AI incidents and GDPR
The General Data Protection Regulation (EU) 2016/679 governs the processing of personal data of people in the European Union and European Economic Area. It has applied since 25 May 2018 and is enforced by national data protection authorities.
For AI systems, the provisions most often cited include lawful basis for processing (Article 6), transparency (Articles 12 to 14), automated decision-making (Article 22) and data protection by design (Article 25).
Confirmed regulatory enforcement
Regulator or court findingA regulator, court, or authority has issued a decision, order, or fine citing GDPR. Regulation-level filtering is not yet available, so this shows recent incidents across the full index instead.
Potential relevance
Relevant regulatory contextThe incident may involve a GDPR regulated context, but no authority has made a finding. Inclusion does not indicate a determination of legal relevance.