Skip to content
AI Privacy - VerityAI
Back to All Topics

AI Privacy

AI and privacy collide wherever personal data trains or runs a model. These articles cover the GDPR duties, when a DPIA is needed, and how techniques like anonymisation and synthetic data hold up under scrutiny.

All AI Privacy Posts (20)

Children's Data in AI: GDPR, COPPA and UK Rules Explained

If a child can reach your AI product, four regimes apply at once. A calm, board-level map of GDPR Article 8, the UK Children's Code, COPPA's 2025 rule and Online Safety Act age assurance, plus the seven things your legal and data teams should check now.

Cross-Border AI Data Transfers: GDPR Rules for Banks

To train or run AI on data that crosses borders, a bank or fintech needs a lawful GDPR Chapter V route: adequacy, SCCs, or a narrow derogation. How to map the transfers an AI deployment hides, pass the transfer risk assessment, and handle the UK's 2026 divergence on top.

Frequently asked questions

Does GDPR apply to AI systems?

Yes. Wherever an AI system processes personal data, GDPR applies in full: lawful basis, data minimisation, purpose limitation, and the rights of the people in the data. Training on personal data is processing.

When do you need a DPIA for AI?

A data protection impact assessment is required for processing likely to be high-risk to people, which covers most AI that profiles, scores or makes decisions about individuals. It is best done before deployment, not after.

Is synthetic data exempt from GDPR?

Not automatically. Synthetic data sits outside GDPR only when a real person cannot realistically be re-identified from it. If re-identification is possible, the data is still personal data.

Related topics