Describe AI processing plainly
Users should understand whether their content, prompts, files, messages, profile data, or usage events are processed by AI systems. The privacy policy should describe the purpose of that processing in product language rather than hiding it under generic service improvement wording.
The most important questions are practical: what data is sent to the AI workflow, which provider receives it, whether humans may review it, whether outputs are stored, whether data is used for model training, and how long input and output records are retained.
Connect providers to purposes
If an AI provider processes prompts, files, transcripts, or generated outputs, that provider belongs in the vendor and processor review. The disclosure should not bury AI processing under a broad infrastructure category if the feature meaningfully changes how user content is handled.
The contract review should check data processing terms, subprocessors, retention defaults, training settings, security measures, transfer mechanisms, and support access. Product configuration matters too: one provider may offer different data retention or training options depending on account settings.
Keep GDPR and AI Act questions separate
The GDPR applies when personal data is processed, regardless of whether the system uses AI. That means transparency, legal basis, data minimization, retention, processor contracts, transfer safeguards, security, and rights handling still need to be addressed.
The EU AI Act adds a separate risk-based framework. As of the European Commission's current implementation timeline, the AI Act entered into force on 1 August 2024, with most rules applying from 2 August 2026 and some obligations applying earlier or later. Privacy notices should not claim AI Act compliance unless the team has actually assessed the relevant role and obligations.
Watch for automated decision-making
AI features that only summarize support tickets or draft text may raise different privacy questions from features that score people, make recommendations about them, or affect access to a service. When automated decision-making or profiling is involved, Article 22 and related transparency language may become relevant.
Product teams should identify whether AI output is advisory, user-controlled, reviewed by a human, or used to make decisions with legal or similarly significant effects. The privacy policy should match that reality and avoid broad claims that no automated decisions occur if the product roadmap says otherwise.
Design controls before launch
AI privacy review works best before release. Teams should decide what data is excluded from prompts, whether sensitive fields are masked, how long logs are retained, who can inspect outputs, how users can delete content, and how incidents will be investigated.
A launch checklist should include the privacy policy, processor list, data retention rules, security review, transfer assessment, customer-facing documentation, and support instructions. AI features move quickly, so these controls need an owner after launch as well.