A due-diligence framework for buyers assessing AI tools that process employee, customer, prospect or other personal data.
This is a procurement problem, not a technology problem
If you are choosing which AI tools your business can use, start with the companion guide on GDPR-friendly AI tools. This article covers the next step: the specific contractual and documentary checks to run before you sign.
The distinction matters because most AI procurement failures are not caused by picking a bad product. They are caused by signing standard terms, skipping the DPIA, and discovering eighteen months later that nobody can say where the data went.
The pre-contract checklist
1. Data Processing Agreement (Article 28)
Non-negotiable. Without a DPA you cannot lawfully engage a processor. Check it actually contains:
- Subject matter, duration, nature and purpose of processing
- Categories of personal data and data subjects
- Processor acts only on documented instructions
- Confidentiality obligations on personnel
- Security measures (Article 32)
- Sub-processor authorisation and notification of changes
- Assistance with data subject rights
- Assistance with breach notification, DPIAs and prior consultation
- Deletion or return of data at end of contract
- Audit and information rights
A vendor whose "DPA" is three paragraphs long has not done this properly.
2. Training and model improvement clauses
Read the actual words. Look for:
- Explicit statement that customer content is not used to train or improve models
- Whether that applies to all tiers or only some
- Whether "abuse monitoring" retains data, for how long, and who can view it
- Whether human review of content occurs, and under what circumstances
- Whether opt-out is default-on or requires a support ticket
Human review for safety purposes is common and often reasonable — but you need to know it happens, because it changes what you can honestly tell data subjects.
3. Data location and transfers
| What to establish | Why it matters |
|---|---|
| Processing location(s) | Determines whether a transfer occurs at all |
| Storage location(s) | Often different from processing location |
| Backup and DR locations | Frequently overlooked, and frequently in another region |
| Support access locations | Support staff in a third country is a transfer |
| Transfer mechanism | DPF certification, SCCs, or adequacy |
| Change notification | Can they move your data without telling you? |
4. Sub-processors
Get the current list, and check the contract gives you notice of additions with a right to object. AI vendors typically sit on top of a model provider, a cloud provider and often a vector database — the chain is longer than buyers expect and each link is a transfer question.
5. Retention and deletion
- Default retention period for prompts, outputs and logs
- Whether it is configurable, and to what minimum
- Deletion timeline on termination, including backups
- Whether deletion is verifiable
"We delete on request" without a stated timeline is not a control.
6. Security evidence
Ask for current attestations rather than claims: ISO 27001 certificate (check the scope statement — it often excludes the relevant service), SOC 2 Type II report, recent penetration test summary, and their own breach notification commitment timeline.
When you need a DPIA
A Data Protection Impact Assessment is mandatory where processing is likely to result in high risk. For AI deployments, that commonly includes:
- Systematic and extensive evaluation of people, including profiling, with legal or similarly significant effects
- Large-scale processing of special category data
- Systematic monitoring of a publicly accessible area
- Any AI use in recruitment, performance management or access to services
Recruitment and HR are the highest-risk category most businesses actually encounter, and they are also where the EU AI Act's high-risk obligations bite. If your AI purchase touches hiring, budget properly for the assessment.
Red flags in vendor responses
- "We're GDPR compliant" with no DPA offered
- Unwillingness to name sub-processors
- Data location described only as "the cloud" or "globally distributed"
- Training exclusion available only on request rather than contractually
- Certification claims without a certificate, or with a scope that excludes the product
- No breach notification timeline, or one longer than your own 72-hour obligation allows
- Terms that permit unilateral change of processing location
Documentation to retain
Whatever you buy, keep: the signed DPA, the transfer assessment, the DPIA if required, the ROPA entry, the sub-processor list as at signature, the security attestations, and a dated record of the configuration choices you made. If a regulator ever asks, the question will be what you decided and why — and a decision you cannot evidence is functionally a decision you did not make.
Frequently asked questions
The vendor says they are DPF-certified. Is that enough?
It provides a valid transfer mechanism if the certification genuinely covers the relevant entity and data type. Verify on the official Data Privacy Framework list rather than taking it on trust, and keep a dated copy.
Can we rely on the vendor's DPIA?
No. The DPIA is the controller's obligation and must reflect your specific use, data and context. A vendor template is useful input, not a substitute.
What if we are using AI features inside software we already own?
The same checks apply, and they are easy to miss because there is no new purchase event. Existing suppliers adding AI features is currently the most common route to unassessed AI processing.

