Skip to content

GDPR and AI: the six friction points that stall projects

Legal basis, DPIA, minimization, Article 22, transparency, vendors: the six GDPR friction points where AI projects stall, and how to unblock each one.

An AI project gets approved, a pilot works, and then someone asks the question that freezes the room: "has legal signed off on the data?" Six months later the pilot is still a pilot. The problem is rarely that the GDPR forbids the project. The problem is that nobody mapped the specific friction points in advance, so each one surfaces as an emergency instead of a checklist item. This article maps the six points where AI projects actually stall under the GDPR, with the article that applies, what the blocker looks like from inside the company, and the move that unblocks it. I write from the Italian market, where the Garante per la protezione dei dati personali has been the most aggressive AI enforcer in Europe, but the mechanics are the same in any EU country. The primary sources are the GDPR text on EUR-Lex and the EDPB Opinion 28/2024…