How to make sure your AI agency is GDPR compliant
When an AI agency processes your data, GDPR responsibility is shared — so check before you sign: require a signed data processing agreement, confirm the lawful basis and where data is stored, get explicit terms on whether your data trains models, and confirm data minimisation, security, and support for data subject rights. Put it in the contract, not in conversation.
General information for buyers, not legal advice. Confirm your specific obligations with qualified counsel.
You remain accountable for personal data even when an agency processes it for you. These are the checks that keep that accountability from becoming a liability.
A signed data processing agreement (DPA)
Sets out what data is processed, why, how it's protected, and each side's responsibilities. If the agency processes personal data for you, this is the baseline document.
Clear lawful basis
Be clear on the lawful basis for the processing (consent, legitimate interest, contract, etc.) and that the agency's handling stays within it.
Data location and transfers
Know where your data is stored and processed. Cross-border transfers outside the EEA carry extra requirements — confirm they're handled.
Explicit terms on model training
State whether your data, and data derived from it, can be used to train or improve models. Silence here is a risk; make it explicit.
Data minimisation and retention
The agency should collect only what's needed and delete it when it's no longer required. Agree retention periods.
Security and access controls
Encryption, access limited to those who need it, and a clear process if there's a breach.
Support for data subject rights
You must be able to fulfil access, deletion and correction requests. Confirm the agency can support these on the data it holds.
Where GDPR fits with the AI Act
GDPR governs personal data; the EU AI Act governs AI systems and their risks. Most projects touch both — see EU AI Act vs GDPR for how they differ, and what the EU AI Act means when you're buying AI. Fold both into the same Statement of Work.
Agencies built for European data rules
NorthBridge AI is built for European enterprise — agencies are vetted and each engagement runs on a Statement of Work where data-handling and GDPR terms can be set out clearly. See how it works.
Frequently asked questions
How do I make sure an AI agency is GDPR compliant?
Require a written data processing agreement (DPA), confirm where your data is stored and processed, establish the lawful basis for the processing, and get explicit terms on whether your data is used to train models. Check the agency applies data minimisation, has security and access controls, and can support data subject rights. Put these in the contract rather than relying on verbal assurance. This is general information, not legal advice — confirm your obligations with qualified counsel.
Do I need a data processing agreement with an AI agency?
Almost always, yes. If the agency processes personal data on your behalf, GDPR generally requires a data processing agreement (DPA) that sets out the scope, purpose, security measures and each party's responsibilities. An agency that handles personal data professionally should already have a DPA and be ready to sign one.
Can an AI agency use my data to train its models?
Only if your agreement permits it. This is one of the most important things to pin down: state explicitly whether your data — and any data derived from it — may be used to train or improve models, for you or for anyone else. If you don't want your data feeding a shared or future model, the contract must say so.
Hire agencies ready for GDPR
Vetted agencies and clear, contractual data terms on NorthBridge AI.
Browse verified agencies