The GDPR has no chapter on artificial intelligence, and it does not need one. When an employee pastes customer data into a chatbot your company never approved, several obligations can fail at once: the provider holds personal data with no Article 28 contract, the processing is missing from your Article 30 record, the data may have left the EEA without a Chapter V transfer mechanism, and the Dutch data protection authority treats the paste itself as a data breach, which Article 33 may require you to report. You may not know the tool exists.
Agents add Article 22. Once software acts on a person, scoring a lead or closing an account, the question becomes whether the decision rested solely on automated processing.
Regulators and law firms explain these articles. This guide covers what you must be able to show a supervisory authority: the records, contracts and logs behind each article. EUR-Lex lists no act amending the GDPR, and the Digital Omnibus on AI does not amend it.
Last verified: 8 October 2026.
What will a supervisory authority ask you to show?
The GDPR runs on proof. Under Article 5(2) the controller must "be able to demonstrate compliance with" the principles in Article 5(1). Article 30(4) makes the record of processing available to the authority "on request", and Article 33(5) requires breach documentation that will "enable the supervisory authority to verify compliance". An inquiry into AI use starts with a document request.
| AI activity | GDPR article | What you must be able to show |
|---|---|---|
| An employee pastes customer data into an unapproved chatbot | 4(12), 33, 34 | A breach record: facts, effects, remedial action, the reasoning for notifying or not, and when you became aware |
| Staff use any AI tool with personal data | 24(2), 29, 32(4) | Staff instructions, proof of receipt, and the controls that enforce them |
| An AI provider processes personal data for you | 28 | A written Article 28(3) contract, authorized subprocessors, your due diligence |
| Any AI tool in use, approved or not | 30 | A record entry: purposes, categories of data and data subjects, recipients, transfers, retention, security measures |
| Prompts processed outside the EEA | 44 to 46, 30(1)(e) | The transfer mechanism, listed in the record |
| An assistant rolled out at scale | 35 | A DPIA done before processing, reviewed when the risk changes |
| Deploying a model that retains personal data from training | 5(1)(a), 6, with EDPB Opinion 28/2024 | Your assessment that it was not developed by unlawfully processing personal data |
| An agent scores, ranks or decides about people | 22, 15(1)(h), 35(3)(a) | The Article 22(2) exception relied on, real human review, and logs that explain the procedure applied |
| An agent with standing access to mail, files or a CRM | 25, 32 | Scoped permissions and an action log for each task |
Article 83(4) sets fines of up to €10 million or, for an undertaking, up to 2% of total worldwide annual turnover of the preceding financial year, whichever is higher, for breaches of Articles 25 to 39, which include 28, 30, 33 and 35. Article 83(5) doubles both figures for Articles 5, 6, 12 to 22 and 44 to 49.
Is pasting personal data into a chatbot a data breach?
It can be. On 6 August 2024 the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, or AP) said it had received breach notifications caused by employees sharing personal data with AI chatbots, among them patients' medical data at a GP practice and a file containing customer addresses at a telecom company. For staff acting on their own initiative against the employer's agreements, the AP is blunt: "If personal data have been entered in the process, this means there is a data breach." Notifying the AP and the people affected "is mandatory in many cases".
The AP also drew a line: where chatbot use is part of an organization's policy, "it is not a data breach, but often not permitted by law." Approval moves the question from Article 33 to Articles 5, 6 and 28.
Not every paste must be reported. Article 33(1) requires notification "without undue delay and, where feasible, not later than 72 hours after having become aware of it", unless the breach "is unlikely to result in a risk to the rights and freedoms of natural persons". Article 34 adds the people affected when the breach is likely to result in a high risk.
Two details make this an evidence problem.
The first is the clock. The EDPB's breach notification guidelines treat a controller as aware once it has "a reasonable degree of certainty that a security incident has occurred that has led to personal data being compromised". A discovery report can be that moment, so have triage ready before discovery goes live. The second is the file: Article 33(5) requires you to document any personal data breach, including "the facts relating to the personal data breach, its effects and the remedial action taken", whether or not you notify. A decision not to report needs its reasoning on record.
Who is the AI provider under the GDPR, and where is the contract?
Article 4(8) defines a processor as a body "which processes personal data on behalf of the controller". Article 28(3) requires that the processing "shall be governed by a contract or other legal act" binding the processor to act "only on documented instructions from the controller". It must be in writing (Article 28(9)), and subprocessors need your prior written authorization (Article 28(2)).
An unapproved chatbot fails this in one of two ways. If it processes prompts on your behalf, it is a processor with no contract. If its terms let it use submissions for its own purposes, it decides the purposes and means of that processing, which makes it a controller under Article 4(7), and your employee has disclosed personal data to it without anyone entitled to make that call. Either way there is no paperwork, and nobody signs a contract for a tool they never knew about.
If prompts are processed outside the EEA, Article 44 allows the transfer only under the conditions of Chapter V, typically an adequacy decision (Article 45) or appropriate safeguards such as standard data protection clauses (Article 46). For a tool nobody approved, none of that exists.
Why does shadow AI break your Article 30 record?
Article 30(1) requires a record of processing activities listing, among other items, purposes, categories of data subjects and personal data, recipients "including recipients in third countries", transfers and, where possible, erasure time limits and security measures. A tool nobody approved is a recipient missing from that record, and it stays missing until someone finds the tool. Our shadow AI hub collects the discovery patterns.
Article 30(5) exempts enterprises employing fewer than 250 people, but not where the processing is likely to result in a risk, involves special category or criminal conviction data, or is "not occasional". Daily use of an assistant is hard to call occasional.
Two provisions make the AI policy itself evidence. Article 24(2) expects "appropriate data protection policies" where proportionate, and Article 32(4) requires steps to ensure staff with access to personal data do not process it "except on instructions from the controller". The policy is the instruction. Discovery and prompt DLP are the steps. Acknowledgment records show the instruction arrived.
When does an AI deployment need a DPIA?
Article 35(1) requires a data protection impact assessment "prior to the processing" where processing, "in particular using new technologies", is likely to result in a high risk to people's rights and freedoms. Article 35(3)(a) makes one mandatory for systematic and extensive evaluation based on automated processing that drives decisions with legal or similarly significant effects. A chatbot that rephrases marketing copy rarely meets the bar. In our reading, an assistant wired into a workforce's mail, files and HR systems usually does, and Article 35(11) requires a review, where necessary, at least when the risk changes. New vendor features such as memory or agents can change it.
Your controls may need one too. Norway's Datatilsynet lists systematic monitoring of employee activities, with internet activity and electronic communication as examples, among operations that always require a DPIA. Discovery and prompt inspection process employee data, so assess them before switching them on.
The model belongs in the file. In Opinion 28/2024, adopted on 17 December 2024, the EDPB said that where a deployed model retains personal data from its training, authorities should consider whether the deployer "conducted an appropriate assessment" to ascertain that the model "was not developed by unlawfully processing personal data", considering, for example, the source of the data and whether the model results from an infringement, such as one found by an authority or a court.
Formats are converging: the EDPB consulted on a common DPIA template from 14 April to 9 June 2026 and encourages organizations to use it before it is finalized. The Dutch government has also published a DPIA on Microsoft 365 Copilot (updated 11 September 2025).
What changes when an AI agent acts on a person?
A chatbot raises the question of where data went. An agent raises a harder one: what the software did.
Article 22(1) gives people "the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her". Article 22(2) permits such decisions only where necessary for a contract, where EU or member state law authorizes them, or with explicit consent. For the contract and consent routes, Article 22(3) requires at least "the right to obtain human intervention on the part of the controller, to express his or her point of view and to contest the decision".
Two judgments set the bar. In SCHUFA (C-634/21, 7 December 2023), the Court of Justice held that automated credit scoring by a credit information agency is automated individual decision-making where a third party "draws strongly on that probability value to establish, implement or terminate a contractual relationship" with the person. An agent whose rankings people downstream lean on can sit in the same position. In Dun & Bradstreet Austria (C-203/22, 27 February 2025), the Court held that, for such decisions, Article 15(1)(h) lets the person require an explanation of "the procedure and principles actually applied". You cannot explain a procedure you did not record.
France's CNIL has applied this to agents. Its exploratory note with the Conseil de l'IA et du Numérique (20 July 2026) says agent autonomy can, in some cases, produce Article 22 decisions, and that human approval of an agent's proposed output does not necessarily take the decision outside it; purely formal or automatic validation is not enough. It also favors traceability showing, for each task, the personal data used, the agents and third-party services involved, and the exchanges in order.
The Dutch DPA focused on security. On 12 February 2026 it called on users and organizations not to run OpenClaw and similar AI agents on systems holding privacy-sensitive or confidential data, adding that "Innovation and open source do not discharge the obligation to limit risks in advance."
For an agent that touches people, keep four things: the Article 22(2) exception relied on, a DPIA where Article 35(3)(a) applies, a review record showing what the agent proposed and whether the reviewer overrode it, and a log of every task. Our AI agent audit log guide lists the fields; the analysis of agents reading CRM data covers Salesforce and HubSpot.
Does the AI Act or the Digital Omnibus change any of this?
Not for the GDPR. The Digital Omnibus on AI, Regulation (EU) 2026/1744 of 8 July 2026, amends three regulations: the AI Act (2024/1689), Regulation 2018/1139 and the Machinery Regulation (2023/1230). The GDPR is not one of them. Article 2(7) of the AI Act, as replaced, still says the AI Act "shall not affect" the GDPR, without prejudice to its Articles 4a and 59.
Changes to the GDPR sit in separate proposals, and none is law. The Commission's Digital Omnibus, COM(2025) 837, would amend the GDPR along with other digital laws; on 3 October 2026 Parliament's Legislative Observatory lists it as awaiting committee decision. Omnibus IV, COM(2025) 501, which extends some SME relief to small mid-cap companies, would also amend it. A provisional agreement on Omnibus IV was confirmed on 26 June 2026, and Parliament's plenary vote is indicatively set for 23 November 2026. Plan against the text in force.
Where the two laws meet, the AI Act points back to the GDPR. From 2 December 2027, when deployer obligations for Annex III high-risk systems apply, Article 26(9) requires deployers, where applicable, to use the provider's Article 13 information for their DPIA, and the amended Article 27(4) lets a fundamental rights impact assessment cross-refer to the DPIA. Our EU AI Act compliance guide covers the rest.
What about Norway and Switzerland?
Norway: the GDPR applies, the AI Act does not yet
The GDPR applies in Norway through the EEA Agreement. Section 1 of the Personal Data Act (personopplysningsloven, LOV-2018-06-15-38, in force 20 July 2018) gives it force as Norwegian law, and section 20 makes Datatilsynet the supervisory authority. Every GDPR obligation above applies. The AI Act does not: EEA-Lex lists it as "under scrutiny for incorporation into the EEA Agreement".
Switzerland: the FADP, read the same way
Switzerland has its own Federal Act on Data Protection (FADP, SR 235.1), in force since 1 September 2023. The Federal Data Protection and Information Commissioner (FDPIC) said on 9 November 2023, and again on 8 May 2025, that it is "directly applicable to AI-supported data processing". Article 9 covers processors, Article 12 records of processing, Article 21 automated individual decisions (inform the person, and on request hear them and allow human review) and Article 22 DPIAs. Breaches differ: Article 24 requires notice to the FDPIC as quickly as possible when a breach is likely to lead to a high risk, with no fixed number of hours.
What should you put in place first?
Work backward from the request: start with whichever of your Article 30 record, AI provider contracts, breach register and largest AI DPIA you could not produce. Usually that is the inventory, because every other document assumes you know which tools exist.
- Inventory. Find AI use in browsers, desktop apps and agents, and give each tool a record entry.
- Contracts. Tier tools by what the contract says. No Article 28 terms, no personal data.
- Instructions. Publish the policy, record acknowledgment, and map data classes to tool tiers.
- Prompt controls. Redact or block personal data before it leaves; keep each intervention as Article 32 evidence.
- Breach triage. Decide in advance who judges whether a paste is "unlikely to result in a risk", and on what test.
- Agents. Log each task, record each review, and tie each decision about a person to an Article 22(2) exception.
AccuroAI covers the first, fourth and sixth: discovery from a catalog of 1,400+ AI tools, inline inspection of prompts and agent actions, and evidence mapped to 8 frameworks, GDPR among them. The second and third are policy work you can start without us.
Our AI acceptable use policy template, an editable DOCX, defines tool tiers by contract, maps data classes to those tiers in a permission matrix, gives staff a one-page paste decision tree, adds an agent blast-radius table, and records the underlying model in its tool register. It is the instruction layer Articles 24(2) and 32(4) point to.
This article is not legal advice. Quotations and article numbers were checked against the official texts on 8 October 2026; notification, lawful basis and transfer decisions belong with your DPO or counsel.