AI Security

AI GDPR Risk Mapper

An AI GDPR risk mapper turns three facts about a system, whether it processes EU personal data, how sensitive that data is, and whether it makes decisions without a human, into the list of GDPR articles that apply. It is a triage step before a DPIA, not a substitute for one.

Last reviewed by the Radiatus Cloud team

GDPR Risk Assessment

Securing AI in production?

We build guardrails, governance & compliance for AI systems.

Talk to an AI advisor

The three questions and what they trigger

EU personal data brings the whole regulation into scope: a lawful basis under Article 6, transparency notices under Articles 13 and 14, and the data subject rights in Articles 15 to 22. GDPR applies by the location of the data subject, not the company, so a US-hosted model serving EU users is caught.

Sensitive or special category data, meaning health, biometrics, ethnicity, religion, sexual orientation, politics and union membership, needs an Article 9 exception on top of the Article 6 basis. Consent is the usual one and it must be explicit. Processing this data at scale with new technology is exactly the profile Article 35 names as requiring a DPIA.

Automated decision-making triggers Article 22: individuals have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. Credit, hiring, insurance pricing and benefits eligibility are the textbook cases. The exceptions are contract necessity, explicit consent or a legal authorisation, and each requires safeguards: a way to obtain human intervention, express a view and contest the decision.

Right to explanation, carefully worded

The mapper flags an explanation requirement for automated decisions. Strictly, Articles 13 to 15 require meaningful information about the logic involved and the envisaged consequences, and Recital 71 mentions an explanation of the decision reached. Whether that amounts to a full right to explanation of an individual output is contested; the CJEU's 2025 Dun and Bradstreet ruling pushed it closer to yes. Plan for it.

What the mapper does not cover

  • Controller versus processor role, which decides who owes which obligation.
  • International transfers under Chapter V, including where the model provider stores prompts.
  • Article 30 records of processing and Article 28 processor contracts with the AI vendor.
  • The EU AI Act, which layers separate risk tiers on top of GDPR for the same system.

A worked case

A recruitment screening model trained on CVs of EU applicants that auto-rejects below a score: EU data yes, basic data with a real chance of inferred special category data, automated decision yes. Result: Article 6 basis (legitimate interest is hard to argue for rejection), Article 22 safeguards with human review of rejections, a DPIA, and under the AI Act a high-risk classification with its own conformity duties.

Related tools

  • GDPR DPIA Generator — Build a GDPR Article 35 Data Protection Impact Assessment: necessity, proportionality, risk scoring and mitigations. Structured DPIA template, free.
  • GDPR Lawful Basis Selector — Determine appropriate GDPR lawful basis for data processing activities.
  • EU AI Act Risk Classifier — Classify an AI system into minimal/limited/high/unacceptable risk using a simplified questionnaire.
  • AI PII Detector — Paste AI output to scan for sensitive PII/PHI patterns.

Frequently Asked Questions

Does using an AI vendor's API make them the controller?

Usually not. If you decide the purpose, you are the controller and the vendor is a processor, which means you need an Article 28 contract and you carry the obligations the mapper lists. Vendors that train on your prompts may become independent controllers for that use.

Is a DPIA mandatory for every AI system?

No. Article 35 requires one where processing is likely to result in a high risk, and supervisory authorities publish lists of triggers. Systematic profiling, large-scale special category data and innovative technology on personal data are the usual AI triggers; a spell-checker is not.

Does Article 22 apply if a human reviews the output?

Only if the review is meaningful. A person who rubber-stamps model decisions at volume does not make the processing non-automated; regulators look at whether the reviewer has authority and information to change the outcome.

What counts as a similarly significant effect?

Anything that materially affects circumstances, behaviour or choices: loan denial, job rejection, insurance price, access to services. Targeted advertising generally does not, unless it exploits vulnerability or affects access to essentials.

Can I rely on legitimate interest for AI training on personal data?

Sometimes. The EDPB's 2024 opinion says it can work with a three-part test and strong safeguards, but expectations of the data subjects matter. Scraping profiles to train a model people never expected is where authorities have objected.

Privacy & Security

Mapping is local.

Data: None
Client-side-Side
Active
v1.0

About This Tool

This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.