Key takeaway

A proposed AI use needs its own assessment. An NDA, a buyer’s interest or a removed name does not resolve lawful processing.

Identify the data and the jurisdictions.

Map the people represented in the records, the collecting entity, the proposed recipient and the locations of processing. EU GDPR applicability depends on the facts, including territorial scope. Employee and business-contact information can still concern identifiable people. Do not classify the whole archive as non-personal because it came from a business system.

Assess each stage and purpose.

Collection for customer service and disclosure for AI training are different processing contexts. Ask counsel to assess the applicable lawful basis, purpose compatibility, transparency, individual rights and any special-category rules. Consent is not the only possible GDPR basis, and it is not a universal shortcut.

StageReview question
InventoryCan the purpose be explained using metadata alone?
EvaluationWhat minimum real material is necessary?
LicenseWhich new uses and recipients are proposed?
Ongoing useWho handles rights requests and retention?

Clarify roles and cross-border arrangements.

Determine whether the receiving entity is a processor, independent controller or another arrangement for the intended use. The contract label alone should not determine the answer. Ask which agreements, safeguards and transfer mechanisms are needed. Identify downstream recipients before a license grants them access.

Do not assume a model is anonymous.

The EDPB’s December 2024 AI opinion calls for case-specific assessment of anonymity and legitimate interests. An anonymous model is not established merely because a supplier says training data was de-identified. Keep the record package, derived material and trained system as separate review objects.

  • Ask what evidence supports anonymity for the proposed artifact.
  • Identify whether people can be singled out or information extracted.
  • Assess the necessity and balancing of any legitimate-interest rationale.
  • Ask whether a data protection impact assessment is needed for the actual risks.

Prepare an accountable decision.

Create a short brief with the proposed purpose, data categories, affected people, lawful-processing questions, recipients and exclusions. Assign a reviewer to each unresolved issue. This guide is an educational agenda for EU GDPR review, not legal advice or a determination that a particular dataset is lawful to license.

Tools for this decision

Rights & privacy review →Diligence question builder →