GDPR compliance when using AI: a practical guide
How to stay GDPR-compliant when generating content with AI: handling images, voice, prompts and input materials with traceability and accountability.

Complying with the General Data Protection Regulation is still a core legal obligation for any company, and that doesn’t change just because the image, video, voice or text was created with artificial intelligence.
The moment an agency, production company, brand or media outlet feeds information about an identified or identifiable person into an AI tool, it is processing personal data. That means it needs a lawful basis, and it needs to be able to show what data it used, for what purpose, and under what conditions.
The exposure isn’t limited to what ends up published. It can just as easily sit in the photographs, recordings, documents, databases, prompts and reference material used along the way.
When does the GDPR apply to AI use in a company?
Images, voice, names and biometric data in generative tools
The GDPR applies to uses such as:
- A real person’s image or voice.
- Their name, email address, location or professional details.
- Data about customers, employees, contributors or audiences.
- Event photography or stock images that show recognisable people.
- Health information, children’s data, or biometric data used to identify someone uniquely.
Processing also occurs when that data is sent to an AI provider to generate, edit, transform or analyse content.
Personal data in prompts, inputs and transfers to providers
Spain’s data protection authority, the AEPD, has pointed out that processing can take place at several different stages in the life cycle of an AI system. If an organisation claims its data is anonymised, it needs to be able to demonstrate that the anonymisation genuinely works, and to assess the risk of re-identification.
Accountability in data protection and AI: what you have to be able to show
The GDPR is built around accountability: formal compliance on paper isn’t enough. An organisation has to be able to demonstrate, in practice, that it put appropriate measures in place to protect personal data.

Documenting your lawful basis, purpose and data minimisation
Before personal data goes into a creative asset, it’s worth documenting:
- What data is being used, and where it came from.
- The purpose it’s being processed for.
- The lawful basis that permits that use.
- Which AI tool and provider are involved.
- Whether the provider retains the data or uses it to improve its models.
- Where it’s processed, and whether any international transfers are involved.
- What minimisation, security and access-control measures apply.
- How long the data is retained.
- What human review takes place before publication.
- Whether a data protection impact assessment is needed.
Consent isn’t the only lawful basis available. But the fact that an image, a voice or a piece of data is public online doesn’t make it fair game for any purpose. The lawful basis has to be worked out case by case, and the company has to check that any third-party data was obtained lawfully in the first place.
Why keeping evidence of your materials and tools matters
Picture a production company building avatars from employee photographs, an agency running a campaign built on images of consumers, or a newsroom recreating an interviewee’s voice with AI.
If a complaint comes in, saying you used an approved tool won’t be enough. You’ll need to show which files went in, what permissions existed, which provider processed them, what changes were made, and who signed off on the result.
How does VeriqX help?
VeriqX lets you document the tools and models used, the prompts, the input files, the intermediate materials, the human involvement and the controls applied during production.
That evidence is bound to the final content through a certificate, timestamping and provenance standards such as C2PA / Content Credentials.
VeriqX doesn’t replace your record of processing activities, your processor agreements, your impact assessments or your legal advice. What it adds is a layer of traceability that helps you show how personal data was actually handled during production.
In data protection terms, what you publish is only half the picture. The other half is what you put into the AI to make it.
Key points and frequently asked questions about the GDPR and AI
Does the GDPR apply when you put photos, voices or personal data into an AI prompt?
Yes. Uploading images, audio, documents or people’s data to an AI tool counts as processing personal data, and is subject to the GDPR.
Is user consent enough to use someone’s data in AI tools?
Not always. The company still needs to establish the specific lawful basis, check that the source data was lawfully obtained, and verify whether the provider uses it to train its models.
How does VeriqX help evidence GDPR compliance when using AI?
VeriqX evidences the prompts, input files, tools used and human involvement through timestamped certificates and the C2PA standard.
Need to audit data protection across your AI projects?
- Technical consultancy and corporate certification: [email protected]
- Talk to the author directly (David Lahoz): https://www.linkedin.com/in/dlahoz/
Certify your content with VeriqX
Document how each file was made, seal it with C2PA Content Credentials and share a certificate anyone can verify.
Certify your first file for freeRelated articles

The legal risks of using AI in business
The main legal risks of using AI in business: commercial licensing, intellectual property, privacy and contractual protection against third-party claims.
- Legal risk
- Licensing
- Business

How to get your company ready for the EU AI Act: a compliance checklist
An EU AI Act compliance checklist for companies: audit your tools, train your teams and document how you use AI in line with the 2026 rules.
- EU AI Act
- Governance
- Business

How to document and certify AI-generated content, step by step
A 2026 step-by-step guide to documenting and certifying AI-generated content under the EU AI Act — build your evidence trail before you need it.
- EU AI Act
- Certification
- C2PA