AI for Data Protection Practitioners
I attended a webinar recently where someone asked if “AI” was a skill required of GDPR advisors now. Yes, it is – this blog lays out what this means for data protection practitioners and privacy professionals working in law, compliance and other information-focused roles.
@growtika on Unsplash
AI and Data Protection
Regardless of what you think about prevalent use of AI by people, the fact is that it won’t go away. Using AI today is:
increasingly encouraged by employers
expected by clients
actively experimented with by professionals themselves.
This is why people working in data protection compliance and related roles need to understand the overlap between machine learning and information law.
What You Need to Know
Hard knowledge:
The different types of “AI”
AI and new technologies, for example facial recognition
Intellectual property law basics
Data protection law, specifically assessments, balancing exercises, principles
Developing legislation, e.g. the EU AI Act
Soft skills:
Critical thinking
Knowing how manage AI systems in a useful way
Creativity
Attention to detail
Different Types of AI and Emerging Technologies
“AI” can mean several different things. Understanding the basics helps with deciding what to do next, based on the personal data in use.
Generative AI systems that create new content based on patterns learned from large datasets
These are tools such as ChatGPTs, bringing in questions whether you have lawful basis for the use of the training data, accuracy of the outputs, IP issues and how much personal (and special category) data there is.
There can also be governance challenges when employees use them poorly and can endanger business information.
Systems that analyse historical data to predict future outcomes or behaviour
This includes credit scoring and recruitment screening and other areas where bias and discrimination can be rife. Advisors have to account for compliance with the rules on automated decision-making under the GDPR.
Systems that analyse images, video or other sensor data
A well-known example is facial recognition technology, where biometric data is in use and all that it brings in terms of data protection, sometimes national compliance requirements as well.
These technologies also bring questions about proportionality and necessity under data protection law.
Data Protection Law and AI Systems
AI and GDPR Compliance
Machine learning systems are often used in automated decision-making under the GDPR. This means that your data protection impact assessments (DPIAs) may need to consider AI-specific risks, or you might want to start doing dedicated AI assessments for AI tools used internally and externally.
Deciding on your lawful basis is your first step to take. In many business contexts, organisations rely on legitimate interests.
Remember that this is flexible but not a get-out-jail card, so when you do your legitimate interest assessments (LIA), treat it as an opportunity to be a pessimist, anticipate risks and consider how that use will affect your average consumer or human at work.
Data minimisation will be a real challenge, given that AI and the GDPR are at stark odds on this point. Speak to your software / product / technical team to decide what’s necessary - using AI is a multidisciplinary exercise.
Transparency
Do you and your team understand how the AI system is working? Do you understand it well enough to explain it in an accessible way to the people whose personal data you will use?
If the answer is no, prepare for challenges, complaints. You should get to a confident “yes” as much as possible to ensure the information you give is useful for the public, your customers, and people who data you use.
Human rights
The GDPR isn’t the only law in action when you use AI - you will have to get acquainted with employment and equality laws at least. We are trying to embed and protect the human in the loop here because while we place full reliance on machines, it will be people that will be affected.
The EU AI Act
The AI Act is a beast one blog post cannot handle, but if you sell or provide a product that qualifies as an “AI system”, your organisation is likely to be subject to it.
It’s a huge compliance effort, so you should review:
Risk categories: keep in mind some risks are unacceptable, so you won’t be able to sell the product.
Obligations for deployers vs providers: they are not the same as those for controllers and processors and it doesn’t matter what you are for GDPR purposes.
Digital Omnibus: keep an eye on these proposals because if the recommendations go through, some of the burdens might be eased.
Intellectual Property Issues in AI
AI systems require and thrive on voluminous amounts of data. Data means all data on the internet - personal, sensitive, general, and such that is subject to IP laws.
When IP comes in the picture, we have an intellectual creation of a person that can only be used under certain circumstances - something like exemptions under data protection law. If you use it without one of those, you are infringing someone else’s IP.
Remember that personal data cannot be owned in an IP sense even though there is an overlap between data protection and IP law.
Copyright
AI, however, does not ask about these circumstances and just uses the information. Online content is not free to use only because it is “made publicly available.”
This makes training data used in, for example, ChatGPT problematic. Most of the information online is subject to someone’s copyright because copyright arises very easily - as soon as you create something (write a post, take a photo, write a song), it attracts copyright. That’s why household names have not been happy about generative AI systems relying on their work.
Ownership of AI outputs
When something comes out of Copilot, do you know who owns the IP in it? If you use Claude Code, who is the creator and owner?
The answer is likely to be in the term and conditions, which the average person does not read. Even if they say you own the content, are you sure that’s the case? Because it’s not 100% clear what data it was trained on at first to give you the output you get.
Licensing
Licensing is one option to use someone’s IP lawfully. Mumsnet for instance tried to make a deal with OpenAI* and license its information-rich platform to train the model (OpenAI had been scraping their website to gather information), but OpenAI refused.
Licensing is a sensible way creators can get what they are due for their content used by AI companies. How that would work in practice, though, I can’t say.
Soft Skills Privacy Professionals Need to Work with AI
You are unlikely to stop learning when it comes to AI. There are a few critical skills you need to hone to be able to use it in a meaningful and productive way, and help others do so.
Critical thinking
Is the output accurate?
Are the references old / real?
Is the AI system trying to be nice to me (it wants to)?
Can I corroborate the output with official sources?
Prompting
Have I given enough context to get the best answer?
Have I told the system not to make things up and give me only facts?
Have I explained what I expect in the output?
Would it benefit from knowing its role (e.g. research not a strategic adviser)?
As you’re working with AI, don’t forget to use your own brain.
* https://www.mumsnet.com/talk/site_stuff/5122770-why-were-taking-legal-action-against-open-ai-and-other-scrapers accessed 10.03.2026