GDPR compliance when using AI: a practical guide

How to stay GDPR-compliant when generating content with AI: handling images, voice, prompts and input materials with traceability and accountability.

By David Lahoz4 min read
A magnifying glass over perforated paper, as an audit metaphor

Complying with the General Data Protection Regulation is still a core legal obligation for any company, and that doesn’t change just because the image, video, voice or text was created with artificial intelligence.

The moment an agency, production company, brand or media outlet feeds information about an identified or identifiable person into an AI tool, it is processing personal data. That means it needs a lawful basis, and it needs to be able to show what data it used, for what purpose, and under what conditions.

The exposure isn’t limited to what ends up published. It can just as easily sit in the photographs, recordings, documents, databases, prompts and reference material used along the way.

When does the GDPR apply to AI use in a company?

Images, voice, names and biometric data in generative tools

The GDPR applies to uses such as:

  • A real person’s image or voice.
  • Their name, email address, location or professional details.
  • Data about customers, employees, contributors or audiences.
  • Event photography or stock images that show recognisable people.
  • Health information, children’s data, or biometric data used to identify someone uniquely.

Processing also occurs when that data is sent to an AI provider to generate, edit, transform or analyse content.

Personal data in prompts, inputs and transfers to providers

Spain’s data protection authority, the AEPD, has pointed out that processing can take place at several different stages in the life cycle of an AI system. If an organisation claims its data is anonymised, it needs to be able to demonstrate that the anonymisation genuinely works, and to assess the risk of re-identification.

Accountability in data protection and AI: what you have to be able to show

The GDPR is built around accountability: formal compliance on paper isn’t enough. An organisation has to be able to demonstrate, in practice, that it put appropriate measures in place to protect personal data.

An articulated wooden hand on a white background

Documenting your lawful basis, purpose and data minimisation

Before personal data goes into a creative asset, it’s worth documenting:

  • What data is being used, and where it came from.
  • The purpose it’s being processed for.
  • The lawful basis that permits that use.
  • Which AI tool and provider are involved.
  • Whether the provider retains the data or uses it to improve its models.
  • Where it’s processed, and whether any international transfers are involved.
  • What minimisation, security and access-control measures apply.
  • How long the data is retained.
  • What human review takes place before publication.
  • Whether a data protection impact assessment is needed.

Consent isn’t the only lawful basis available. But the fact that an image, a voice or a piece of data is public online doesn’t make it fair game for any purpose. The lawful basis has to be worked out case by case, and the company has to check that any third-party data was obtained lawfully in the first place.

Why keeping evidence of your materials and tools matters

Picture a production company building avatars from employee photographs, an agency running a campaign built on images of consumers, or a newsroom recreating an interviewee’s voice with AI.

If a complaint comes in, saying you used an approved tool won’t be enough. You’ll need to show which files went in, what permissions existed, which provider processed them, what changes were made, and who signed off on the result.

How does VeriqX help?

VeriqX lets you document the tools and models used, the prompts, the input files, the intermediate materials, the human involvement and the controls applied during production.

That evidence is bound to the final content through a certificate, timestamping and provenance standards such as C2PA / Content Credentials.

VeriqX doesn’t replace your record of processing activities, your processor agreements, your impact assessments or your legal advice. What it adds is a layer of traceability that helps you show how personal data was actually handled during production.

In data protection terms, what you publish is only half the picture. The other half is what you put into the AI to make it.

Key points and frequently asked questions about the GDPR and AI

Does the GDPR apply when you put photos, voices or personal data into an AI prompt?

Yes. Uploading images, audio, documents or people’s data to an AI tool counts as processing personal data, and is subject to the GDPR.

Not always. The company still needs to establish the specific lawful basis, check that the source data was lawfully obtained, and verify whether the provider uses it to train its models.

How does VeriqX help evidence GDPR compliance when using AI?

VeriqX evidences the prompts, input files, tools used and human involvement through timestamped certificates and the C2PA standard.

Need to audit data protection across your AI projects?

Certify your content with VeriqX

Document how each file was made, seal it with C2PA Content Credentials and share a certificate anyone can verify.

Certify your first file for free

Related articles

Glasses resting on a keyboard next to a terms document
4 min read

The legal risks of using AI in business

The main legal risks of using AI in business: commercial licensing, intellectual property, privacy and contractual protection against third-party claims.

  • Legal risk
  • Licensing
  • Business