In 2018, the GDPR was everywhere. Organisations mapped, documented, tidied up and brought in external help. Then the deadline passed. Projects ended, documents were archived and attention moved on.

That was understandable. But it also created a comforting impression that the GDPR was something we had completed.

AI is now exposing the problem with that way of thinking. When an agent gains access to SharePoint, a CRM system or customer service, earlier decisions about purpose, access and retention suddenly become part of a new workflow. Privacy is not an appendix to the AI project. It is a property of the solution we are building.

In brief

  • The time when the GDPR could be treated as a self-contained consulting project is over.
  • The AI Act does not replace the GDPR. The regulations serve different purposes and must be applied together when AI processes personal data.
  • A short GDPR refresher should be mandatory for anyone using AI with organisational data. Project managers and implementation leads need greater depth.

The consulting wave did its job – and left a problem behind

The GDPR wave prompted organisations to act. It put privacy on the leadership agenda and forced a clearer view of data, suppliers and accountability. That was necessary.

But the project format had a downside. When the work was organised around a start date, a project manager and a list of deliverables, it became easy to assume that the job also had an end date. Many organisations completed the documentation without making privacy a natural part of product development, procurement and changes to work processes.

In my view, the era of the standalone GDPR project is over. Good privacy practice cannot be outsourced as a bundle of documents. It must be owned by the people who decide how the work is actually done.

A consultant can help with direction and difficult assessments. The organisation must own the day-to-day practice.

The AI Act does not cover everything

The AI Act became generally applicable on 2 August 2026, with important exceptions and later deadlines for parts of the rules on high-risk systems. The new regulation deserves attention. It provides a risk-based framework for certain AI systems, introduces requirements including transparency, and allocates responsibility between providers and deployers.

But the AI Act is not a new data protection regulation.

The European Data Protection Board is clear that the AI Act and EU data protection law should be understood as complementary and mutually reinforcing. The GDPR continues to apply fully when personal data is processed throughout the lifecycle of an AI system.

Low AI risk does not mean low privacy risk

An AI tool may be classified as minimal or low risk under the AI Act and still raise difficult GDPR questions: Do we have a lawful basis? Are we using the data for a new purpose? Is the amount of data necessary? Who can access the result, and how long is it retained?

I will return to the AI Act in a separate review. It deserves its own map, not a footnote in a GDPR article.

AI moves the GDPR into the workflow

Generative AI affects privacy differently from many traditional system procurements. The technology does not simply arrive as one new database. It sits across existing work surfaces and is used to search, summarise, assess, write and suggest actions.

This creates value, but it also changes how personal data is processed:

  • Meetings: A transcript becomes a summary with tasks and assessments.
  • Customers: A customer history becomes the basis for a suggested next action.
  • HR: Documents become searchable through a conversational interface.
  • Agents: Information from several systems is combined and passed on.
  • Access: An old document gains a new audience because it is easier to find.

None of these examples is necessarily unlawful. But they show why “we already have access” is not a sufficient assessment. Access, purpose and necessity must be considered in the new workflow, not only in the system where the data was originally stored.

Three questions leaders should ask

Before an organisation scales an AI solution, I would start with three questions:

From data to accountability

Assess the entire workflow

What goes in?

Map sources, categories and access, and assess whether the solution may retrieve more than the user expects.

What is the new purpose?

Summarisation may fall within the original purpose. Profiling, ranking or new decision support may require a different assessment.

What happens to the result?

Clarify controls, retention, sharing, deletion and who is accountable when the AI output is used further.

These questions should not sit with legal counsel alone. They must be answered by leaders, project owners, subject-matter experts, security teams and the people who understand the work process.

Access, purpose and necessity must be assessed in the new workflow – not only in the system where the data was stored.

A refresher should be mandatory

I believe everyone who uses AI with organisational data should receive a short GDPR refresher. Not another full-day seminar on legal provisions, but a practical minimum: What is personal data? What do purpose limitation and data minimisation mean? When should I stop and ask for help?

Those who lead implementation or development need more. They must understand privacy risk, DPIAs, data protection by design, data mapping, lawful bases, and how decisions are documented and followed up throughout the project.

That is why I have brought back and relaunched two earlier GDPR courses. Both are updated, free and available without registration or login:

For implementation leads

GDPR for project managers

Go deeper into risk, DPIAs, data protection by design, data mapping and operational compliance.

Go to the in-depth course

Some people should take both. The foundation course creates shared language. The advanced course shows how the principles are built into solutions and work processes.

The GDPR matters again – because work is changing

The most interesting part of today’s AI wave is not only what the technology can do. It is how it shifts boundaries between systems, roles and decisions. Information becomes easier to find, combine and use in new ways. Work processes that were previously manual can become partly automated.

It is not enough to point to a privacy policy or assume that the AI Act takes care of the rest. The organisation must understand what actually happens to the data in the specific workflow.

The GDPR does not need another consulting boom. It needs a new place in the conversation – closer to leadership, projects and everyday decisions. A refresher is a small place to begin. What matters is that privacy becomes part of how we build better work.