Jurisdiction
European Union
- Source
- Editorial review of primary sources — not yet re-anchored
- Verified
- Evidence not verified
- Confidence
- Low
Structured issue-spotting to support your own review — not legal advice. Verify against the cited primary sources and your counsel.
01Framework
The EU regulates personal data under the GDPR and AI under Regulation (EU) 2024/1689, the AI Act. The AI Act applies in stages: prohibitions since 2 February 2025, general-purpose AI and governance since 2 August 2025, general application since 2 August 2026. Regulation (EU) 2026/1744, in force since 27 July 2026, moved the high-risk obligations to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I. Member State law adds to both — in Germany, employee data protection and works-council co-determination usually bind before either regulation does.
- Region
- Europe
- ISO code
- EU
- Privacy framework
- Regulation (EU) 2016/679 (GDPR). Directly applicable in every Member State and unamended as of the review date. An AI deployment engages Articles 5 and 6 on principles and lawful basis, 9 on special categories, 13 and 14 on information, 22 on decisions based solely on automated processing, 28 on processors, 32 on security, 35 on impact assessments and Chapter V on transfers out of the EEA. Member States retain room to legislate on employment, which is where Germany’s BDSG § 26 comes in.
- AI-specific rules
- The AI Act classifies systems by risk. Annex III point 4 makes AI used to recruit or select people, to evaluate candidates, to decide on terms of employment or promotion, or to monitor and evaluate performance, a high-risk class — and the deployer, not just the provider, carries obligations. Those obligations now apply from 2 December 2027 rather than 2 August 2026, because Regulation (EU) 2026/1744 moved them. Prohibitions, AI literacy, general-purpose AI duties, governance and the Article 50 transparency duties are already applicable. Two new prohibitions and an Article 50(2) transition arrive on 2 December 2026. On the data protection side, EDPB Opinion 28/2024 addresses when an AI model can be treated as anonymous and when legitimate interest supports developing or deploying one.
- Last reviewed
- 20 Aug 2026
- Status
- published
Cross-border transfer
Chapter V GDPR governs transfers to third countries. Without an adequacy decision the usual route is the Commission’s standard contractual clauses under Decision (EU) 2021/914, with the module matched to the actual relationship and a transfer impact assessment behind it. For an AI deployment the transfer is often invisible in the architecture diagram: a model API call, an evaluation pipeline, a support tunnel, or a subprocessor two layers down. Ask where inference runs, where logs are retained, and where support staff sit — three different answers are common. Where a vendor offers a regional endpoint it usually has to be selected explicitly; the default endpoint is rarely the regional one.
Regulators
Primary sources
- LegislationRegulation (EU) 2016/679 (GDPR) — EUR-Lex
- LegislationRegulation (EU) 2024/1689 (AI Act), consolidated to 27 July 2026 — EUR-Lex
- LegislationRegulation (EU) 2024/1689 (AI Act), as adopted — EUR-Lex
- LegislationRegulation (EU) 2026/1744 (Digital Omnibus on AI) — EUR-Lex
- Official faqEuropean Commission — Timeline for the implementation of the EU AI Act
- Regulator pageEuropean Commission — Regulatory framework for AI
- LegislationCommission Implementing Decision (EU) 2021/914 (standard contractual clauses)
- Regulator guidanceEDPB Opinion 28/2024 on data protection aspects of AI models
- LegislationBundesdatenschutzgesetz § 26 — gesetze-im-internet.de
- LegislationBetriebsverfassungsgesetz § 87 — gesetze-im-internet.de
- LegislationBetriebsverfassungsgesetz § 90 — gesetze-im-internet.de
02Regulations and guidance
| Instrument | Status |
|---|---|
| BetrVG § 87Where no statutory or collective rule applies, the works council co-determines listed matters. Number 6 covers the introduction and use of technical devices designed to monitor the behaviour or performance of employees. If no agreement is reached, a conciliation board decides and its award replaces the agreement. | In force |
| BetrVG § 90The employer must inform the works council in good time, with the necessary documents, about planning of working procedures and workflows including the use of artificial intelligence, and must consult on the intended measures and their effects early enough for the council’s suggestions and concerns to be taken into account. | In force |
| BDSG § 26The German provision on processing employee data. Processing is permitted where necessary for a decision on entering into, performing or ending an employment relationship. Consent in an employment relationship is subject to conditions, collective agreements are an available basis, and the participation rights of employee representatives are expressly preserved. | In force |
| EU SCCsThe Commission’s standard contractual clauses for transferring personal data to third countries under Article 46(1) and (2)(c) GDPR. Built as general clauses plus modules for controller-to-controller, controller-to-processor, processor-to-processor and processor-to-controller transfers; the right module has to be chosen for the actual relationship. | In force |
| EDPB Opinion 28/2024European Data Protection Board opinion, requested under Article 64(2) GDPR, on when an AI model can be considered anonymous, on legitimate interest as a basis for developing and deploying AI models, and on the consequences of unlawful processing during development. It is an opinion, not a binding instrument. | In force |
| GDPRThe EU’s general data protection regulation. For AI deployments the operative articles are 5 and 6 (principles and lawful basis), 9 (special categories), 13 and 14 (information), 22 (automated individual decision-making), 28 (processors), 32 (security), 35 (data protection impact assessment) and Chapter V (transfers to third countries). | In force |
| EU AI ActThe EU’s horizontal AI regulation, applying by risk class. Annex III point 4 covers employment, worker management and access to self-employment, including systems used to recruit or select people and to evaluate candidates. Chapter III Sections 1 to 3, which carry the high-risk obligations, now apply from 2 December 2027 for Annex III systems. | Partly in force |
| Digital Omnibus on AIAmends the AI Act and two product regulations to simplify implementation. Its effect on planning is the timetable: the high-risk rules in Chapter III Sections 1 to 3 move to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, and new prohibitions and an Article 50(2) transition arrive on 2 December 2026. | In force |
03Common enterprise issues
High-risk AI
Recruitment screening is an Annex III high-risk use
Filtering applications or scoring candidates falls in Annex III point 4. The deployer obligations apply from 2 December 2027, which means the design decision is being made now under rules that are known but not yet enforceable — the wrong time to build something that cannot be retrofitted.
Automated decision-making
Article 22 bites before the AI Act does
A shortlisting system that rejects candidates without meaningful human involvement can engage Article 22 today. The AI Act timetable does not postpone the GDPR.
Cross-border transfers
The model API call is the transfer
Teams document the SaaS contract and miss the inference hop. Establish where prompts are processed and where they are logged, and get both into the transfer analysis.
Logging
German works councils co-determine monitoring-capable systems
Introducing a technical device suited to monitoring employee behaviour or performance engages BetrVG § 87(1) no. 6, and § 90 requires the works council to be informed about planning that includes the use of artificial intelligence. Roll-out without an agreement is a common and avoidable stall.
Model training
Whether the vendor trains on your data, in writing
A marketing page is not a commitment. The answer belongs in the DPA or an order form, with the retention period and the opt-out mechanism named.
04Vendor restrictions
Restrictions we have written down and the page each one must be checked against. A restriction becomes a verified claim only once the sync job has fetched that page and found the phrase it declares; until then it is an editorial note with a link, and says so.
Mistral AIclaim pending review
Mistral offers regional inference through dedicated endpoints, with the European Union as one of two available geographies. If EU processing matters, it has to be selected and evidenced — the default endpoint is not the regional one.
Microsoftclaim pending review
Azure model availability differs by region, and a model you can buy in one European region may not exist in another. Confirm the specific model in the specific region before writing it into an architecture.
05Stacks with notes for this jurisdiction
No published stack carries a compliance note for this jurisdiction yet.
06Evidence
Every instrument above that we have fetched and anchored carries a footnote. The rest link to their primary source but have not been fetched and hashed yet, and are marked ASSESSMENT rather than FACT.
No sources were recorded for this answer. Nothing on this page should be treated as verified.
Improve this page
Sign in to contribute
From the field
0 deployments · 0 questions
Nobody has reported deploying this here yet, and no question has been opened against this page. Both appear once a reviewer accepts them.