GDPR is the number one reason Irish business owners hesitate before deploying AI. Not cost. Not complexity. The fear of doing something that puts the business in front of the Data Protection Commission.
That instinct is not irrational. Research commissioned by the DPC found 61% of people are concerned about the use of AI, 74% believe new technology should comply with data protection rules even if that delays it, and 67% say misuse of personal data significantly reduces their trust in an organisation. Your customers are watching this closely.
But the fear is usually out of proportion to the actual risk, because the AI systems an Irish SME actually builds are not the ones the regulation is most worried about. An invoice reconciliation engine is not a facial recognition system. This piece sets out what GDPR requires in practice, what the EU AI Act adds on top, and what a properly built system looks like.
The three questions every Irish SME needs to answer
Before any AI system touches data in an Irish business, three questions settle most of the compliance picture.
Does the system process personal data?
If yes, GDPR applies in full. Personal data means any information that can identify a living person — names, email addresses, phone numbers, health records, financial transactions, call recordings. If the system only touches anonymised operational metrics, data protection law is not your primary concern. Most operational AI does touch personal data, so assume it does until you have checked.
Is it special category data?
Health data, biometric data and a defined set of other sensitive categories carry higher protection under Article 9 of GDPR and the Data Protection Act 2018. A GP practice system, a legal call transcription system and an invoice reconciliation system handling sensitive personal detail all sit in more demanding territory. The bar is higher, not unreachable — it is cleared with the right architecture and a valid Article 9 condition.
Where does the data go?
EU-hosted infrastructure is the baseline. Data leaving the EEA triggers additional transfer mechanism requirements and a great deal more scrutiny. Every Keystone build uses EU-hosted infrastructure exclusively, which removes the question rather than answering it.
What GDPR actually requires in practice
Four practical requirements. None of them are exotic, and all of them are considerably easier to satisfy at design time than to retrofit.
A lawful basis
You need a legal reason to process the data. For most operational AI — invoice processing, call transcription, email management — that is legitimate interests or performance of a contract. For healthcare data used in direct care it is Article 9(2)(h). Not complicated, but it must be documented before processing starts.
Data minimisation
The system should only process what it needs. A call transcription system that transcribes, acts, and then deletes the audio meets this. One that keeps audio recordings indefinitely does not. DPC guidance is explicit that AI systems should not retain input data or prompts indefinitely.
A Data Processing Agreement
If a third party processes personal data on your behalf, you need a written DPA covering scope, purpose, duration and obligations. This is a standard document that any reputable provider will have ready. Keystone provides one with every engagement.
A DPIA for high-risk processing
Required where AI processes special category data at scale, or makes automated decisions with significant effects on people. Healthcare, legal and financial systems typically need one. Keystone works through this with clients as part of the build rather than after it.
Compliance is not a document you produce at the end. It is a set of decisions about hosting, retention and access that get made in the first week of a build and are almost impossible to reverse cheaply afterwards.
The EU AI Act: what changed in August 2026
Regulation (EU) 2024/1689 — the EU AI Act — reached full application in August 2026. For most Irish SMEs it changes considerably less than the coverage suggests.
The Act works on risk tiers. The overwhelming majority of systems an SME deploys sit in the minimal or limited risk categories, which carry transparency obligations rather than the full compliance regime.
Minimal / limited risk — most SME systems
- Invoice processing and reconciliation
- Client call transcription
- Email triage and routing
- Document generation from existing records
High risk — the full regime
- Credit scoring and creditworthiness assessment
- Recruitment and HR screening
- Biometric identification
- Systems affecting access to essential services
Two things do change for everyone. General-purpose AI models used in the business now carry transparency requirements, meaning people should understand when they are dealing with an automated process. And where a system makes automated decisions that significantly affect a person — declining an application, flagging an employee for review — human oversight is mandatory.
Keystone builds human-in-the-loop review into every system as a default rather than as a compliance response. The system proposes; a person decides anything consequential. That was the design principle before the Act required it, because it is also how you get systems people will actually trust and use.
How Keystone builds compliance in
Article 25 of GDPR requires data protection by design and by default. In practice that comes down to four engineering standards applied to every client build.
- EU-hosted infrastructure on every build Patient data, client call recordings and financial transaction data all stay inside the EEA. No cross-border transfer mechanism to justify, no third-country jurisdiction exposure to explain to a client.
- Data minimisation by design The call transcription system transcribes and acts; it does not retain the audio. The invoice reconciliation system processes transaction data; it does not hold indefinite copies of full financial records.
- Role-based access control and audit logs In the GP practice build, receptionists, nurses and GPs each see only the patient data relevant to their role. Every data access event is logged, so the answer to "who saw this record" is a query, not an investigation.
- DPA documentation as standard A written Data Processing Agreement with every engagement, setting out what data is processed, for what purpose, on what legal basis, and for how long.
Sector-specific notes
Healthcare
Special category data under Article 9. The lawful basis for direct care is Article 9(2)(h).
A DPIA is required and EU hosting is non-negotiable. Role-based access is what makes the difference in practice — a receptionist scheduling an appointment does not need the clinical record.
The GP practice build was designed with all of this in place from the first week.
Legal
Privileged communications are not special category data under GDPR, but they carry professional obligations that overlap heavily with GDPR principles.
Call transcription handling client communications needs a clear retention policy, transparency notices under Articles 13 and 14, and an audit trail that can actually be produced.
The solicitor practice build includes a verifiable audit trail for exactly this reason.
Finance
Transaction data is personal data, and RCT records for subcontractors carry tax information about identifiable people.
Salesforce and Xero reconciliation systems process significant volumes of it. The lawful basis is typically contract performance or legitimate interests.
Retention needs to align with Revenue's record-keeping requirements, which run to six years after the relevant accounting period.
This is a plain-language guide written from build experience, not legal advice. Your obligations depend on your specific processing, and the DPC publishes detailed guidance on lawful bases, DPIAs and AI. For a system handling special category data at scale, take advice from a data protection professional as well.
Common questions about AI and GDPR in Ireland
Is AI GDPR compliant?
AI is not compliant or non-compliant in itself — the deployment is. A system is compliant when it has a documented lawful basis, processes only what it needs, runs on EU-hosted infrastructure, is covered by a DPA, and has a DPIA where the processing is high risk. Every one of those is achievable for the kind of operational system an Irish SME actually builds.
Can I use AI on customer data without asking for consent?
Usually yes — consent is only one of six lawful bases under Article 6, and for operational processing it is often the wrong one to rely on. Legitimate interests or contract performance typically fit better and are more robust, because consent can be withdrawn at any time. What you cannot skip is identifying and documenting which basis you are relying on, and telling people what you are doing under Articles 13 and 14.
What happens to my data when it goes through an AI model?
That depends entirely on how the system is configured, which is why it is worth asking directly. In a properly built system, data is processed for the specific purpose and not retained by the model provider or used for training. DPC guidance is clear that AI systems should not hold input data or prompts indefinitely. Get the answer in writing in the DPA.
Does the EU AI Act mean I need to register my system?
Not for the minimal and limited risk systems most Irish SMEs run. Registration and conformity obligations attach to high-risk uses such as credit scoring, recruitment screening and biometric identification. If you are automating invoice matching or email triage, your obligations are transparency and, where decisions affect people, human oversight.
Who is responsible if the AI gets something wrong — us or the provider?
As the business deploying the system you are the data controller, so responsibility for the processing sits with you. That is exactly why human-in-the-loop review on consequential decisions matters, and why the DPA needs to set out the provider's obligations clearly rather than vaguely.
The honest bottom line
GDPR is not the reason to avoid AI in an Irish business. It is the reason to be careful about who builds it and how.
The systems that create genuine exposure are the ones assembled without anyone asking where the data is hosted, how long it is kept, or who can see it. Those questions have straightforward answers if they are asked in the first week. They become expensive if they are asked after go-live, and they become a Data Protection Commission matter if they are never asked at all.
If you want to know what the compliance picture looks like for a specific system in your business, that is one of the things the Discovery Call covers. It is free and takes twenty minutes. You can also see how these controls work in practice across our case studies.