AI and GDPR: The Compliance Checklist (2026)
The GDPR checklist for compliant AI use: lawful basis, minimisation, DPIA, records. The key lever: anonymise your data before the prompt.
Your teams already use AI. That's a fact, not a hypothesis. So the real question is no longer « should we allow it? », but « how do we make it GDPR-compliant? ». Here is a concrete 10-point checklist, built for a manager or a DPO (data protection officer). One thread runs through it. The minimisation principle requires exposing only what is strictly necessary. In practice: anonymise identifiers before you send them to the AI. Data that is never transmitted cannot leak.
The problem: AI already processes personal data
A prompt is not neutral. Your staff paste in client names. Emails. Contract excerpts. HR tables. As soon as data identifies a person, it is personal data. And running it through an AI tool is processing under the GDPR.
The stakes are twofold. First, the substance of the law: every processing must rest on a lawful basis and respect the regulation's principles. Second, the concrete risk: data pasted into a consumer tool can be retained, reviewed or reused. The CNIL, France's data protection authority, published practical guidance in 2025 for applying the GDPR to AI systems. The message: innovation and people's rights can hold together, provided you set a frame.
Should you ban AI internally, then? No. A ban pushes usage into the shadows, out of any control. Better to frame it. The checklist below does exactly that.
The GDPR checklist in 10 points
Work through these ten steps in order. Each is actionable this week. Point 3 is the central lever: it applies minimisation concretely.
- 1List the personal data entering the AI: prompts, attached files, conversation history.
- 2Define a lawful basis (Article 6 of the GDPR) for this processing — often contract performance or legitimate interest, depending on context.
- 3Apply minimisation: anonymise identifiers BEFORE the prompt. This is lever number one. Data never sent cannot leak.
- 4Check the tool's contract: a DPA (data processing agreement) and a « no training on your data » clause.
- 5Run a DPIA (data protection impact assessment, Article 35) if the use presents a high risk.
- 6Inform the people concerned — employees, clients. Transparency is an obligation, not an option.
- 7Keep your records of processing (Article 30) up to date; add your new AI use to them.
- 8Keep a human in the loop for decisions that affect people.
- 9Frame transfers outside the EU if the tool is American. The EU-US Data Privacy Framework exists, but remains to be verified.
- 10Train your teams: the best rule fails if no one knows it.
The DPIA: mandatory only if the risk is high
A common confusion: « we use AI, so a DPIA is mandatory ». That's false. Article 35 of the GDPR triggers a DPIA when a processing is likely to result in a high risk to people's rights and freedoms. The DPIA then describes the processing, assesses its necessity and proportionality, and sets the measures to control the risks.
How do you know the risk is high? The CNIL has defined nine criteria. Here are the main ones.
- Profiling or evaluation of individuals.
- Automated decision with legal effect.
- Systematic monitoring.
- Processing of sensitive data or on a large scale.
- Matching of datasets, or vulnerable individuals.
The CNIL's practical rule: a processing that meets at least two of these nine criteria is presumed high-risk. The DPIA then becomes mandatory. Another useful nuance: using AI does not, on its own, require appointing a DPO. Article 37 makes it mandatory only in three specific cases. First, public bodies. Next, those whose core activities involve large-scale, regular and systematic monitoring. Finally, those that process special-category or criminal data on a large scale.
| GDPR step | What you do concretely |
|---|---|
| Minimisation (Art. 5) | Anonymise identifiers before pasting them into the AI |
| Lawful basis (Art. 6) | Document the ground: contract or legitimate interest, as the case may be |
| DPIA (Art. 35) | Run it if the processing meets at least 2 of the 9 CNIL criteria |
| Records (Art. 30) | Add the new AI use to your records of processing activities |
The solution: anonymise before the prompt
The whole checklist rests on one simple control. If the AI never sees your identifiers, the risk collapses. You no longer have to trust a third-party tool's retention. The sensitive data simply never left your machine. That is minimisation applied to the letter.
In practice, the gesture takes four steps. You keep control of the mapping between the token and the real value, locally.
- 1Spot the personal data in your text: names, emails, identifiers, amounts.
- 2Replace them with reversible tokens, in the browser.
- 3Send only the anonymized text to the AI.
- 4Restore the real values in the reply, locally.
That's exactly what ONYRI Sanitize is for. The engine spots sensitive data — names, emails, identifiers, amounts — and replaces it with reversible tokens before sending. Detection and the mapping stay in your browser. Only anonymized text reaches the model. You tick the heaviest box on your GDPR checklist — minimisation — without giving up the power of AI.
Frequently asked questions
- How do you make AI use GDPR-compliant?
- Follow a checklist of a few key steps. List the personal data entering the AI. Define a lawful basis (Article 6). Apply minimisation by anonymising identifiers before the prompt. Check the tool's contract (DPA, no training). Run a DPIA if the risk is high. Update your records of processing. The most effective lever is anonymisation before sending: data that is never transmitted cannot leak.
- Is a DPIA mandatory for any AI use?
- No. Article 35 of the GDPR requires a DPIA (impact assessment) only when the processing presents a high risk to people's rights and freedoms. The CNIL has defined nine criteria; a processing that meets at least two is presumed high-risk. Using AI therefore does not automatically trigger a DPIA, nor the obligation to appoint a DPO.
- Can you use an American AI while complying with the GDPR?
- Yes, provided you frame the transfer of data outside the EU. The EU-US Data Privacy Framework exists, but its adequacy remains to be verified at the time of your project. The most robust defence: don't transfer any personal data at all. By anonymising identifiers before the prompt, the tool receives only tokens — there is then no personal data left to transfer.
Sources & references
- AI — How to comply? (practical guidance and recommendations on applying the GDPR to AI) — CNIL
- General Data Protection Regulation (GDPR) — full text (Art. 5 minimisation, 6 lawful bases, 35 DPIA) — EUR-Lex / European Union
- GDPR: the records of processing activities (Art. 30 — purposes, categories, recipients, retention, security) — CNIL
Keep your sensitive data in your browser
ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.
Anonymize my prompt