Aegis Oversight
Sign UpSchedule Demo
Aegis Oversight
Sign UpSchedule Demo
European Union

GDPR

GDPR applies to every AI system that processes personal data. Establish lawful basis, run DPIAs, honor data subject rights, and document automated decisions — with audit trails that stand up to regulator scrutiny.

In effect since 25 May 2018
1

Framework Overview

The General Data Protection Regulation (Regulation 2016/679) governs the processing of personal data of EU residents. It applies directly to AI systems that ingest, infer, or produce personal data, regardless of where the processing occurs.

Core principles — lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality — all bind AI development and deployment. Controllers must identify a lawful basis for processing, limit data to what is necessary, and demonstrate compliance.

Article 22 grants individuals the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects, plus the right to obtain human intervention and an explanation. Article 35 requires a Data Protection Impact Assessment for high-risk processing, which includes most profiling and large-scale automated decisions.

Article 25 mandates data protection by design and by default, Article 30 requires records of processing activities, and Article 33 requires breach notification within 72 hours. A Data Protection Officer is mandatory for certain organizations, and transfers outside the EU require safeguards.

Who must comply

Controllers and processors established in the EU, and any organization outside the EU that processes personal data of EU residents in connection with offering goods or services or monitoring their behavior — extraterritorial scope.

Maximum penalties

Up to €20 million or 4% of global annual turnover (whichever is higher) for the most serious infringements, such as violating data subject rights or failing to perform a DPIA.

2

Key Requirements Checklist

Use this checklist to scope your GDPR compliance program.

Establish a lawful basis for processing

Identify and document the lawful basis (consent, contract, legitimate interests, etc.) for each AI processing activity and model.

Honor data subject rights

Build workflows for access, rectification, erasure, restriction, portability, and objection, including the right to withdraw consent.

Conduct Data Protection Impact Assessments

Run a DPIA for high-risk AI processing — profiling, large-scale processing of sensitive data, and systematic monitoring.

Implement Article 22 safeguards

For solely automated decisions with legal or significant effects, provide human intervention, the ability to contest, and meaningful explanations.

Apply data minimization and purpose limitation

Limit training and inference data to what is necessary for the documented purpose and prevent function creep.

Maintain records of processing activities

Keep Article 30 records current, including purposes, categories of data, recipients, retention, and transfers.

Implement data protection by design and by default

Build privacy controls into the AI lifecycle and default to the least invasive settings and data exposure.

Notify breaches within 72 hours

Detect, document, and notify personal-data breaches to the supervisory authority within 72 hours, and to affected individuals when high risk.

Manage international data transfers

Use appropriate safeguards (adequacy, SCCs, BCRs) and document transfer impact assessments for data leaving the EU.

Appoint a Data Protection Officer where required

Designate a DPO for large-scale systematic monitoring, large-scale special-category processing, or public authorities.

3

How Aegis Oversight Automates GDPR Compliance

Pre-built controls, continuous checks, and audit-ready evidence — so you implement the checklist once and stay compliant automatically.

Automated DPIA generation

Generate structured Data Protection Impact Assessments from your model inventory, data sources, and processing context instead of building them manually.

Data inventory and lineage

Map which personal data flows into each AI system, where it originates, and where it is transferred, supporting minimization and transfer safeguards.

Consent and lawful-basis records

Record the lawful basis and consent state for each processing activity so you can demonstrate compliance on demand.

Automated decision logging (Article 22)

Log automated decisions, the data used, and the outcomes to support human-intervention requests and explanations.

Data subject request workflows

Track and fulfill access, rectification, erasure, and portability requests against the personal data your AI systems hold.

Breach notification and audit trail

Incident records and audit logs give you the timeline and evidence needed for 72-hour notification and regulator inquiries.

4

Frequently Asked Questions

Does GDPR apply to AI systems?

Yes. Any AI system that processes personal data — training, inference, or profiling — is subject to GDPR, including the principles of minimization, purpose limitation, and the safeguards in Article 22.

What is Article 22 and when does it apply?

Article 22 gives individuals the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects, plus the right to human intervention and an explanation. It applies to fully automated decisions with significant impact, such as credit or hiring screening.

When is a DPIA required for AI?

A Data Protection Impact Assessment is required for high-risk processing, which includes systematic profiling, large-scale processing of sensitive data, and systematic monitoring of publicly accessible areas — most AI profiling triggers it.

What are the penalties for GDPR non-compliance?

Up to €20 million or 4% of global annual turnover, whichever is higher, for the most serious infringements such as violating data subject rights, the principles, or failing to conduct a DPIA.

What is a lawful basis for AI processing?

The same six bases apply to AI as to any processing — consent, contract, legal obligation, vital interests, public task, and legitimate interests. The choice depends on the context, and profiling with significant effects typically requires consent or contract.

Does GDPR apply to companies outside the EU?

Yes. The regulation has extraterritorial scope: it applies to any controller or processor processing EU residents’ personal data in connection with offering them goods or services or monitoring their behavior, regardless of where the organization is established.

Start your GDPR compliance journey today

Get a personalized walkthrough of how Aegis Oversight maps controls to GDPR requirements and keeps you audit-ready as the regulation evolves.