The frame: GDPR applies to AI features like any other processing
Nothing about AI exempts a feature from GDPR, personal data processed by an AI feature (entered by users, retrieved into prompts, stored in logs) is personal data under the regulation. The practical build requirements flow from the same principles as any data processing: lawful basis, purpose limitation, data minimization, disclosure, retention limits, and user rights. What AI changes is the surface area: prompts can contain anything a user types, outputs can echo personal data, and third-party AI providers become processors in the legal chain. Counsel owns the legal positions; the build implements them, and this page is the implementation map.
The build requirements, mapped to GDPR principles
- Lawful basis, named before build. Consent (explicit, for sensitive uses), legitimate interest (documented assessment), or contract performance, chosen with counsel, disclosed in the privacy policy, and honored in the flow (consent-gated where that is the basis).
- Disclosure of AI use. Users should know when they are interacting with an AI system and what happens to their input, stated in the interface, not buried. The chatbot builds carry this in their welcome copy as standard.
- Data minimization in prompts. The engineering discipline from the AI-assisted build process: prompts constructed to exclude personal data where the task does not need it, identifiers stripped or tokenized, sensitive classes filtered at retrieval time.
- Retention and deletion honored. Prompt logs and AI outputs are data: retention windows set, deletion requests executable across the AI layer (which means logs must be structured and searchable, an architecture decision, not an afterthought).
- Processor agreements. The AI provider is a processor under GDPR: enterprise agreements with no-training commitments, EU data handling where required, and the processing documented.
- DPIA when high-risk. Systematic evaluation of individuals, sensitive categories, or large-scale processing triggers a Data Protection Impact Assessment, counsel decides when; the build supplies the technical documentation it needs.
The honest boundaries
This page is engineering guidance, not legal advice: which lawful basis covers YOUR feature, whether your use is high-risk, and how your jurisdiction reads the rules, those are counsel's calls, made before the build is scoped. What the build delivers: an architecture where those calls can be implemented cleanly and changed when guidance evolves. The AI-readiness checklist covers the privacy prep; the AI services pages cover the features; the brief starts the scoping with counsel in the loop from day one.