for outputs, rights to AI-generated content, data location, and compliance with the AI Act and the GDPR.

4. Ensure regular training that combines the AI Act, the GDPR, and practical data hygiene - from 2025 the AI Act explicitly requires adequate knowledge and competence of AI users.

5. Implement procedures for reporting and documenting AI-related incidents, especially in high-risk systems.

4. What the company gains: compliance as a competitive advantage

A consistent AI compliance program that combines the GDPR and the AI Act gives a company two key benefits: a significant reduction in the risk of fines (up to €35 million or 7% of global turnover for AI Act violations) and the ability to scale AI usage safely in business processes. Organizations that build an AI systems register, a data risk map, and documented human oversight procedures will be able to deploy new tools faster while maintaining an acceptable risk level - which directly translates into a competitive advantage.

FAQ

- 1. Does every company using AI fall under the AI Act? Yes - if you operate in the EU and use tools containing an AI component (e.g. CRM, chatbot, recruitment platform), the AI Act will apply, although the scope of obligations depends on the system’s risk class.

- 2. How do you distinguish a high-risk AI system from a “regular” tool? The key question is whether the AI system affects rights or people’s situations in areas such as employment, education, or access to financial services; such uses are typically classified as high-risk and require detailed compliance assessment and documentation.

- 3. Is having an AI usage policy enough to comply with the GDPR and the AI Act? No - you also need an AI systems register, risk assessment procedures, human oversight, vendor verification, and real employee training that ties legal requirements to practical data-handling rules.

- 4. How should organizations approach “shadow AI”? First inventory it, then assess legal and technical risks and decide which tools can be legitimized and covered by policies and which must be blocked due to non-compliance with the GDPR or the AI Act.