ComplianceEuropeCybersecurity, Privacy & Compliance

GDPR-Compliant AI Tools: What Buyers Should Check

A due-diligence framework for buyers assessing AI tools that process employee, customer, prospect or other personal data.

MENTARA Editorial
On this page
Quick orientationCybersecurity, Privacy & Compliance

A due-diligence framework for buyers assessing AI tools that process employee, customer, prospect or other personal data.

GDPRAI GovernanceVendor RiskEurope

This is a procurement problem, not a technology problem

If you are choosing which AI tools your business can use, start with the companion guide on GDPR-friendly AI tools. This article covers the next step: the specific contractual and documentary checks to run before you sign.

The distinction matters because most AI procurement failures are not caused by picking a bad product. They are caused by signing standard terms, skipping the DPIA, and discovering eighteen months later that nobody can say where the data went.

The pre-contract checklist

1. Data Processing Agreement (Article 28)

Non-negotiable. Without a DPA you cannot lawfully engage a processor. Check it actually contains:

  • Subject matter, duration, nature and purpose of processing
  • Categories of personal data and data subjects
  • Processor acts only on documented instructions
  • Confidentiality obligations on personnel
  • Security measures (Article 32)
  • Sub-processor authorisation and notification of changes
  • Assistance with data subject rights
  • Assistance with breach notification, DPIAs and prior consultation
  • Deletion or return of data at end of contract
  • Audit and information rights

A vendor whose "DPA" is three paragraphs long has not done this properly.

2. Training and model improvement clauses

Read the actual words. Look for:

  • Explicit statement that customer content is not used to train or improve models
  • Whether that applies to all tiers or only some
  • Whether "abuse monitoring" retains data, for how long, and who can view it
  • Whether human review of content occurs, and under what circumstances
  • Whether opt-out is default-on or requires a support ticket

Human review for safety purposes is common and often reasonable — but you need to know it happens, because it changes what you can honestly tell data subjects.

3. Data location and transfers

What to establishWhy it matters
Processing location(s)Determines whether a transfer occurs at all
Storage location(s)Often different from processing location
Backup and DR locationsFrequently overlooked, and frequently in another region
Support access locationsSupport staff in a third country is a transfer
Transfer mechanismDPF certification, SCCs, or adequacy
Change notificationCan they move your data without telling you?

4. Sub-processors

Get the current list, and check the contract gives you notice of additions with a right to object. AI vendors typically sit on top of a model provider, a cloud provider and often a vector database — the chain is longer than buyers expect and each link is a transfer question.

5. Retention and deletion

  • Default retention period for prompts, outputs and logs
  • Whether it is configurable, and to what minimum
  • Deletion timeline on termination, including backups
  • Whether deletion is verifiable

"We delete on request" without a stated timeline is not a control.

6. Security evidence

Ask for current attestations rather than claims: ISO 27001 certificate (check the scope statement — it often excludes the relevant service), SOC 2 Type II report, recent penetration test summary, and their own breach notification commitment timeline.

When you need a DPIA

A Data Protection Impact Assessment is mandatory where processing is likely to result in high risk. For AI deployments, that commonly includes:

  • Systematic and extensive evaluation of people, including profiling, with legal or similarly significant effects
  • Large-scale processing of special category data
  • Systematic monitoring of a publicly accessible area
  • Any AI use in recruitment, performance management or access to services

Recruitment and HR are the highest-risk category most businesses actually encounter, and they are also where the EU AI Act's high-risk obligations bite. If your AI purchase touches hiring, budget properly for the assessment.

Red flags in vendor responses

  • "We're GDPR compliant" with no DPA offered
  • Unwillingness to name sub-processors
  • Data location described only as "the cloud" or "globally distributed"
  • Training exclusion available only on request rather than contractually
  • Certification claims without a certificate, or with a scope that excludes the product
  • No breach notification timeline, or one longer than your own 72-hour obligation allows
  • Terms that permit unilateral change of processing location

Documentation to retain

Whatever you buy, keep: the signed DPA, the transfer assessment, the DPIA if required, the ROPA entry, the sub-processor list as at signature, the security attestations, and a dated record of the configuration choices you made. If a regulator ever asks, the question will be what you decided and why — and a decision you cannot evidence is functionally a decision you did not make.

Frequently asked questions

The vendor says they are DPF-certified. Is that enough?

It provides a valid transfer mechanism if the certification genuinely covers the relevant entity and data type. Verify on the official Data Privacy Framework list rather than taking it on trust, and keep a dated copy.

Can we rely on the vendor's DPIA?

No. The DPIA is the controller's obligation and must reflect your specific use, data and context. A vendor template is useful input, not a substitute.

What if we are using AI features inside software we already own?

The same checks apply, and they are easy to miss because there is no new purchase event. Existing suppliers adding AI features is currently the most common route to unassessed AI processing.

Further reading

Security and governance

Discuss your security and governance requirements.

MENTARA can help structure technology implementation and delivery requirements without claiming legal or regulated advisory services.

Discuss the requirement
Weekly briefing

Enterprise technology intelligence, delivered weekly.

AI, cyber security, cloud, enterprise software and technology workforce guidance.

New guides and comparisons, no more than weekly.