Skip to main content

CKT

Using AI in Business: Key Legal Lessons from the Data Protection Commission’s AI Insights Report

Artificial intelligence (AI) is becoming an increasingly common part of business operations. Organisations use generative AI and other AI systems to draft and summarise documents, analyse data, communicate with clients, support recruitment, deliver services and assist with decision making.

While AI can improve productivity and efficiency, its use may create legal and regulatory obligations, particularly where personal data is involved. Organisations must consider not only what an AI tool can do, but whether its use complies with data protection law and the wider European legal framework governing AI.

On 24 September 2026, the Data Protection Commission (DPC), Ireland’s data protection regulator, published its AI Insights Report, titled “Responsible Artificial Intelligence Innovation: Insights from the Data Protection Commission’s Supervision of AI (2021 to 2025)” (Report). The Report provides useful insight into the DPC’s approach to supervising the development, training and deployment of AI systems. In this article, Amy McNicholas of CKT’s Employment Law Team examine the key legal lessons for organisations using AI, including lawful basis, transparency, data minimisation, confidentiality and human oversight.

What does the Report tell us?

Between 2021 and 2025, the DPC engaged with organisations concerning approximately 180 AI products and services. These included Large Language Models (LLMs), recommender systems, facial recognition technology, age assurance systems, personalisation tools and AI agents.

The Report confirms that innovation and data protection compliance are not mutually exclusive. However, it also makes clear that the DPC is prepared to intervene where organisations do not adequately address risks to individuals’ rights.

The DPC identifies transparency, lawful basis, legitimate interests, the right to object, data minimisation, the protection of children and automated decision making as key areas of concern. While much of the Report concerns organisations developing AI systems, its findings are equally relevant to organisations using commercially available AI tools.

How does data protection law apply?

The General Data Protection Regulation (GDPR) applies where personal data is processed wholly or partly by automated means. An organisation using AI to process information about customers, clients, employees, service users or other identifiable individuals may be processing personal data under the GDPR.

This can arise in routine business activities. An organisation may use AI to summarise client correspondence, analyse customer behaviour, process a complaint, review an application or draft a communication concerning an individual.

The organisation must comply with the data protection principles under Article 5 of the GDPR. Personal data must be processed lawfully, fairly and transparently, collected for specified purposes, limited to what is necessary, kept accurate and secure, and retained only for as long as required. The organisation must also be able to demonstrate its compliance with these principles.

Using an external AI provider does not remove these obligations. An organisation should establish whether the provider processes personal data on its behalf or for the provider’s own purposes. Where the provider acts as a processor, an appropriate data processing agreement will generally be required.

Lawful basis and transparency

Article 6 of the GDPR requires an organisation to identify a lawful basis for processing personal data. Depending on the circumstances, this may include the performance of a contract, compliance with a legal obligation or legitimate interests.

The Report places particular emphasis on legitimate interests in connection with AI training. Where an organisation relies on legitimate interests, it should identify the interest being pursued, establish that the processing is necessary and balance that interest against the rights and freedoms of affected individuals. This should be recorded in a Legitimate Interests Assessment.

The lawful basis relied upon by an AI provider is separate from the lawful basis required by the organisation using the tool. The fact that a provider may lawfully process information to operate or develop its system does not automatically mean that an organisation can lawfully upload personal data to that system.

Where special category personal data is involved, such as health, biometric or racial or ethnic origin data, the organisation must also identify an applicable condition under Article 9 of the GDPR.

Transparency is another central theme of the Report. The complexity of an AI system does not remove an organisation’s obligation to explain clearly how and why personal data is being processed.

Privacy notices should identify the purpose and lawful basis of the processing, the relevant recipients, applicable retention periods and the rights available to individuals. Those rights include access, correction, erasure, restriction and objection. Organisations must be able to facilitate these rights even where an external AI system is used.

Data minimisation, confidentiality and security

Before entering information into an AI tool, users should consider whether personal data is required at all. Where possible, information should be anonymised and unnecessary identifying details removed.

Organisations should not permit staff to enter personal, confidential, commercially sensitive or legally privileged information into an AI tool unless the tool has been assessed and approved for that purpose.

Organisations should establish whether prompts and uploaded documents are retained, whether information may be used to train the provider’s system, where it is stored, who can access it and whether it will be transferred outside the European Economic Area (EEA).

These issues may engage not only data protection law, but also contractual obligations, professional duties, intellectual property rights and duties of confidentiality.

Automated decisions and human oversight

Particular care is required where AI is used to make or materially influence decisions about individuals. This could include decisions concerning access to services, creditworthiness, insurance, recruitment, employee performance or suspected fraud.

Article 22 of the GDPR provides protections in respect of certain decisions based solely on automated processing that produce legal or similarly significant effects.

Even where Article 22 does not apply, organisations should maintain meaningful human oversight. A person reviewing an AI output should assess its accuracy and suitability independently rather than simply accepting its recommendation. AI outputs may be inaccurate, incomplete or affected by bias. Responsibility for the final decision remains with the organisation.

The European Union Artificial Intelligence Act (EU AI Act)

Organisations must also consider the EU AI Act. It operates alongside the GDPR and imposes obligations according to the level of risk associated with an AI system. Compliance with one regime does not ensure compliance with the other.

Certain AI practices are prohibited, while systems used in areas including employment, education, access to essential services, creditworthiness and biometric identification may be classified as high risk.

Organisations should determine whether they are a provider or deployer of an AI system and identify the obligations that apply. Requirements concerning AI literacy already apply, meaning organisations should ensure that staff have an appropriate understanding of the AI systems they use.

What should organisations do?

Organisations should identify the AI tools used across their business, including tools adopted informally by staff, and establish what personal or confidential information is being entered into them.

Before adopting an AI tool, organisations should review the provider’s contractual terms, privacy information, security arrangements, retention practices and use of customer information for training. They should document the lawful basis for processing and consider whether a Data Protection Impact Assessment is required under Article 35 of the GDPR.

An internal AI policy should identify approved tools, prohibited uses, information that must not be entered and when human review is required. Staff should also receive appropriate training on the permitted uses and legal limitations of AI.

The Report demonstrates that organisations can benefit from AI while maintaining strong data protection standards, provided legal compliance and individual rights are considered from the outset.

The DPC’s AI Insights Report is available here.