GDPR applies in full to any AI tool that processes personal data, with no exemption for artificial intelligence. Irish businesses stay responsible for lawful basis, transparency, data minimisation and human oversight of automated decisions, exactly as they would for any other software that touches personal data.
AI does not get a special exemption from GDPR. The moment an AI tool touches a customer name, an email address, or any other personal data, standard GDPR obligations apply, with no carve-out for artificial intelligence. The Data Protection Commission says as much directly in its own guidance on AI and data protection, published specifically because so many organisations assumed otherwise.[1] A ChatGPT draft reply, a CRM's AI lead-scoring feature, and a chatbot answering website queries are all ordinary GDPR processing activities wearing a new label.
Before rolling AI tools out any further, most businesses benefit from knowing exactly what is already in use and what data it touches. That is what the AI Readiness Assessment maps.
Does GDPR Apply When You Use AI Tools in Your Business?
Yes, and the Data Protection Commission has been explicit about it since July 2024, when it published dedicated guidance addressing exactly this question.[1] The guidance names several specific risks that show up once personal data meets an AI tool, including data fed in during training or fine-tuning being used in ways nobody agreed to, AI models occasionally reproducing fragments of the data they were trained on, and staff pasting customer details into a free consumer tool with no record of where that text ends up.
Picture a Kerry retailer that starts using an AI chatbot to answer website queries. Within a fortnight, staff are copying customer order numbers and complaint details into the same chatbot to draft replies faster. Nobody signed off on that. Nobody checked what the chatbot's terms say about retaining what it is fed. That scenario sits close to the exact situation the DPC's guidance was written to head off.
In summary
Check what data a new AI tool actually receives before checking what it produces.
What Lawful Basis Do You Need for AI Under GDPR?
Every use of personal data needs one of six lawful bases under Article 6 of GDPR, which are consent, contract, legal obligation, vital interests, public task, and legitimate interests.[2] For most everyday internal AI use, legitimate interests tends to be the basis businesses reach for, such as drafting emails faster, summarising a meeting, or categorising incoming enquiries. Claiming that basis properly means being able to show the interest is real, that using the AI tool is a proportionate way of meeting it, and that it does not override the rights of the person whose data is involved.
Skipping that documentation step leaves the lawful basis unrecorded. That gap surfaces fast the day a customer, an employee, or the DPC asks the question directly.
In summary
Write down the lawful basis before the AI tool goes live, before anyone has to ask.
When Do You Need a DPIA Before Using an AI Tool?
A Data Protection Impact Assessment becomes mandatory once processing is likely to result in high risk to people's rights. The DPC's guidance sets out several specific triggers for that risk level, including large-scale profiling and automated evaluation that produces legal or similarly significant effects for someone.[3] A tool giving one customer a single score does not automatically meet that bar on its own. Scale, the data involved, and how significant the outcome is for the person all factor into whether a given AI use case crosses it.
Ordinary internal AI use, drafting text, summarising a document, tidying up a spreadsheet, sits well below that bar. The question gets sharper the moment an AI tool starts to score, rank, or filter specific people, moving past simple task assistance. Take an insurance broker piloting an AI tool that adjusts quotes based on a customer's browsing behaviour and claims history. That is systematic profiling feeding into a decision with a real financial effect on a named person, and it sits squarely inside the DPIA trigger the DPC describes.
Getting this wrong in either direction costs something. Skip a DPIA that was actually required, and the business has no documented risk assessment to show if a complaint arrives. Run a full DPIA for an internal writing tool that never touches a decision about a specific person, and hours go on paperwork nobody needed.
In summary
Does the AI tool score a specific person, or just assist with a task?
What Happens When an AI Tool Makes a Decision About Someone?
Article 22 of GDPR gives people the right not to be subject to a decision based solely on automated processing where that decision produces legal effects or similarly significantly affects them.[4]
The word doing the work in Article 22 is "solely". Where a competent person genuinely reviews an AI-generated recommendation before it becomes a decision, and can actually change it, the decision falls outside what the law means by automated. Where the AI output gets nodded through as a formality every time, a regulator is entitled to treat that as automated in substance, whatever the process chart claims. The safeguards GDPR requires once this kind of automated processing is permitted include the right to obtain human intervention, the right to put forward a point of view, and the right to challenge the outcome.[4] Special category data, health, ethnicity, and similar, raises the bar further. Automated processing of that kind is lawful only with explicit consent or a substantial public interest justification.
EU AI Act deployer duties under Article 26 apply alongside GDPR only where the AI system involved is classified as high-risk under Annex III, for example systems used to make decisions about creditworthiness, employment, or access to essential services. Most everyday customer-facing tools, general chatbots and drafting assistants included, fall outside that category. Using AI Yourself vs Deploying It for Customers covers what Article 26 requires once a tool does cross that threshold.
In summary
A human sign-off only counts if the human could actually have said no.
What Should You Actually Do Before Rolling Out an AI Tool?
A short, ordered sequence covers most of what actually matters before an AI tool goes anywhere near real customer or staff data.
Map what is already in use
Most businesses have more AI tools running than anyone in charge could name off the top of their head. Tools get adopted team by team, one person finds something that works, word spreads, and the picture builds up long before anyone maps it properly. A one-page inventory, tool by tool, what it does, and what data reaches it, is the starting point everything else depends on. Four columns cover it, naming the tool, what it does, what data it touches, and who is responsible for it.
Confirm the vendor's Data Processing Agreement
Where personal data reaches a third-party AI vendor, GDPR Article 28 requires a written agreement covering how that vendor handles it. A well-known brand does not automatically mean there is a signed agreement in place, though most vendors will hand one over if asked. Why Buying AI Does Not Outsource Accountability sets out that specific gap in full, and why a vendor's own compliance claims do not close it.
Write down the lawful basis
For each tool on the inventory, write down which of the six Article 6 bases applies and why. Keep it plain enough that someone else could read it back and understand it. For an AI writing assistant used on internal emails, that might just be legitimate interest, used to draft routine correspondence faster, no special category data involved, checked by whoever sends the email before it goes out. Ten minutes now saves a scramble later, when nobody can remember the reasoning.
Decide where human review sits
Name a specific, identifiable person for this job, with real authority to change the outcome and enough time to look at it properly before signing off. A reviewer given ninety seconds to approve twenty AI-generated recommendations cannot provide genuine oversight. The time to look properly matters as much as the authority to act on what they find.
Two related pieces worth reading next. EU Data Residency and AI Tools covers where the data physically goes once it leaves the business. AI Literacy Training: What Article 4 Requires covers the separate EU AI Act requirement to make sure staff actually understand the tools they are using. For the next tool decision itself, How to Choose the Right AI Tools gives a repeatable filter so this does not have to be worked out from scratch each time.
In summary
One page naming every AI tool and its data usually surfaces the real gap faster than a policy meeting.
The AI Policy and Governance Pack turns these obligations into a written policy built around the tools this business actually uses, rather than a generic template.
