Artificial intelligence is being adopted rapidly across organisations. However, many AI initiatives encounter data protection challenges long before they deliver any business value. In many cases, the technology works exactly as expected, but organisations later discover that, due to the integration of AI, personal data is transferred outside the EU, user prompts are used to train models, or a Data Protection Impact Assessment (DPIA) reveals significant risks.
The key lesson is simple: most AI-related privacy risks exist before deployment, and not only during it.
What is Data Protection by Design and Default?
Data Protection by Design and Default is defined in Article 25 of the GDPR.It requires data controllers to implement appropriate technical and organizational measures that ensure data protection principles and the rights of data subjects are effectively protected.
The concept consists of two complementary principles.
Privacy by Default means systems should be configured to process the minimum amount of personal data necessary, limit processing activities, apply the shortest possible retention periods, and restrict access to those who genuinely need the data.
Privacy by Design means that privacy considerations must be embedded into the development of products, services, and processes from the beginning, rather than being added after implementation.
Why Is AI Different?
AI systems introduce unique privacy challenges. Users can submit virtually any information into the system, personal data may be processed unexpectedly, and AI solutions often rely on complex supplier ecosystems involving multiple processors and sub processors.
In addition, AI systems may generate inferences about people, potentially creating significant impacts on individuals. These characteristics make GDPR principles such as data minimisation, transparency, accountability, risk assessment, and continuous monitoring more important than ever.
Four Dimensions of AI System Acquisition
Data Protection by Design starts before a contract is signed. Organisations should assess four critical areas before making a procurement decision.
- What personal data will be processed?
Organisations need to understand what data enters the system, whether all data is necessary, and whether special categories of personal data are involved.
- How will the data be used?
Will the information be used solely to provide the service, or will it also be used to train or improve AI models? Will the purpose of processing change over time?
- Who processes the data?
Organisations should identify the controller, processors, subprocessors, data locations, and any transfers outside the EU or EEA.
- How are risks managed?
Organisations should determine whether a DPIA is required, how data subject rights will be fulfilled, how data can be deleted, and how system changes will be monitored.
Ten Questions to Ask Before Acquiring AI
In practice, these four dimensions can be considered with following questions when acquiring an AI system:
- What are the data requirements?
- Are there data minimisation opportunities?
- What are model training practices?
- Are there secondary uses of data?
- Who are the subprocessors?
- Where are the data locations and is there transfers?
- Is a DPIA required?
- Are there profiling and automated inferences?
- How are data subject rights respected?
- What are the data deletion and retention practices?
If you cannot answer one or more of these questions, you likely do not yet understand the privacy implications of the AI solution well enough.
How to Ensure AI Compliance in Practice
AI compliance is not a single document or assessment. It is an ongoing governance process built on four layers.
- First, organisations need a solid foundation that includes strategy, data governance, technology, skills, ethics, and accountability.
- Second, they need visibility through AI use case inventories, risk classifications, and AI policies.
- Third, they need assessments such as DPIAs, FRIAs, and supplier reviews.
- Finally, they need continuity through annual planning, metrics, incident management, and management reporting.
Conclusion
The privacy of an AI system is not determined during deployment. It is determined by the choices made much earlier during procurement and design. Organizations that identify personal data uses, supplier chains, privacy risks, and compliance obligations at the beginning of the journey will significantly reduce later risks and rework. Privacy by Design and by Default is therefore not only a GDPR requirement but also a practical framework for successful and sustainable AI adoption.
