Are you working with generative AI, or is your organisation exploring its potential? The Dutch Data Protection Authority (AP) has published 2 resources to help implement generative AI responsibly: a checklist and a comprehensive guide on the General Data Protection Regulation (GDPR or AVG, in Dutch).
These documents complement each other but serve distinct purposes. The Guidance Generative AI and the GDPR explains how the GDPR applies to the development and use of generative AI. The Tool Generative AI and the GDPR helps organisations assess whether they are permitted to use generative AI and assist with implementation. Both resources are designed as starting points for public-sector organisations looking to adopt generative AI or reassess their current approaches.
Legal insights for responsible AI
The guidance is tailored for organisations developing generative AI models or overseeing their deployment. It sets out the AP’s initial interpretation of GDPR requirements for AI development and implementation, covering data collection, management, cleaning, storage, and the use of personal data in training AI models.
Practical tool for implementation
The tool supports professionals involved in procuring, introducing, or using generative AI. It enables step-by-step assessments of whether, how, and when an organisation should adopt generative AI. A key consideration: Can the application function without personal data? If not, the checklist helps identify which GDPR obligations apply and which technical and organisational measures are required.
Access the resources
Review the Guidance Generative AI and the GDPR and the Tool Generative AI and the GDPR on the Dutch Data Protection Authority’s website.



