Why Art. 28 GDPR is often overlooked with AI tools
As soon as an AI provider processes personal data on behalf of your organisation, you are the controller and the provider is a processor within the meaning of Art. 28 GDPR. This applies not only to classic SaaS services but also to generative AI systems, customer-facing chatbots, or analytics tools that process inputs, prompts, or training data containing personal data.
The practical problem: many AI providers offer standard terms and conditions that neither fully cover the requirements of Art. 28(3) GDPR nor address the particularities of AI processing (e.g. using input data for model training). Anyone who signs such terms without checking them bears the full liability risk as controller.
What the contract under Art. 28(3) GDPR must contain
Art. 28(3) GDPR requires a contract or other legal act setting out at least the following:
- Subject matter and duration of the processing, nature and purpose of the processing, type of data, categories of data subjects
- Processing only on documented instructions (Art. 28(3)(a)) — a critical point for AI services: if input data is used for model training or product improvement, this constitutes separate processing requiring its own instruction or legal basis
- Confidentiality obligations for staff involved (point (b))
- Measures under Art. 32 GDPR for data security (point (c))
- Conditions for engaging further processors, in particular sub-processors such as cloud infrastructure or model-hosting providers (point (d), paragraphs 2 and 4)
- Assistance with data subject rights (point (e)) and with the obligations under Art. 32 to 36 GDPR (point (f))
- Deletion or return of data after termination of the contract (point (g))
- Rights to demonstrate compliance and allow audits, including inspections (point (h))
If any of these elements is missing, the contract is not Art. 28-compliant — regardless of how extensive the terms and conditions otherwise are.
Typical gaps in AI provider contracts
In practice, recurring weaknesses appear in AI service contracts:
Instructions versus model training. Many providers reserve the right to use user inputs to improve their models. This is no longer pure processing on instruction but a change of purpose, which must be separately regulated or contractually excluded under Art. 28(3)(a) GDPR.
Sub-processor chains. AI providers frequently rely on third-party cloud or data-centre infrastructure as well as third-party foundation models. Under Art. 28(2) and (4) GDPR, you must be informed of any further processors engaged and be able to object; the chain of obligations must be passed on without gaps.
Rights to demonstrate compliance and audit. Art. 28(3)(h) GDPR requires the provider to make available information to demonstrate compliance and to allow for audits. Many standard AI contracts lack a workable arrangement for this right — it remains a mere assertion in the contract text.
Deletion after contract termination. For models that have been further trained on input data, complete deletion is often no longer technically possible. This must be addressed contractually before the service goes into production use — not only when the contract ends.
Interface with the AI Act: a dual compliance check
The GDPR review under Art. 28 does not replace the assessment under the AI Act (EU) 2024/1689. From 2 August 2026, the transparency obligations under Art. 50 AI Act apply to certain AI systems, with a grace period until 2 December 2026 for systems already placed on the market beforehand. Anyone engaging an AI provider should therefore also check, in parallel, whether the system used falls under these transparency obligations — independently of its classification as a processor under data protection law.
What you should check now
Go through existing and planned AI provider contracts systematically against the catalogue in Art. 28(3) GDPR. In particular, check whether usage data is used for model training, whether all sub-processors are named, and whether you are actually granted audit rights — not just on paper.
For a structured starting point on which obligations under the GDPR and the AI Act specifically apply to your organisation, see the free risk check at /einstufung.