2.2 · Privacy, GDPR & AI

The Six Landmines: Where GDPR and AI Collide

13 minCourse 02

Beyond the legal basis question, there are six specific areas where AI and GDPR create the most significant conflicts. These are the landmines that organisations consistently step on.

Landmine 1: Purpose Limitation

Data collected for one purpose cannot simply be reused for another without a fresh legal basis or a formal compatibility assessment. AI training is a new purpose — and it requires justification.

Landmine 2: Data Minimisation

GDPR requires that only data "adequate, relevant and limited to what is necessary" be processed. AI systems, particularly deep learning models, often perform better with more data — creating direct tension with the minimisation principle. You must be able to justify every data field used in training.

Landmine 3: Automated Decision-Making — and Why the UK and EU Now Differ

This landmine has two versions, and they now work in opposite directions. Under EU GDPR, Article 22 gives individuals the right not to be subject to solely automated decisions that produce legal or similarly significant effects — the default is prohibition unless an exception applies. Under UK GDPR, that is no longer the rule. Section 80 of the Data (Use and Access) Act 2025 replaced Article 22 with new Articles 22A–22D, in force since 5 February 2026, and flipped the default: solely automated significant decisions are now permitted for most personal data, provided the controller has the required safeguards in place.

  • Automated loan decisions without human review → triggers the provision in both regimes; permitted in the UK only with safeguards
  • AI-generated performance reviews that directly determine pay or promotion → same
  • Algorithmic candidate screening that produces a hire/no-hire output → same
  • Insurance premium pricing set entirely by algorithm → same
The UK Safeguards, Not a Free Pass

Under Articles 22A–22D, permission is conditional. The safeguards must include: information to the data subject about the decision, the ability for them to make representations, the ability to obtain meaningful human intervention, and the ability to contest the decision. Skip any one of these and the decision is unlawful — the UK removed the prohibition, not the accountability.

The "Solely Automated" Threshold

In the EU, Article 22 applies to "solely" automated decisions. Many organisations believe a rubber-stamp human approval avoids it. Regulators and courts have consistently rejected this — the CJEU's 2023 SCHUFA ruling held that even a credit score itself can be the "decision" if a downstream party relies on it near-automatically. If a human routinely approves 95%+ of AI outputs without meaningful review, the decision is effectively automated regardless of the label. Treat this the same way under the UK's "meaningful human involvement" test — the bar for what counts as genuine review hasn't moved, only the default outcome when it's absent.

Landmine 4: The Right to Erasure

Individuals have the right to request deletion of their personal data. For data in a database, this is straightforward. For data that was used to train an AI model, it is technically very difficult — the data's influence is embedded in model weights and cannot be selectively removed without retraining.

Landmine 5: Transparency & Explainability

GDPR requires that individuals receive "meaningful information about the logic involved" when automated decisions affect them. For deep learning models, providing a genuine explanation of the decision logic is technically challenging — but legally required.

Landmine 6: Data Protection Impact Assessments (DPIAs)

A DPIA is mandatory before any processing that is "likely to result in a high risk" to individuals. The ICO's guidance makes clear that AI systems processing personal data at scale, using novel technologies, or making automated decisions about individuals will almost always require a DPIA. Many organisations deploy AI without one.

Your GDPR AI Checklist

For every AI system processing personal data: (1) Identify the lawful basis; (2) Document the purpose and confirm data minimisation; (3) Check whether Article 22 (EU) or Articles 22A–22D (UK) apply, and ensure the required safeguards or human oversight are genuinely in place; (4) Assess the right to erasure implications; (5) Build explainability into the model design; (6) Conduct a DPIA.