If your company uses AI tools but does not build AI models, four GDPR articles decide almost everything: Article 28 (your processor agreement), Article 30 (your processing register), Article 35 (when a DPIA is mandatory) and Article 5 (how long data may be kept). The Brussels fight over AI training is a model-developer problem, not yours. Here is the split, checked on 2 September 2026.
That distinction matters more in the Netherlands than the coverage suggests. Statistics Netherlands reported in March 2026 that 29.8 percent of Dutch companies with 10 to 249 staff used at least one of seven AI technologies in 2025, against 13.8 percent of firms with 2 to 9 staff and 66.2 percent of large companies. The most common uses were text mining (21.3 percent in the SME band) and natural language generation (14.6 percent). Those are reading and writing tasks. They are almost never model training.
Which GDPR questions actually apply to you?
There are three positions a company can occupy, and they carry very different duties.
Position one: you use a product that has AI features built in. Copilot inside Microsoft 365, a reply suggestion in your helpdesk, a summary button in your CRM. You remain the controller for the personal data involved. The vendor is a processor. Your work is contractual and administrative.
Position two: you send your own data to a model API. Directly, or through a workflow in n8n, Make or Zapier. Same role, but now you also choose the destination, the retention setting and the region, so those choices become yours to document and defend.
Position three: you train or fine-tune a model on personal data. This is the position that the legal literature is written about, and the one that raises the hard questions about lawful basis, purpose limitation and whether the resulting model is anonymous. We covered it separately in our piece on training AI on company data.
Almost every Dutch SME sits in position one or two. Almost all of the commentary is written about position three. That mismatch is why so many owners believe they are waiting on a legal question that has no bearing on them.
Why the Digital Omnibus argument is not your argument
On 19 November 2025 the Commission tabled the Digital Omnibus Regulation proposal (COM(2025) 837 final, procedure 2025/0360(COD)). Two of its GDPR amendments drew most of the fire: a redefinition of personal data so that pseudonymised data would not count as personal for a party with no means of re-identification, and a new Article 88c creating an explicit legitimate-interest basis for developing and operating AI models.
Neither is law. The European Parliament’s legislative train still listed the file as tabled in its 22 May 2026 update. Analysts tracking the Council text report that member state ambassadors failed to agree on 8 June 2026 and that the presidency compromise circulated on 10 June deleted Articles 88a, 88b and 88c, the cookie-consent and AI-training provisions, with the Cypriot presidency handing the file on without a deal. The EDPB and the EDPS had published a sharply critical joint opinion on the package in February 2026. The Irish presidency, which took over in July, then reopened the Commission text on pseudonymisation, processing for AI development and cookie consent rather than reusing the Cypriot compromise, so Article 88c is back on the table.
Read that as a practitioner rather than as a lawyer. If you are in position one or two, Article 88c would not have changed a single obligation you have. The lawful basis for your use case, answering customer email faster or drafting a quote, is a separate assessment from the lawful basis for training a foundation model on scraped data. Waiting for the omnibus is not a plan. It is a way of postponing an afternoon of work.
What does your AI vendor actually keep, and for how long?
This is the question that changes behaviour, and it has published answers.
OpenAI’s enterprise privacy page states that API inputs and outputs may be retained for up to 30 days to run the service and detect abuse, after which they are removed unless retention is legally required. Zero data retention is available on request for eligible endpoints and qualifying use cases. Business data from ChatGPT Business, ChatGPT Enterprise and the API is not used to train models by default. On 19 August 2026 OpenAI extended zero data retention to its frontier models for eligible API customers, alongside a private safety processing system that screens for abuse without keeping the content.
Microsoft 365 Copilot works differently: prompts and responses are stored in a hidden folder inside the user’s own mailbox, which means they sit in your tenant and are discoverable, exportable and deletable through Purview eDiscovery like any other message.

Now do the arithmetic on a deletion request. A customer asks you to erase their data. If your team used Copilot on business accounts, the prompts are in mailboxes you control and one eDiscovery search closes the request. If a colleague pasted the same customer details into a personal ChatGPT account, the data sits outside your tenant and outside your contract. You cannot search it, you cannot export it and you cannot prove it is gone.
So the highest-value privacy control in a 20 to 50 person company is not a policy document. It is making sure every AI tool in daily use runs on a business account covered by your own agreement. That single move converts an unbounded, unsearchable exposure into a bounded one with a known retention window. It also decides whether a Copilot rollout or a ChatGPT deployment is defensible on paper.
When is a DPIA mandatory for an AI tool?
The Dutch data protection authority publishes a list of processing operations that always require a DPIA, on top of the nine criteria in the European guidance. The trigger is what the processing does to people: evaluation or scoring, systematic monitoring, and automated decisions with legal or similarly significant effect.
In practice, a tool that drafts an email or summarises a meeting is unlikely to reach that bar. A model that ranks job applicants, prioritises debtors or scores customers for risk almost certainly does. The important nuance, and the one most often missed: the DPIA duty comes from Article 35 GDPR, not from the AI Act’s high-risk list. The postponement of the high-risk deadline changed nothing about it.
The EDPB opinion on personal data in AI models from December 2024 is still the reference text for the harder judgement calls, particularly on when a model can be treated as anonymous.
What changed on 2 August 2026, and what did not
Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July. It moved the compliance deadline for standalone high-risk systems under Annex III from 2 August 2026 to 2 December 2027, and for AI embedded in regulated products under Annex I to 2 August 2028. We wrote up what the high-risk deadline shift does and does not cover when it landed.
What did not move is Article 50. The transparency duties apply from 2 August 2026: people must be told when they are interacting with an AI system, and synthetic content must be marked. Systems generating synthetic content that were already on the market get a four-month transition to 2 December 2026. If you run a chatbot on your website, this is the obligation that binds you today, and it is far more likely to touch a Dutch SME than anything in the high-risk annexes. Article 50(2), the machine-readable marking duty, is where that four-month transition bites. In the Netherlands the draft Uitvoeringswet AI-verordening, which went into public consultation on 20 April 2026, gives the Autoriteit Persoonsgegevens and the Rijksinspectie Digitale Infrastructuur the coordinating role in a structure of around ten sector supervisors. It is a bill, not enacted law. Our AI Act checklist for SMEs and the risk checker walk through which category your system falls into.
Start from the register you already built in 2018
When the GDPR became applicable on 25 May 2018, most Dutch companies built a verwerkingsregister in a spreadsheet, filed it, and never opened it again. That spreadsheet is the fastest way through all of this, because an AI tool is not a new legal regime. It is a new processing activity in a register that already exists.
Add a row. Name the purpose, the lawful basis, the processor, the categories of data and the retention period. If a row cannot be filled in, that gap is the finding, and it is a more useful finding than any audit report. Four rows of honest text beat forty pages of policy that nobody reads.
One caveat worth stating plainly: this is a Dutch reference. Flemish and Belgian readers carry the same GDPR duties, but under a different national implementation and a different supervisory authority, so the register habit and the guidance you follow will not be identical.
A sequence you can finish in two weeks
One. List the AI tools actually in use, including the ones nobody approved. Ask the team rather than the IT inventory; the answer differs.
Two. Move every one of them onto business accounts covered by your own contract. This is the step that does the most work for the least effort.
Three. Collect the data processing agreement for each vendor and read the retention setting you actually have, not the one the marketing page implies.
Four. Add each tool as a row in the register, and run a DPIA only where the AP list or the nine criteria say you must. Then write the short internal rule that tells staff what may and may not be pasted into a prompt. Our guide to drafting an AI policy covers the wording.
None of this needs a budget line. It needs a few days of one person’s attention and a decision about who owns the answer. If you would rather have someone walk it with you, that is the kind of thing our SME work starts with.
Last checked: 2 September 2026. The Digital Omnibus is still in negotiation, so the GDPR side of this can change; the AI Act side is settled law.