# GDPR checklist for generative AI

Eight questions to see whether your use of generative AI meets GDPR and what exactly is missing. No sign-up, and nothing you answer is stored.

- Human version: https://rubitec.co/tools/gdpr-generative-ai-checklist
- All tools: https://rubitec.co/tools
- llms.txt: https://rubitec.co/llms.txt

Free tool by Rubitec. No sign-up required and the calculation runs in the browser.

## What it asks for

| Input | Default value |
| --- | --- |
| 1. What data will you put into the tool? | Identifiable personal data: names, emails, phone numbers, CVs |
| 2. Which plan of the tool are you on? | Free or consumer plan |
| 3. Do you have a data processing agreement with the provider? | No, or I do not know |
| 4. Where is the data processed? | In the US, with a provider certified under the adequacy framework |
| 5. Have you informed the people affected? | No |
| 6. Does the AI make decisions about people on its own? | No, a person with authority to change it always reviews |
| 7. Is the processing in your record of processing activities? | No, or I have no record |
| 8. Have you run a data protection impact assessment? | Done, or not required in my case |

## Example with default values

| Result | Value |
| --- | --- |
| Status | High risk |
| Pending actions | 4 |
| Maximum GDPR penalty | €20M or 4% of worldwide turnover |

### Right now you should not be putting that data into the tool

Here is what is missing, in the order worth tackling it:

- Move to a business plan. On free and consumer plans the provider may use your conversations to improve their models, which turns every customer detail you paste in into a disclosure you cannot justify.
- Sign or accept the Article 28 data processing agreement. Without it, any personal data you enter is an uncovered data transfer, and it is the first thing an inspection looks at.
- Update your privacy policy and information clauses to mention the use of AI systems, for what purpose and with which providers. If staff are affected, inform their representatives too.
- Add the processing to your record of activities: purpose, data categories, processors, retention periods and transfers. It is mandatory and fits on one page.

## How it is calculated

The test walks through the points the Spanish DPA and the European Data Protection Board flag as critical when using generative AI: legal basis and data type, the Article 28 processing agreement, international transfers, the duty to inform, Article 22 automated decisions, the record of processing activities and the impact assessment.

If you answer that you only use public data, internal data without people, or genuinely anonymised data, most obligations do not trigger, because GDPR only applies to personal data. Be careful with anonymisation: removing the name while keeping an ID number, a phone or any re-identifying combination is not anonymisation, it is pseudonymisation, and that is still personal data.

GDPR fines reach €20M or 4% of worldwide turnover, whichever is higher. They are independent of AI Act penalties: the same system can breach both at once.

> **Notice.** General guidance, not legal advice. Nothing you answer leaves your browser or is stored on any server.

## Frequently asked questions

### Can I paste customer data into ChatGPT?

With a business plan, a signed processing agreement and an updated privacy policy, yes for ordinary personal data. On the free version, no: the provider may use those conversations for training and you have no contractual cover for the disclosure.

### Can health data go into a generative AI tool?

They are special category data and need an Article 9 basis on top of the Article 6 one. In practice, a clinic should pseudonymise before sending anything, or deploy the model on its own infrastructure or a healthcare provider's with the guarantees signed.

### Are GDPR and the AI Act the same thing?

No, and they apply simultaneously. GDPR protects personal data and triggers as soon as you process information about people. The AI Act regulates the system itself by risk level, even with no personal data involved. Complying with one does not exempt you from the other.

## Related links

- [EU AI Act risk level test](https://rubitec.co/tools/eu-ai-act-risk-test)
- [How to use generative AI without breaching GDPR](https://rubitec.co/insights/como-usar-ia-generativa-sin-incumplir-rgpd)
- [AI guide for companies](https://rubitec.co/guia-ia)
