Marketers, the AI You're Using Could Cost You 20 Million
This article explains how GDPR and the EU AI Act affect marketers using AI tools, covering risks such as user profiling, black-box decisions, and automated decision-making. It outlines five compliance pillars, common pitfalls, and the role of an AI governance framework in protecting user data and building trust.
A while back, a friend of mine who runs an e-commerce shop came to me with a complaint.
He said he'd just switched to a new AI tool that automatically tagged every visitor who landed on his store. "High intent." "Price-sensitive." "Likely to repurchase within three months." The tags were frighteningly accurate. He was thrilled, and he was getting ready to feed all this data into his ad system for precision retargeting.
Then his legal team shut him down with a single sentence: This is user profiling. That's personal data. Did you run the compliance process?
He froze. So did I.
Because we both realized something in that moment: today, almost every marketer is holding a ticking time bomb.
The bomb's name is GDPR
What exactly is GDPR?
Put plainly, it's a data protection law passed by the European Union. The rules aren't complicated: a user's name, email, IP address, cookie ID, click behavior — all of it belongs to the user, not to you. If you want to use it, you ask.
Some people will say, "I don't do business in Europe. What does it matter to me?"
Wrong.
The moment a single visitor arrives on your site from Paris, you're subject to these rules. Its reach extends much farther than you'd think.
So why has this law suddenly become so radioactive these past few years?
Because AI arrived.
AI turned the old rules into new headaches
Think about it. Back in the day, the worst a marketer did with collected data was hand out a discount code or jot down an email address. Simple.
And now?
Your AI tool learns on its own, segments on its own, decides on its own which price to show whom. The more data it eats, the more accurate it gets. Sounds beautiful.
But hidden inside this is a particularly nasty problem — the "black box."
What does that mean?
It means the AI made a decision, and even you can't explain why it did what it did. For instance, it quoted User A a price 30% higher than User B. When somebody asks you why, all you can do is scratch your head.
GDPR has zero patience for this "I don't know why."
Its stance is hard: the user has the right to know why you're using their data, and what you did with it. Can't explain it clearly? Then you're in violation.
And then there's a sharper one called "automated decision-making." If a machine makes a decision on its own that affects a user's life — whether they get a loan, whether they get hired — you have to put meaningful human oversight in place, review it regularly, and never just hand it off to the algorithm and walk away.
Five pillars to hold the house up
So what do you do?
I've put together five things every marketing team needs. This isn't advice — it's the floor.
First, lawful basis. Stop "collect first, ask later." Either you get the user's explicit consent, or you have a valid legal ground (like fulfilling a contract). Don't hide the cookie banner — make it clear.
Second, transparency. Stop writing your privacy policy like legalese gibberish. Tell the user in plain language: here's what I collect about you, and here's what I do with it.
Third, consent management. When the user says "no," you stop immediately. None of this "let's observe them for two more days."
Fourth, data minimization. Don't hoard a warehouse "just in case." Collect what you use, and only what you use.
Fifth, user rights. When a user asks to be deleted, you delete — including the copy you handed to the third-party AI tool.
These five things sound plain. But go check around, and you'll find the overwhelming majority of teams can't tick all five boxes.
Look past GDPR — there's also the EU AI Act
A lot of people don't know this, but on top of GDPR, the EU came back and added another layer, called the EU AI Act.
What it does is simple: it grades AI tools by risk.
Most marketing tools fall into the "low-risk" bucket — recommendation engines, ad targeting, email optimization all count. But you do have to do one thing — don't fake it. When a user is chatting with your chatbot, you have to tell them it's a bot, not a human.
If your AI touches hiring or credit scoring, that's "high-risk." The rules are much stricter — you have to build documentation, run audits, leave a trail. Regular marketers won't brush against this tier, but you should know it exists.
Pitfalls we've all fallen into
Let me walk you through the three most common ways to get burned.
The first: assuming "if it's a big-name vendor, it must be compliant." Wrong. A tool can be wildly popular and compliant itself, and that still doesn't make you compliant. How you use it, and on whom — that's what matters.
The second: thinking that once you've collected consent, you're set forever. Wrong. The moment you add a new model or a new use case, you have to ask again. Consent has an expiration date.
The third: hoarding old data you don't even use, because you can't bear to delete it. This one's the deadliest. Old data sitting around doesn't gain value — it only adds to your legal liability. Cut it off in one clean stroke, and you'll actually sleep at night.
One document that can save your skin
Every marketing team should have one of these on hand: an AI governance framework.
Think of it as an operating manual. Inside, spell out three things clearly:
- Who's allowed to use AI?
- What data can they use?
- Which tools has the company approved?
Why does this matter so much?
Because there's a thing called "shadow AI" — employees quietly using ChatGPT, using little tools here and there to process user data, and the company has no idea. You'll catch one every time you look; and when something goes wrong, it goes very wrong.
This framework, plus regular training, plus a Data Protection Impact Assessment (DPIA) every time a new AI project launches, and your foundation is solid.
When regulators actually come knocking, you can hand over logs, hand over documents, hand over audit records — that's what "I'm taking this seriously" looks like. Compared to "I don't know," that's night and day.
The flip: compliance isn't a cost, it's an asset
At this point you might be feeling this whole thing is nothing but a burden.
But the more I think about it, this might actually be an opportunity.
Why?
Because today's users are sick of being tracked. Pop-ups, tracking, ads that show up for no explainable reason — everybody's annoyed.
And right then, if a brand stands up and says: I won't secretly scrape your data. Whether you give it to me is up to you. What I collect, I make clear. What I do with it, I make plain.
How will users respond?
They'll actively hand you more accurate data.
This is what the industry calls Zero-Party Data — data the user actively tells you: what they like, when they're going to buy, what their budget is. It's ten times more accurate than what you'd quietly infer on your own.
See — the brands that play by the rules actually end up with cleaner data. And higher ROI.
The underlying logic here is dead simple:
Users trust you, so they give you the real stuff.
One last thing
The GDPR rulebook is going to keep changing. Every country will put out its own version, and the AI Act will keep iterating.
But the core won't change. Three lines:
Speak plainly. Act decently. Treat users like humans.
Marketers forget this one sometimes. We get so used to treating users as data points, conversion rates, LTV (Lifetime Value).
But the user isn't a data point. The user is a living person who scrolls their phone at 3 a.m., gets annoyed by pop-ups, and gets furious when a brand seems to be "listening in" on them.
Treat your users the way you'd want to be treated.
That iron rule matters more than any regulation.
As for that 20 million fine — it's just the price of waking up before it's too late.
The real cost is when users never trust you again.
And that's the biggest hit a marketer can ever take.