In practice the biggest problem does not start with the AI model but with the data: first names, email addresses, incident histories, contracts, conversation transcripts and other materials that allow identification of a person. According to UODO, it is worth asking an initial set of questions before deploying an AI tool, but these do not replace a risk assessment, DPIA or an analysis of impact on fundamental rights.
According to UODO, using AI alone does not determine a legal breach, but it requires verifying whether the system actually processes personal data, who is the controller, what the purpose of processing is and whether the tool provider exceeds the agreed scope.
According to UODO and practical implementation guides, the starting point is simple: inventory the data entering the system, indicate the legal basis for processing and assess whether a DPIA is necessary. If the system uses employee, customer or job candidate data, the risk increases because it is easy to breach the data minimization principle and put information into the tool that is unnecessary for the business purpose.
UODO articles also emphasize that control questions help detect gaps but do not exempt from documenting decisions and demonstrating GDPR compliance. Practitioners' materials recommend establishing in advance a procedure for exercising the rights of data subjects: access, deletion, objection and information about processing.
Compliance with the AI Act does not replace GDPR, and GDPR does not replace the AI Act. This is particularly important when an AI tool is used for ticket classification, document analysis, HR support or customer service automation, because then data protection rules and obligations specific to the AI system must be monitored in parallel.
In practice this means three layers of control: first, limit input data to what is actually necessary; second, check the contract with the provider and rules for subprocessing; third, update privacy notices and internal procedures to cover AI use. According to UODO and industry sources, entering data into public tools without the organization's consent and without checking where data go and how long they are stored is particularly risky.
Lub System helps B2B companies implement AI, automation and IT solutions end-to-end - from strategy to deployment. See our services or get in touch to discuss your case.
Source: https://uodo.gov.pl/pl/138/4533