Privacy and Data Protection Law for AI: GDPR from Scratch

The data protection law every AI governance framework silently assumes you know: GDPR lawful bases, controller and processor roles, data-subject rights, Article 22 automated decision-making, DPIAs, international transfers — plus the EDPB’s AI rulings and the American answer in CCPA/CPRA and California’s ADMT regulations.

Content current as of 2026-09.

Lessons

  1. Why AI governance runs on privacy law
  2. The seven principles and the six lawful bases
  3. Article 22: the automated-decision rule
  4. Data-subject rights meet machine learning
  5. DPIAs and international transfers
  6. The American answer: CCPA/CPRA and California’s ADMT rules