Before implementing an AI tool, check whether it complies with GDPR requirements
The Personal Data Protection Office presents a set of initial questions that should be considered before deciding to develop or use artificial intelligence systems. The questions do not replace a risk analysis, a data protection impact assessment, or an assessment of the impact on fundamental rights, but they provide a good starting point for conducting such analyses. They do not constitute a binding interpretation of the law and do not determine whether a given solution complies with the GDPR. There is no need to submit the answers to these questions to the supervisory authority.
A study of organisations’ needs, conducted by the Social Team of Experts operating under the President of the Personal Data Protection Office (UODO), showed that between 41% and 58.5% of entities do not perceive a connection between artificial intelligence (AI) tools and the processing of personal data. At the same time, as many as 95.9% do not consider themselves prepared to implement AI in compliance with the GDPR. The question of compliance is usually raised when the tool is already operational, while decisions concerning the data to be used and the provider have already been made. The purpose of the questions published below is to encourage organisations to consider these issues before launching an AI system.
The Polish SA has prepared four sets of questions tailored to specific groups and stages of AI implementation. The first is dedicated to small and medium-sized enterprises that use ready-made AI systems. Such organisations therefore do not go through the model training stage and generally do not have extensive legal expertise. The second set of questions is intended for public-sector entities and takes into account the principle of legality and the rules of administrative procedure. Version 0 is aimed at organisations that do not fall into either of the above groups, including those developing or further training their own AI models.
The Extended Version, on the other hand, is common to all of the above-mentioned entities. It takes into account not only the GDPR but also highlights obligations arising from the AI Act, including risk classification and an assessment of the impact on fundamental rights. It should be completed when the initial checklist identifies the circumstances described in the Extended Version, in particular the development or further training of a model or an impact on the legal situation of individuals.
The checklists were prepared by Professor Dominik Lubasz, PhD, habilitated doctor at the University of Łódź, with the support of the other members of the Social Team of Experts and experts from the Personal Data Protection Office. We encourage you to provide the full document, or the section relevant to the recipient, to data protection officers and to individuals responsible for procurement and technological implementation.
Until 30 September 2026, comments and experiences concerning the use of the checklists may be sent to pytania_inicjalne@uodo.gov.pl. They will be taken into account when updating the materials presented above.