Do you need a legal basis to use AI with customer data?
Yes, in effectively every case where personal data feeds an AI system. Article 6 GDPR requires one of six lawful bases before you can process personal data at all, and for AI use cases the realistic options are usually narrower than teams assume:
- Consent — valid only if it's freely given, specific, and as easy to withdraw as to give. A pre-ticked box or a "by using this site you agree" banner does not qualify.
- Contract necessity — the AI processing has to be genuinely necessary to deliver what the customer signed up for, not merely convenient for you.
- Legitimate interest — requires a documented balancing test weighing your interest against the individual's rights, and it gets harder to justify the more consequential the AI decision is.
If the data includes special categories — health, biometric, political opinion, and similar under Article 9 — the bar rises further, and most AI use cases will need explicit consent or a narrow statutory exception.
The two GDPR rights that most often collide with AI projects
Of everything in GDPR, two provisions most often force a mid-project redesign:
- Article 22 — automated decision-making. Individuals can't be subject to a decision based solely on automated processing, including profiling, that has legal or similarly significant effects — unless an exception applies, and even then they can demand human review.
- Article 35 — DPIA. Required when processing is likely to create high risk to individuals' rights — which covers most large-scale profiling, systematic monitoring, and automated decision-making with significant effects.
GDPR doesn't go away because the AI Act exists — the two apply in parallel and answer different questions. The AI Act asks whether the AI system itself is safe and well-documented; GDPR asks whether the personal data flowing through that system is processed lawfully, regardless of how well-built the system is.
Where this gets country-specific
GDPR is EU-wide, but enforcement runs through each country's own data protection authority, and some — like Spain's AEPD — have published AI-specific guidance that goes further than the regulation's bare text, particularly around agentic and autonomous AI systems. If you operate in Spain, how the AEPD is regulating autonomous AI covers what that means concretely.
Frequently asked questions
Do I need a legal basis under GDPR to use AI with customer data?
Yes, whenever the AI system processes personal data — which most consequential AI systems do. Article 6 GDPR requires a lawful basis: consent, contract necessity, legal obligation, or legitimate interest are the most common for AI use cases, and which one applies changes what you owe the data subject.
Does the AI Act replace GDPR?
No. They are separate regulations that apply together. The AI Act is a product-safety regulation focused on the AI system itself — its risk tier, documentation, oversight. GDPR governs the personal data the system processes, regardless of how sophisticated the system is. A fully AI Act-compliant system can still violate GDPR if it lacks a lawful basis for the data it uses.
When does an AI system need a DPIA?
GDPR Article 35 requires a Data Protection Impact Assessment when processing is "likely to result in a high risk to the rights and freedoms of natural persons" — which the EDPB's own guidance says commonly includes automated decision-making with legal or similarly significant effects, large-scale profiling, and systematic monitoring. Most high-risk AI Act systems meet this bar automatically.
Can a customer object to an AI-driven decision about them?
Under GDPR Article 22, individuals have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects — with exceptions for contract necessity, authorization by law, or explicit consent, each of which still requires safeguards like the right to obtain human review.