Praxikon

Guidelines

Generative AI and the EUDPR. Orientations for ensuring data protection compliance when using Generative AI systems (Version 2)

PublishedEDPS (European Data Protection Supervisor)28 Oct 2025

Revised version of the EDPS orientations on generative AI and personal data, primarily aimed at EU institutions under Regulation (EU) 2018/1725 but practically usable for any organisation. Covered are, amongst other things, determining roles and responsibilities in the chain, when use of a generative system processes personal data, the role of the data protection officer, when a DPIA is required, purpose limitation, data minimisation, accuracy, bias and automated decision-making. The EDPS provides these orientations explicitly in its role as data protection supervisor and not as market supervisor under the AI Act, and states that they leave the AI Act unaffected.

What this means for you

This is the most practical official checklist for organisations that deploy generative AI and must demonstrate that they have data protection law alongside the AI Act in order.