Skip to content
Is there an AI for this?

Jurisdiction

European Union

Source
Editorial review of primary sources — not yet re-anchored
Verified
Evidence not verified
Confidence
Low

Structured issue-spotting to support your own review — not legal advice. Verify against the cited primary sources and your counsel.

01Framework

The EU regulates personal data under the GDPR and AI under Regulation (EU) 2024/1689, the AI Act. The AI Act applies in stages: prohibitions since 2 February 2025, general-purpose AI and governance since 2 August 2025, general application since 2 August 2026. Regulation (EU) 2026/1744, in force since 27 July 2026, moved the high-risk obligations to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I. Member State law adds to both — in Germany, employee data protection and works-council co-determination usually bind before either regulation does.

Region
Europe
ISO code
EU
Privacy framework
Regulation (EU) 2016/679 (GDPR). Directly applicable in every Member State and unamended as of the review date. An AI deployment engages Articles 5 and 6 on principles and lawful basis, 9 on special categories, 13 and 14 on information, 22 on decisions based solely on automated processing, 28 on processors, 32 on security, 35 on impact assessments and Chapter V on transfers out of the EEA. Member States retain room to legislate on employment, which is where Germany’s BDSG § 26 comes in.
AI-specific rules
The AI Act classifies systems by risk. Annex III point 4 makes AI used to recruit or select people, to evaluate candidates, to decide on terms of employment or promotion, or to monitor and evaluate performance, a high-risk class — and the deployer, not just the provider, carries obligations. Those obligations now apply from 2 December 2027 rather than 2 August 2026, because Regulation (EU) 2026/1744 moved them. Prohibitions, AI literacy, general-purpose AI duties, governance and the Article 50 transparency duties are already applicable. Two new prohibitions and an Article 50(2) transition arrive on 2 December 2026. On the data protection side, EDPB Opinion 28/2024 addresses when an AI model can be treated as anonymous and when legitimate interest supports developing or deploying one.
Last reviewed
20 Aug 2026
Status
published

Cross-border transfer

Chapter V GDPR governs transfers to third countries. Without an adequacy decision the usual route is the Commission’s standard contractual clauses under Decision (EU) 2021/914, with the module matched to the actual relationship and a transfer impact assessment behind it. For an AI deployment the transfer is often invisible in the architecture diagram: a model API call, an evaluation pipeline, a support tunnel, or a subprocessor two layers down. Ask where inference runs, where logs are retained, and where support staff sit — three different answers are common. Where a vendor offers a regional endpoint it usually has to be selected explicitly; the default endpoint is rarely the regional one.

Primary sources

  1. LegislationRegulation (EU) 2016/679 (GDPR) — EUR-Lex
  2. LegislationRegulation (EU) 2024/1689 (AI Act), consolidated to 27 July 2026 — EUR-Lex
  3. LegislationRegulation (EU) 2024/1689 (AI Act), as adopted — EUR-Lex
  4. LegislationRegulation (EU) 2026/1744 (Digital Omnibus on AI) — EUR-Lex
  5. Official faqEuropean Commission — Timeline for the implementation of the EU AI Act
  6. Regulator pageEuropean Commission — Regulatory framework for AI
  7. LegislationCommission Implementing Decision (EU) 2021/914 (standard contractual clauses)
  8. Regulator guidanceEDPB Opinion 28/2024 on data protection aspects of AI models
  9. LegislationBundesdatenschutzgesetz § 26 — gesetze-im-internet.de
  10. LegislationBetriebsverfassungsgesetz § 87 — gesetze-im-internet.de
  11. LegislationBetriebsverfassungsgesetz § 90 — gesetze-im-internet.de

02Regulations and guidance

8 instruments
InstrumentStatus
BetrVG § 87Where no statutory or collective rule applies, the works council co-determines listed matters. Number 6 covers the introduction and use of technical devices designed to monitor the behaviour or performance of employees. If no agreement is reached, a conciliation board decides and its award replaces the agreement.In force
BetrVG § 90The employer must inform the works council in good time, with the necessary documents, about planning of working procedures and workflows including the use of artificial intelligence, and must consult on the intended measures and their effects early enough for the council’s suggestions and concerns to be taken into account.In force
BDSG § 26The German provision on processing employee data. Processing is permitted where necessary for a decision on entering into, performing or ending an employment relationship. Consent in an employment relationship is subject to conditions, collective agreements are an available basis, and the participation rights of employee representatives are expressly preserved.In force
EU SCCsThe Commission’s standard contractual clauses for transferring personal data to third countries under Article 46(1) and (2)(c) GDPR. Built as general clauses plus modules for controller-to-controller, controller-to-processor, processor-to-processor and processor-to-controller transfers; the right module has to be chosen for the actual relationship.In force
EDPB Opinion 28/2024European Data Protection Board opinion, requested under Article 64(2) GDPR, on when an AI model can be considered anonymous, on legitimate interest as a basis for developing and deploying AI models, and on the consequences of unlawful processing during development. It is an opinion, not a binding instrument.In force
GDPRThe EU’s general data protection regulation. For AI deployments the operative articles are 5 and 6 (principles and lawful basis), 9 (special categories), 13 and 14 (information), 22 (automated individual decision-making), 28 (processors), 32 (security), 35 (data protection impact assessment) and Chapter V (transfers to third countries).In force
EU AI ActThe EU’s horizontal AI regulation, applying by risk class. Annex III point 4 covers employment, worker management and access to self-employment, including systems used to recruit or select people and to evaluate candidates. Chapter III Sections 1 to 3, which carry the high-risk obligations, now apply from 2 December 2027 for Annex III systems.Partly in force
Digital Omnibus on AIAmends the AI Act and two product regulations to simplify implementation. Its effect on planning is the timetable: the high-risk rules in Chapter III Sections 1 to 3 move to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, and new prohibitions and an Article 50(2) transition arrive on 2 December 2026.In force

03Common enterprise issues

5
  • High-risk AI

    Recruitment screening is an Annex III high-risk use

    Filtering applications or scoring candidates falls in Annex III point 4. The deployer obligations apply from 2 December 2027, which means the design decision is being made now under rules that are known but not yet enforceable — the wrong time to build something that cannot be retrofitted.

  • Automated decision-making

    Article 22 bites before the AI Act does

    A shortlisting system that rejects candidates without meaningful human involvement can engage Article 22 today. The AI Act timetable does not postpone the GDPR.

  • Cross-border transfers

    The model API call is the transfer

    Teams document the SaaS contract and miss the inference hop. Establish where prompts are processed and where they are logged, and get both into the transfer analysis.

  • Logging

    German works councils co-determine monitoring-capable systems

    Introducing a technical device suited to monitoring employee behaviour or performance engages BetrVG § 87(1) no. 6, and § 90 requires the works council to be informed about planning that includes the use of artificial intelligence. Roll-out without an agreement is a common and avoidable stall.

  • Model training

    Whether the vendor trains on your data, in writing

    A marketing page is not a commitment. The answer belongs in the DPA or an order form, with the retention period and the opt-out mechanism named.


04Vendor restrictions

2

Restrictions we have written down and the page each one must be checked against. A restriction becomes a verified claim only once the sync job has fetched that page and found the phrase it declares; until then it is an editorial note with a link, and says so.

  • Mistral AIclaim pending review

    Mistral offers regional inference through dedicated endpoints, with the European Union as one of two available geographies. If EU processing matters, it has to be selected and evidenced — the default endpoint is not the regional one.

    Page to verify against

  • Microsoftclaim pending review

    Azure model availability differs by region, and a model you can buy in one European region may not exist in another. Confirm the specific model in the specific region before writing it into an architecture.

    Page to verify against


05Stacks with notes for this jurisdiction

0

No published stack carries a compliance note for this jurisdiction yet.


06Evidence

0 records · 0 of 8 instruments

Every instrument above that we have fetched and anchored carries a footnote. The rest link to their primary source but have not been fetched and hashed yet, and are marked ASSESSMENT rather than FACT.

No sources were recorded for this answer. Nothing on this page should be treated as verified.

Improve this page

Sign in to contribute

From the field

0 deployments · 0 questions

Nobody has reported deploying this here yet, and no question has been opened against this page. Both appear once a reviewer accepts them.