The GDPR and AI crossover begins whenever personal data is used to train, test, prompt, operate or evaluate an AI system. Personal data can be obvious, such as names, employee numbers or recordings. It can also be less obvious, such as location data, device identifiers or a combination of details that points to one person. Replacing a name with a code is pseudonymisation, not anonymisation, so the data will usually still be covered by GDPR (ICO, 2023). Practitioners should map the full data journey: what goes into the system, where it is stored, what the supplier can access, what the model produces and who acts on the output.
The seven UK GDPR principles provide a useful checklist: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. Before processing starts, the organisation needs a lawful basis under Article 6 (Carey, 2020). Consent is only one option and may not be suitable where people cannot freely say no. If AI uses special category data, an Article 9 condition is also required, and some conditions require an appropriate policy document under the Data Protection Act 2018 (ICO, 2024).
Special category data and protected characteristics are related, but they are not the same thing. Special category data is a GDPR term for sensitive personal information, such as health data, racial or ethnic origin, religious or philosophical beliefs, trade union membership, biometric data used for identification, and sexual orientation. Protected characteristics are the nine characteristics covered by the Equality Act 2010, including age, disability, sex, race, religion or belief and sexual orientation (ICO, 2024; Equality Act 2010; GOV.UK, nd). Some areas overlap, but practitioners should not treat one list as a substitute for the other. GDPR controls how personal data is processed, equality law addresses discrimination and unfair treatment.
High-risk AI processing should be assessed through a Data Protection Impact Assessment before use. This is especially important for extensive profiling, significant automated decisions, large-scale special category data or systematic monitoring. A DPIA should test necessity, proportionality, transparency, security, individual rights, bias and less intrusive alternatives (ICO, ns a). Following the 2025 reforms, more lawful bases may be available for significant solely automated decisions using ordinary personal data, but safeguards remain essential (ICO, 2025). Practitioners should make sure people are informed appropriately and have meaningful routes to question, challenge or request human review of significant outcomes.
Lawful use is the minimum standard; ethical use asks whether the activity is justified. Practitioners should avoid collecting data just because it is available, using public information in a way people would not expect, or uploading confidential records into unapproved tools. A useful leadership test is to ask: Who benefits? Who carries the risk? Could the same aim be achieved with less data? Have the people affected been considered or consulted? Supplier terms, international transfers, retention, deletion, access controls and breach routes should also be evidenced, not assumed.
Five indicators of algorithmic unfairness for practitioners to monitor:
- Historical bias: The data may accurately show what happened before, but past decisions may have been unfair or unequal (Barocas et al., 2023; NIST, 2022).
- Sampling bias: Some groups, locations or situations are missing or under-represented, so the system may work less well for them (Suresh and Guttag, 2021).
- Target or proxy bias: The chosen measure may not reflect the real goal, or a neutral-looking variable may stand in for a protected characteristic (Tschantz, 2022).
- Automation bias: Users may trust the system too quickly and fail to challenge weak or contradictory recommendations (Parasuraman and Riley, 1997).
- Aggregation bias: One model or rule may be applied to different groups even though their contexts, needs or risks differ (Barocas et al., 2023; Suresh and Guttag, 2021).
These indicators should be checked before deployment and monitored after launch. A system can look successful overall while producing poorer results for a smaller group. Practitioners should compare error rates and outcomes across relevant groups, investigate complaints and overrides, document limitations, and stop or redesign a system where risks cannot be reduced to an acceptable level (NIST, 2023).
Action Point
Choose one AI use case that uses personal data. Map its purpose, data sources, lawful basis, special category data, protected characteristics, supplier access and retention. Test it against the five unfairness indicators and identify where a person can challenge or request review of an outcome. Record one immediate safety improvement and the evidence that will show it has been completed.