Back to insights

    AI governance · 12 min read

    AI Procurement: GDPR, DPIA and Vendor Due Diligence

    Buying an AI tool transfers capability, not accountability. Procurement must establish what the system does, where data flows, which party holds each regulatory role and whether performance claims survive your own tests.

    AI Procurement: GDPR, DPIA and Vendor Due Diligence

    Begin with a use case and data-flow intake

    Do not approve a generic vendor. Approve a defined use case with named users, inputs, outputs, affected people, decisions and integrations. Map personal, confidential and special-category data through prompts, retrieval, logs, support and model-improvement paths.

    This intake determines which privacy, security, AI Act and contractual reviews are proportionate.

    Determine roles and applicable assessments

    Record whether the company acts as deployer, provider, importer or distributor and obtain the vendor's substantiated position. Under GDPR, confirm controller and processor roles, legal basis, retention, subprocessors and international transfers.

    Screen for a DPIA using the real deployment context. A low-risk tool can become high-impact when used at scale, with vulnerable people or to support consequential decisions.

    Demand evidence, not assurances

    Ask for security documentation, incident history, model and data limitations, evaluation results, change-notification practices and relevant AI Act documentation. Verify the claims that matter to your use case through a controlled evaluation.

    • Accuracy and failure modes on representative tasks
    • Prompt injection and unauthorized data exposure
    • Logging, access control and deletion behavior
    • Human override and escalation
    • Availability, cost and operational dependencies

    Contract for lifecycle reality

    Contracts should address permitted data use, confidentiality, subprocessors, security measures, incident notification, audit support, material model changes, service levels, intellectual property and regulatory cooperation.

    Define an exit plan before go-live: export formats, deletion evidence, replacement dependencies and continuity if the service is withdrawn or degrades.

    Approve conditionally and monitor

    Record the approved purpose, prohibited uses, owner, controls, user population and review date. Reassess after a material vendor, model, purpose, data or integration change. Procurement approval is the start of managed operation, not the end.

    Frequently asked questions

    Is a vendor's GDPR compliance statement sufficient?

    No. The buyer must understand the specific data flow, roles, legal basis, retention, transfers and controls for its intended use.

    When may an AI tool require a DPIA?

    A DPIA may be required where processing is likely to create high risk, including systematic evaluation, sensitive data, large-scale monitoring or consequential use involving vulnerable people.

    Why evaluate a commercial AI product?

    Generic benchmarks do not prove fitness for your data, tasks, users and acceptable failure thresholds. Local evaluation supports both performance and risk decisions.