This article is for anyone who uses artificial intelligence in their company with personal data — customers', candidates', employees' — and has heard that compliance starts in 2027. That date exists, but it belongs to the AI Act, and not to all of it: Article 26, which gathers the obligations of whoever deploys a high-risk system, applies from 2 December 2027 for high-risk systems under Annex III and from 2 August 2028 for those under Annex I; it does not reach products under Annex I, Section B. The GDPR waits for neither date: it applies to any processing of personal data, whether a person, a spreadsheet or an AI system carries it out.
Here are the five GDPR articles that weigh most when AI processes personal data, what each one asks and which post covers it. They are not the only ones that apply; they are the ones a company using AI runs into first.
The figure sets side by side two assessments that are often confused. The FRIA, under Article 27 of the AI Act, is owed by the deployer that is a body governed by public law or a private entity providing public services, with an Annex III high-risk system other than point 2, or by any deployer of the systems in Annex III, point 5, points (b) and (c); it is carried out before first use. The DPIA, under Article 35 GDPR, is owed by the controller where the processing is likely to result in a high risk to the rights and freedoms of natural persons; it is carried out prior to the processing. Between them runs a band: they are independent instruments, and Article 27(4) lets the FRIA reuse the evidence of the DPIA. Of the two lanes, the DPIA is the one already in operation.
The five articles
| Article | What it asks when AI processes personal data | Where we cover it |
|---|---|---|
| Article 5 · principles | Lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation and security; and a controller able to demonstrate compliance with them | An employee pastes customer data into a chatbot, for security |
| Article 6 · legal basis | That the processing rests on one of the six conditions in paragraph 1 | No post of its own |
| Article 22 · automated decisions | The right not to be subject to a decision based solely on automated processing with legal or similarly significant effects, subject to three exceptions | The three exceptions in Article 22 |
| Article 28 · processor | Choosing a processor able to implement appropriate technical and organisational measures, and governing the processing by contract | What the Article 28 contract has to say |
| Article 35 · impact assessment | Assessing before the processing where a high risk to rights and freedoms is likely | The AEPD's Article 35(4) list |
Article 5: the principles, and who has to demonstrate them
Article 5 lists the principles under which personal data are processed, and the first already says a great deal about an AI system: data shall be "processed lawfully, fairly and in a transparent manner in relation to the data subject". Two of the ones that follow are tested in particular ways.
Accuracy. Data shall be "accurate and, where necessary, kept up to date", and every reasonable step must be taken to ensure that inaccurate data are "erased or rectified without delay". If the wrong summary that a system produces about a customer is saved to that customer's record, what the record holds is inaccurate personal data.
Accountability. The controller shall be responsible for compliance and "be able to demonstrate compliance". It is the phrase that turns diligence into documentation: having acted well is not enough; you have to be able to show it.
Transparency takes concrete form in Articles 13 and 14, which set out the information the data subject receives: Article 13 where the data are collected from them, Article 14 where they are not. Where there is automated decision-making, that information includes "the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved".
And appropriate security of the data is the principle that breaks when an employee pastes customer data into a tool the company does not control: that is the case we analyse separately.
Article 6: the legal basis comes before the tool
"Processing shall be lawful only if and to the extent that at least one of the following applies", and paragraph 1 lists six conditions: the data subject's consent, the performance of a contract to which the data subject is party, compliance with a legal obligation, the protection of vital interests, a task carried out in the public interest, and the legitimate interests of the controller or a third party, except where they are overridden by the interests or fundamental rights and freedoms of the data subject.
With AI, the practical question is not which tool to use but whether the new use fits the basis already in place: Article 5 bars processing data in a manner incompatible with the purposes for which they were collected, so running them through a system for something unrelated to those purposes means looking at the legal basis again.
Article 22: when the machine decides
"The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her."
Two conditions bound the right: the decision must be based solely on automated processing, and it must produce those effects. Not all automation is an Article 22 decision, and the AEPD makes the same point in its guidance on agentic AI: bringing agents into a processing operation can automate it without there being a decision in the sense of that article.
Paragraph 2 sets out three exceptions: the decision is necessary for entering into or performing a contract, it is authorised by Union or Member State law with suitable measures, or it is based on the data subject's explicit consent. In the first and the third, paragraph 3 requires measures including "at least the right to obtain human intervention on the part of the controller, to express his or her point of view and to contest the decision".
Article 28: the vendor that processes data on your behalf
Where an AI vendor processes personal data on your company's behalf, Article 28 places the burden on whoever chooses it: "the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures".
That processing is governed by a contract or other legal act that sets out the subject-matter, duration, nature and purpose of the processing, the type of personal data and the categories of data subjects, and that requires the processor, among other things, to process the data only on documented instructions from the controller. And the processor may not engage another processor without the controller's prior written authorisation.
Article 35: the impact assessment does not wait for AI Act high risk
"Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact".
The test is the risk of the processing, not how the AI Act classifies the system: a system that is not high-risk under the AI Act may still require a DPIA. The AEPD has published its Article 35(4) list, available in Spanish only, under which a DPIA will be needed in most cases where the processing meets two or more of the eleven criteria it sets out. We explain it in the AEPD's Article 35(4) list.
Where the system is high-risk, the AI Act links to this assessment: its Article 26(9) asks the deployer to use, where applicable, the information the provider supplies to carry it out.
What can already be examined
The AEPD already supervises AI that processes personal data, and the four situations we describe in that article — the assessment that was never done, the automated decision without safeguards, biometrics without a prior assessment and the breach through a vendor — all run through these five articles.
Of the AI Act, Articles 4 and 5 — AI literacy and prohibited practices — have applied since 2 February 2025, except for the prohibitions added by Regulation (EU) 2026/1744, which apply from 2 December 2026. The remaining dates are in the calendar, and the Annex III date, which decides which systems are high-risk, is 2027, not 2026.
To organise the documentation work these five articles call for, the governance module brings together policies, owners and evidence.
Content in accordance with Articles 5, 6, 13, 14, 22, 28 and 35 of Regulation (EU) 2016/679, cited from the text published in OJ L 119 of 4.5.2016 and verified against the consolidated version.
This article is for informational purposes only and does not constitute legal advice.