GDPR and LLMs: Lawful Basis, DPIAs and International Transfers
A practical GDPR walk-through for deploying LLMs: roles, lawful basis, DPIAs and international transfers.
The GDPR was not written with large language models in mind, but it applies the moment a prompt, a retrieved document or a model output contains personal data. For a controller deploying LLMs and agents, the work is mostly familiar questions answered precisely: who is the controller, what is the lawful basis, where does the data go, and what did you assess before you started.
Last verified 2026-10-06. The primary text is the GDPR on EUR-Lex; our shorter reference is GDPR for AI.
1. Get the roles right first
Most enterprise LLM deployments have one shape. Your organization decides why and how personal data is processed, so you are the controller. The model gateway, hosting provider or SaaS vendor processes data on your behalf, so it is usually a processor.
Article 28 then does the heavy lifting. You need a written contract covering:
- processing only on your instructions;
- authorization of sub-processors;
- assistance with your obligations;
- deletion or return of data at the end of the service;
- audits.
The common mistake is to treat the model provider as the only processor. In an agent deployment the chain is longer: the orchestration layer, the vector store, the observability tool and every external tool the agent can call may touch personal data. Map all of them. Our guide to LLM observability explains why trace data deserves the same scrutiny as the prompts themselves.
2. Pick and document a lawful basis
Every purpose needs a lawful basis under Article 6, and you should record it per purpose, not once per platform. If you rely on legitimate interest, the EDPB's Opinion 28/2024 on AI models (17 December 2024) is the document to read. It confirms legitimate interest can be a basis, subject to a three-step test:
- Is the interest legitimate? It should be lawful, clearly articulated and real.
- Is the processing necessary for it? Could a less intrusive route, such as redacting personal data before it reaches the model, achieve the same aim?
- Does it survive balancing? Your interest is weighed against the rights and reasonable expectations of the people concerned.
The same opinion makes two further points for deployers. A model trained on personal data is not automatically anonymous, so each case needs its own assessment. And a deployer should assess whether the model it uses was developed lawfully. In procurement terms, ask vendors what they can say about training-data provenance and record the answer. See also CMS's summary and the EDPB's April 2025 report on LLM privacy risks and mitigations.
3. Special-category data and prompts
Prompts are free text, so health details, union membership or ethnicity can end up in them. If your use case may involve special-category data, plan for it: block or redact it at the gateway, limit it to workflows where it is expected and separately justified, or route those requests to a more tightly controlled deployment.
Separately, the AI Act's Digital Omnibus (Regulation (EU) 2026/1744) added an Article 4a, a legal basis to process special-category data for bias detection and correction where strictly necessary. That is narrow and specific to bias work. See the AI Act timeline for what else changed.
4. Article 22: automated decisions are not a footnote
Article 22 gives people the right not to be subject to a decision based solely on automated processing with legal or similarly significant effects. The exceptions are contract necessity, authorization by law and explicit consent, each with safeguards that include human intervention. Two Court of Justice rulings sharpen this for AI:
- SCHUFA (C-634/21, 7 December 2023): a credit score can itself be an Article 22 decision where the lender draws strongly on it.
- Dun & Bradstreet Austria (C-203/22, 27 February 2025): the data subject is entitled to a meaningful explanation of the procedure and principles actually applied. According to Bird & Bird's analysis, the Court did not require wholesale disclosure of the algorithm and balances trade-secret interests.
For agents, the lesson is about design. If an agent scores, ranks or approves anything that significantly affects a person, treat Article 22 as in play. Build human review with real authority, and keep a trace of the inputs, model version and tools behind each output so you can give the explanation the Court expects.
5. The DPIA: triggers and content
Article 35 requires a data protection impact assessment where processing is likely to result in high risk. It names three triggers in particular: systematic and extensive profiling with significant effects, large-scale processing of special-category data, and large-scale systematic monitoring. Many LLM use cases in HR, credit, customer profiling and employee monitoring can hit at least one.
Article 35(7) sets the minimum content:
| Element | What it means for an LLM deployment |
|---|---|
| Processing and purposes | Data categories in prompts and retrieval sources, models used, tools the agent can call, retention |
| Necessity and proportionality | Why an LLM is needed, what was minimized or redacted, the lawful basis |
| Risks to rights and freedoms | Leakage through outputs, inaccurate statements about people, over-broad agent permissions |
| Measures | Access controls, filtering, human oversight, logging, vendor terms, transfer safeguards |
If a high residual risk remains, Article 36 requires prior consultation with the supervisory authority.
The AI Act connects here. For high-risk systems, Article 26(9) tells deployers to use the provider's Article 13 information in their DPIA. Article 27 adds a fundamental-rights impact assessment for certain deployers, which complements the DPIA. Our DPIA for AI page has a working outline, and the high-risk checklist shows where the two overlap.
6. Security, design and records
Article 32 asks for security appropriate to the risk: pseudonymization and encryption, confidentiality, integrity, availability and resilience, and regular testing. Article 25 adds data protection by design and by default, and Article 30 requires records of processing. For AI, list the model and agent layers as processing activities in their own right.
The controls that matter most for agents are least-privilege tool access, retrieval that respects the requesting user's existing permissions, redaction before data leaves your boundary, and logs detailed enough to reconstruct events without becoming a second uncontrolled copy of the personal data.
7. International transfers
Chapter V (Articles 44 to 49) allows transfers on a recognized basis: adequacy (Article 45), safeguards such as standard contractual clauses or binding corporate rules (Article 46), or a narrow derogation (Article 49).
For US providers the usual route is the EU-US Data Privacy Framework, based on an adequacy decision of 10 July 2023. Check its status at signing. The General Court dismissed the Latombe challenge on 3 September 2025, and according to Digital Policy Alert an appeal is pending at the Court of Justice as case C-703/25 P. The Court's Schrems II judgment (C-311/18, 16 July 2020) invalidated the earlier Privacy Shield and requires a transfer impact assessment when relying on standard contractual clauses. Keep a documented fallback mechanism rather than assuming the framework will last.
8. What in-region inference does and does not do
In-region inference means the model runs inside a defined region, for example the EU. Concretely, that covers where prompts, retrieval indexes, model weights and inference compute, logs and backups sit, and who can administer them. We unpack this in what in-region must mean.
Running inference in the EU shrinks the transfer problem, because the main flow of prompts and outputs no longer crosses a border. It does not remove the rest of the analysis:
- Sub-processors: an EU data center may still involve sub-processors elsewhere. Ask for the list and the locations.
- Remote access: administering EU-hosted systems from a third country is a question to ask, not assume away.
- Adjacent systems: observability, backups and fine-tuning pipelines may sit outside the region even when inference does not.
Treat "EU-hosted" as a claim to verify. See our data sovereignty guide and the EU-first AI stack post. For cloud and model-hosting exit planning, the Data Act's switching rules are covered in Data Act and AI.
9. The GDPR half of the Digital Omnibus is not law
Two different Omnibus efforts exist. The AI one is in force (see above). The separate proposal touching the GDPR and ePrivacy, published by the Commission on 19 November 2025, is only a proposal.
According to Acompli and PrivacyNext, as of early October 2026 there is no Council mandate and no committee vote, with one expected in early 2027. The proposals on the definition of personal data and on legitimate interest for AI training are contested, and the Council is reported to have dropped the Article 22 rewrite from its drafts. The EDPB-EDPS Joint Opinion 2/2026 sets out the regulators' view. Until something is adopted, the GDPR applies unchanged.
What it costs to get wrong
Article 83 allows fines of up to EUR 10 million or 2% of worldwide annual turnover for some infringements, and up to EUR 20 million or 4% for others, whichever is higher.
How Swfte supports this
Swfte is a sovereign-by-design platform built for Europe, designed to let you decide where AI runs, which models are approved and what an agent may do. The Trust Profile records each AI system's owner, risk level, approved models, data classification, data residency, permitted and restricted actions, human approval rule, retention and audit settings, giving a DPIA a concrete inventory to start from. Swfte provides the technical controls, governance mechanisms and evidence to support deployment within applicable requirements; the exact posture depends on use case, jurisdiction, deployment and configuration. Private, dedicated and in-country hosting are the platform's position, scoped through a dedicated deployment engagement. Today, customer data is stored in AWS eu-west-1 (Ireland), and our DPA and subprocessor pages are drafts pending legal review, so check them against your own requirements. See the EU hub, governance, sovereignty and the trust page.
This is not legal advice. Confirm your position with qualified counsel and your data protection officer.