1Legal bases and impact assessment
Every processing activity needs a legal basis art. 6: consent, contract, legal obligation, vital interest, public interest task, or legitimate interest (weighed against individuals' rights — but not available to public authorities for the performance of their tasks).
When processing is likely to result in a high risk (new technologies, large-scale profiling, sensitive data…), a DPIA (Data Protection Impact Assessment, art. 35) is mandatory — a high-risk AI system triggers it almost every time.
2Roles and DPO independence
Controller (determines purposes and means) vs processor (acts on behalf of, and under the instructions of, the controller) art. 28. This qualification determines who is accountable for what.
The DPO advises, monitors compliance, is the point of contact for the authority and for individuals, and raises awareness. They carry out their duties in full independence, free of conflicts of interest, report to the highest level of management, and cannot be penalized for performing their functions. They advise and monitor — they do not decide on processing activities: responsibility for compliance remains with the controller (accountability). Their appointment is mandatory in certain cases art. 37: public authority or body, large-scale systematic monitoring, or large-scale processing of sensitive data.
3Practical obligations and individuals' rights
Consent and rights
When used as the basis, consent must be freely given, specific, informed and unambiguous (and revocable). Individuals have rights: access, rectification, erasure (under conditions), objection, portability — but not a "right to demand a perfect model."
The building blocks of accountability
- Register of processing activities art. 30: lists the processing activities — a key tool for demonstrating compliance.
- DPIA art. 35: description of the processing, risk assessment for individuals, mitigation measures — mandatory in case of high risk.
- Breach notification: to the authority within 72 hours of becoming aware, if the breach presents a risk.