Skip to content
Novot AI
NLBook a call

REFERENCE

Knowledge base

What the GDPR and the AI Act ask of you when you deploy AI in your business. In plain language, with the legal articles and the source included, so you can check everything yourself.

AI and the GDPR: what you as an SME owner actually need to arrange

You remain the controller: the AI vendor is a processor acting on your instructions. You need a data processing agreement, a lawful basis for the processing, and a threshold above which a human decides. That last one is not a courtesy but article 22 GDPR.

The AI Act for SMEs: what already applies today

Two things affect SMEs directly. Nine practices have been fully prohibited since February 2025, including emotion recognition in the workplace. And since August 2026 you must let people know they are interacting with a machine. The rest of the regulation largely concerns high-risk applications the average SME does not deploy.

Processor or controller: who is which when you buy AI?

With an AI handling your customer contact you are almost always the controller and the vendor is the processor. That is not a choice you settle in a contract: the Dutch DPA looks at who in fact determines why and how the data is processed. If the processing agreement says something other than what actually happens, reality wins.

EU hosting and data residency: what it means and when it matters

EU hosting means your data sits on servers within the European Economic Area. That matters because transfers to countries outside it are only permitted if that country offers adequate protection. But hosting is not the same as processing: a vendor can host in the EU and still have data processed outside the EEA through a sub-processor or an AI model. So the question is not only where the servers are, but where the data passes through.

See what Novot AI can do for your business.

Book a call