---------------------------
Title: GDPR for AI Training Data: Legal Bases and Compliance Checklist
URL: https://www.cookiebot.com/en/ai-gdpr/
---------------------------

# GDPR for AI Training Data: Legal Bases and Compliance Checklist

Whether it’s public or proprietary, the customer data you use to train AI tools falls under the scope of the GDPR. This guide covers the legal bases for training data and provides a checklist to work through before you deploy.

## At a Glance

- The GDPR covers the whole AI data lifecycle, from training through output, and it treats IP addresses and other online identifiers as personal data.
- You need a documented legal basis before processing personal data for AI training, with consent, legitimate interest, and contractual obligations being the main options.
- Publicly available or scraped data is not exempt, and high-risk AI processing also calls for a Data Protection Impact Assessment.
- Cookiebot can help provide the foundation for compliance by capturing documented consent and keeping audit-ready records before data feeds any AI workflows.

Imagine you’re building a support chatbot. You already have years of help desk tickets with thousands of real questions and answers. This is ideal material to train on, so you export all of it and feed it to a model.

But those tickets are full of personal data, like names, email addresses, and phone numbers. And, depending on what business you’re in, potentially personal data that’s even more sensitive.

If you have EU-based customers, the [General Data Protection Regulation (GDPR)](/en/gdpr/) applies the moment all of that goes into training, regardless of whether you built the chatbot yourself or you're using a vendor's tool.

The GDPR defines data processing very broadly, but it applies to every stage of an AI data lifecycle. This includes sourcing your training data, building the model, and running it in production.

The regulation’s requirements get clearer once you break them down stage by stage, which is what this guide does. It covers how the GDPR treats AI training data, which legal bases you can rely on when you source it, and a checklist to work through when working with personal data and AI tools.

## Does The GDPR Apply to AI Training Data?

## AI lifecycle stages

- **When the GDPR applies to data:**
    - Collection
    - Training
    - Inference
    - Output
- Before anything enters a training set, ask: **Could this data point be traced back to an individual?**
- If yes, **the GDPR treats it as personal data.**

The GDPR applies whenever the personal data of people located in the EU/EEA is processed as part of an AI system. This covers the entire lifecycle: collection, training, inference, and output.

[Art. 4 GDPR](https://gdpr.eu/article-4-definitions/) defines processing so broadly that almost any operation using personal data falls under the rules, from the first export of a training dataset to the model's responses in production.

The European Data Protection Board (EDPB) confirmed this in its[ Opinion 28/2024](https://www.edpb.europa.eu/our-work-tools/our-documents/opinion-board-art-64/opinion-282024-certain-data-protection-aspects_en), which addresses both the development and the deployment of AI models. A model trained on personal data won’t necessarily be exempt from the rules once training ends, since data can sometimes be extracted or inferred from it later.

The challenge for most teams is determining what exactly qualifies as personal data. Under Art. 4 GDPR, this reaches well beyond names and email addresses, extending to “an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.”

In an AI setting, that routinely includes:

- Behavioral logs such as clickstream, session, and usage data
- Prompt and conversation histories tied to a user or account
- IP addresses and other online identifiers, which [Recital 30](https://gdpr.eu/recital-30-online-identifiers-for-profiling-and-identification/) names as personal data
- Any field that, alone or combined with other data you hold, can be traced back to a person

Key takeaway: If a data point can be linked to an individual, the GDPR treats it as personal data. The question of "Could this potentially be traced back to someone?" is the one to run before anything goes into a training set.

### When Is a DPIA Required for AI Training Data?

[Art. 35 GDPR](https://gdpr.eu/article-35-impact-assessment/) requires a [Data Protection Impact Assessment (DPIA)](https://usercentrics.com/knowledge-hub/data-protection-impact-assessment-dpia/) before conducting any processing likely to cause high risk to individuals. Training data can definitely fit under this umbrella, especially when an AI system profiles individuals, processes personal data at scale, or requires special category data safeguards.

If your training data ticks any of these boxes, it’s best to assume you need a DPIA. Under the EU's Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since July 27, 2026), the deadline for Annex III high-risk AI obligations, including the Article 27 [fundamental rights impact assessment](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-27), has been pushed from August 2, 2026 to December 2, 2027.

### Is Publicly Available Data Exempt From GDPR Regulations on AI Training?

Public availability doesn’t take data outside the scope of the GDPR. If information relates to identifiable people, scraping it for AI training is still processing, and it still needs a lawful basis.

The Dutch DPA’s EUR 30.5 million [GDPR fine](/en/convictions-fines-warnings/) against[ Clearview AI](https://www.autoriteitpersoonsgegevens.nl/en/current/dutch-dpa-imposes-a-fine-on-clearview-because-of-illegal-data-collection-for-facial-recognition) made this clear. The American facial recognition platform was penalized for building a database from billions of publicly scraped images with no valid legal basis.

In another example, the Irish DPC [forced social media platform X](https://www.dataprotection.ie/en/news-media/press-releases/data-protection-commission-welcomes-conclusion-proceedings-relating-xs-ai-tool-grok) to stop feeding EU users' public posts to Grok for training and to delete that data.

## Not sure which laws apply to your website?

We can help. Use our free, interactive tool to determine which regulations apply to your business based on what your website is used for, traffic, where you do business, and more.

[Find My Regulations](https://www.cookiebot.com/en/regulations-finder/?step=1)

## What Legal Basis Can You Use for AI Training Data?

Before you process any personal data to train a model,[ Art. 6 GDPR](https://gdpr.eu/article-6-how-to-process-personal-data-legally/) requires you to identify and document a valid legal basis for doing so. And there’s no exception for AI training purposes.

For most AI training, four of the six legal bases are worth focusing on:

- Consent: Individuals actively agree to their data being used
- Legitimate interest: You rely on a documented balancing test
- Contractual necessity: The training is needed to deliver a service the person signed up for
- Legal obligation: The law requires you to process data

The rest of this section takes a closer look at each one and explains when it fits, what it requires, and where it tends to fall short for AI training.

But one rule cuts across all of them: you can’t swap legal bases after the fact, so identify and document your basis before processing starts. Deciding retroactively or switching after you start processing data won’t hold up under [GDPR compliance requirements](/en/gdpr-compliance-requirements-checklist/).

### Consent

Consent is the clearest basis to rely on, but it’s often the hardest to scale. When someone actively agrees to their data being used to train your model, the legal position is easy to explain and easy to defend.

But the GDPR has very specific guidelines around consent. Under Art. 4 GDPR, consent has to be freely given, specific, informed, and unambiguous.

For AI training, that means the purpose of the data processing has to be named at the point of collection. A general line in your terms of service about "improving our services" won’t cover it, and if you didn’t tell people their data would train an AI model when you collected it, that consent doesn’t stretch to cover this specific purpose.

Consent works best when the dataset is small and you have a direct relationship with the people in it, for example current customers who opt in to help improve a feature. It becomes impractical at scale or for historical data, where going back to thousands of people for specific, informed approval is rarely realistic.

### Legitimate interest

For most AI training, legitimate interest is the basis you’re most likely to rely on, and it’s the one the EDPB addressed most directly in [Opinion 28/2024](https://www.edpb.europa.eu/our-work-tools/our-documents/opinion-board-art-64/opinion-282024-certain-data-protection-aspects_en). This Opinion confirmed that legitimate interest under[ Art. 6(1)(f) GDPR](https://gdpr.eu/article-6-how-to-process-personal-data-legally/) can support both the development and the deployment of AI models, but it also made clear that the basis is never automatic.

To rely on it, you need to complete and document a three-step Legitimate Interest Assessment (LIA):

- Identify the interest: It has to be lawful, clearly defined, and real rather than speculative, e.g., building a chatbot to speed up customer support tickets.
- Show necessity: The processing has to be necessary to achieve that interest, with no less intrusive way to get there and no more data than the purpose requires.
- Balance it out: Weigh your interest against the data subjects’ rights and freedoms taking account of how they would reasonably expect you to handle their information.

The EDPB is explicit that you can’t assume legitimate interest as a default. And a documented LIA is the minimum requirement.

On top of that, you’re expected to apply mitigating measures like pseudonymization to reduce the impact on individuals, and to keep the [data subject's right](/en/gdpr-data-subject-rights/) to object available under [Art. 21 GDPR](https://gdpr.eu/article-21-right-to-object/). If people can’t realistically opt out, this basis doesn’t hold.

### Contractual Necessity and Legal Obligation

Two of the remaining bases may come up, but they’re not as likely to be used to justify data processing for AI training.

#### Contractual Necessity

This only covers processing that is necessary to deliver a specific service someone signed up for. The processing has to be genuinely required to perform the contract. Training a general model on customer data is almost never needed to deliver the service the customer paid for, so contract does not stretch to cover it.

#### Legal Obligation

This applies where a law requires you to process the data, such as tax or anti-money laundering rules. It is narrow by design, and commercial AI training is almost never something the law mandates, so this basis rarely applies.

## GDPR Compliance Checklist for AI Training Data

Now that you know how the GDPR applies to AI training data, you can start identifying compliance gaps in your organization. Use this list to audit your current AI data practices. Anything you can’t check off is a good place to focus first.

- Identify a valid legal basis for every AI training dataset
- Document a legal basis for each type of processing before processing begins
- Inform data subjects whenever their data may be used for AI training
- Apply data minimization principles and only collect and use what is strictly necessary
- Pseudonymize or anonymize training data as early as technically feasible
- Complete a Legitimate Interest Assessment (LIA) if relying on Art. 6(1)(f) GDPR
- Conduct a DPIA for high-risk AI processing activities
- Confirm that website consent for cookies and trackers covers AI training as a named purpose if relevant
- Implement a right-to-object/opt-out mechanism where legitimate interest is the legal basis
- Build processes for access, erasure, and objection requests relating to AI systems
- Review third-party AI vendors and confirm that Data Processing Agreements (DPAs) are in place
- Assess whether the EU AI Act applies to your AI system's risk tier

## How Cookiebot™ Helps You Build a Foundation for GDPR-Compliant AI Use

Most of the requirements in this guide begin at the point of collection. When the data feeding an AI workflow comes from your website and customers, you need a [consent management platform (CMP)](/en/cookie-consent-solution/) like Cookiebot™.

Cookiebot™ handles the consent layer for the cookies and trackers on your site, not the training data itself, so think of it as the first step that puts website-collected data on a lawful footing.

The tool scans your site and shows a consent banner that blocks non-essential cookies and trackers until a visitor makes a choice.

Each choice is recorded with a timestamp and what the visitor agreed to, so the consent behind your data has a clear, documented starting point. Cookiebot™ CMP keeps audit-ready consent logs you can export, which gives you the documentation regulators require without having to reconstruct it after the fact.

Getting the first consent collection step right is what supports everything downstream, from AI training to deployment.

## Put your AI training data on lawful ground

Cookiebot™ CMP collects informed consent from visitors to your site and keeps audit-ready records, supporting compliance for the website data feeding your AI models from day one.

[Start Free Trial](https://admin.cookiebot.com/signup)

## Preamble

Whether it’s public or proprietary, the customer data you use to train AI tools falls under the scope of the GDPR. This guide covers the legal bases for training data and provides a checklist to work through before you deploy.

## Summary

Whether it’s public or proprietary, the customer data you use to train AI tools falls under the scope of the GDPR. This guide covers the legal bases for training data and provides a checklist to work through before you deploy.

---

## Footer

### Products
- [Cookiebot™ Consent Solution](https://www.cookiebot.com/en/cookie-consent-solution/)
- [Audience Survey](https://www.cookiebot.com/en/audience-survey-add-on/)
- [Usercentrics for Wix](https://www.cookiebot.com/en/cookiebot-for-wix-by-usercentrics-app/)
- [Usercentrics Cookiebot WordPress Plugin](https://www.cookiebot.com/en/new-wp-cookie-plugin/)
- [Cookiebot CMP for Shopify](https://www.cookiebot.com/en/cookiebot-cmp-for-shopify/)
- [Cookie checker](https://www.cookiebot.com/en/cookie-checker/)
- [Usercentrics products](https://usercentrics.com/)
- [Pricing](https://www.cookiebot.com/en/pricing/)

### Regulations
- [DMA (EU)](https://www.cookiebot.com/en/digital-markets-act-dma/)
- [GDPR (EU)](https://www.cookiebot.com/en/?page_id=580)
- [CCPA (California)](https://www.cookiebot.com/en/what-is-ccpa/)
- [VCDPA (Virginia)](https://www.cookiebot.com/en/virginia-vcdpa/)
- [LGPD (Brazil)](https://www.cookiebot.com/en/lgpd/)
- [TCF v2.3 (IAB)](https://www.cookiebot.com/en/tcf/)
- [Google Consent Mode (EU)](https://www.cookiebot.com/en/cookiebot-cmp-google-consent-mode/)
- [Microsoft UET Consent Mode](https://www.cookiebot.com/en/microsoft-consent-mode-cmp/)
- [View all regulations](https://www.cookiebot.com/en/regulations-and-frameworks/)

### Partners
- [Become an affiliate](https://www.cookiebot.com/en/affiliates/)
- [Affiliate Login](https://app.impact.com/login.user)
- [Become a partner](https://www.cookiebot.com/en/resellers/)
- [Find a partner](https://www.cookiebot.com/en/cookiebot-reseller/)

### Resources
- [Blog](https://www.cookiebot.com/en/blog/)
- [Customer stories](https://www.cookiebot.com/en/customer-stories/)
- [Customer directory](https://www.cookiebot.com/en/cookiebot-customer-directory/)
- [Digital Markets Act Hub](https://www.cookiebot.com/en/digital-markets-act-dma-resources/)
- [Google Consent Mode Hub](https://www.cookiebot.com/en/google-consent-mode-resources/)
- [Google Consent Mode V2 certification](https://courses.usercentrics.com/course/google-consent-mode-v2)
- [Google Consent Audit Fixes](https://www.cookiebot.com/en/google-consent-audit-fixes/)
- [Cookie Banner Cost Calculator](https://www.cookiebot.com/en/cookie-banner-pricing-calculator/)

### Company
- [About us](https://www.cookiebot.com/en/about/)
- [Careers](https://usercentrics.com/career/)
- [Support](https://support.cookiebot.com/hc/en-us/)
- [Developer documentation](https://www.cookiebot.com/en/developer/)

©2026 Cookiebot. All rights reserved. Cookiebot is a trademark of     Usercentrics     A/S. Usercentrics A/S is registered in Denmark. Company reg. no.: 34624607. Do Not Sell or Share My Personal InformationData Subject RequestsManage Your Preferences

[Privacy Policy](https://www.cookiebot.com/en/privacy-policy/) · [Terms of Service](/en/terms-of-service/) · [Cookie Declaration](https://www.cookiebot.com/en/cookie-declaration/) · [Data Processing Agreement](https://www.cookiebot.com/en/data-processing-agreement/) · [Legal Notice](https://www.cookiebot.com/en/legal-notice/) · [Accessibility Statement](https://www.cookiebot.com/en/accessibility-statement-wcag-compliance/)