Highlight 25/2026: Fundamental rights challenged by AI: which GDPR principles are at risk?
Neda Milosavljevic, 29 July 2026

Nowadays, the development of artificial intelligence is rapid and cannot always be regulated effectively. The General Data Protection Regulation (GDPR) is one of the most extensive regulatory frameworks protecting personal data of EU citizens. However, GDPR principles, despite this regulatory framework, are difficult to apply in the AI context.
Within the GDPR framework lie the principles of lawfulness, fairness and transparency. AI systems may use historical datasets for decision-making processes, particularly biased or irrelevant information. Datasets are integrated into multiple layers of the systems and it can be difficult to remove them completely. As a result, automated decisions may rely on inaccurate data, which affects the principle of fairness. Sometimes AI systems function as “black boxes”, meaning that the output, such as automated decisions, are not easily explainable. Subsequently, individuals affected by these decisions may be deprived of a clear explanation of how the decision was made, which undermines the principle of transparency. In these respects, AI raises concerns regarding the compliance with GDPR principle of lawfulness. Under the GDPR, personal data must be collected for a specific purpose and not further processed. Sometimes, AI systems use data which were initially intended for other purposes, since AI systems rely on existing datasets and use them for other analytical or predictive functions. This represents a challenge to the principle of purpose limitation and shows the gap between innovation and legal compliance. The GDPR guarantees also the principle of storage limitation, which means that personal data shall be stored only for the purposes they are initially intended. Data may be saved for longer periods only in specific cases, such as for reasons of public interest, scientific or historical research, in accordance with Article 89(1), with appropriate safeguards and the protection of the data subject’s rights. Furthermore, the principle of data minimization faces challenges. In order to achieve higher accuracy, AI systems collect plenty of data, including data that may not be strictly necessary for the intended purpose. This may result in excessive processing of personal information. Accuracy is also itself problematic, as AI systems use datasets which aren’t always updated. On the other hand, predictive AI generates data using statistics and machine learning patterns to forecast upcoming events and information about individuals, which may be incorrect or misleading. Personal data must be stored in the manner to ensure appropriate security, which includes protection against unauthorized or unlawful processing, accidental loss, destruction or damage, using appropriate technical or organizational measures. This is known as the principle of integrity and confidentiality. The principle of accountability is not easily applicable, as far as AI systems are complex and it is difficult to be fully complied with regulatory requirements. Risk assessment is complicated because data are continuously updated and system evolves. Sometimes anonymized data may be linked to people, which cause risk of violation of the GDPR and fundamental rights.
To conclude, traditional regulatory frameworks cannot keep pace with rapid developments in digital technologies and artificial intelligence. The potential risk to fundamental rights is a serious alarm for core legal principles, as they are challenged by new technologies. This shows the urgent need for adaptation of the regulatory framework for current and future AI-related challenges.
Neda Milosavljevic, Highlight 25/2026: Fundamental rights challenged by AI: which GDPR principles are at risk?, 29 July 2026, available at www.meig.ch
The views expressed in the MEIG Highlights are personal to the authors and neither reflect the positions of the MEIG Programme nor those of the University of Geneva