AI & Data in practice: 5 legal insights that each organisation should know
In this interview with law firm AKD, discover how your organization can innovate responsibly with data and AI by proactively avoiding legal pitfalls surrounding the GDPR, the AI Act, and external data partnerships.
The use of data and AI offers many opportunities, but also raises important legal questions. Together with law firm AKD, we organized a webinar on Navigating Data and AI under Today’s Laws and Regulations.
[Click here to watch the recording]
In preparation, we asked five questions to AKD attorney Lisa Machgeels. In this interview, she shares valuable insights into common misconceptions, the need for an up-to-date data policy, the AI Act, and where partnerships with external marketing and data providers often fall short.

1. What Do You Notice as a Law Firm in an Era of Growing Focus on AI and Data Usage in Organizations?
Organizations are eager to leverage AI and data to drive efficiency, agility, and competitiveness. However, this momentum introduces complex legal challenges. As a law firm, we see a growing demand for advice on the legal ramifications of artificial intelligence, particularly surrounding data privacy, compliance with regulations like the GDPR and the AI Act, and liability in AI-driven decision-making. We also regularly advise on intellectual property rights and the protection of AI-generated content, while anticipating a rise in AI-related legal disputes moving forward.
Many organizations overlook the critical need to establish clear governance guidelines for algorithms and data usage. They require actionable guidance on how to deploy AI responsibly without infringing on privacy rights, regulatory frameworks, or existing laws. Navigating these challenges successfully demands a multidisciplinary approach that seamlessly bridges legal strategy and technological expertise.
2. What Misunderstandings Do You Often Encounter in Companies That Want to Work With AI or Data-Driven Marketing?
Organizations often assume that publicly available data can be used without restriction. That is a major misconception. Simply because information is accessible on the internet does not grant permission to feed it into AI models or leverage it for marketing campaigns. Privacy regulations and copyright laws may still apply, restricting or outright prohibiting its use.
Another common misconception is that obtaining opt-in consent covers all forms of data usage. While user consent is vital, it is rarely a catch-all solution. Data-processing organizations must also comply with core GDPR principles, such as purpose limitation and data minimization. Furthermore, consent cannot always be used as a legal basis—for instance, in employer-employee relationships where power imbalances exist. Lastly, consent is valid only when individuals are fully informed, meaning generic agreement statements simply will not suffice.
Organizations also mistakenly assume that adopting or purchasing a third-party AI tool shields them from liability, assuming responsibility lies entirely with the vendor. In reality, deployers remain legally accountable, particularly when AI-driven decision-making results in biased, harmful, or misleading outcomes.
Finally, it is a misconception that AI-generated creative work comes without legal limitations. While AI tools can produce copy, images, and marketing campaigns, ownership rights remain a complex grey area. If a user provides significant creative direction through prompts, do they own the intellectual property of the output? Legal scholars remain divided, and with no established case law in the Netherlands yet, definitive judicial guidance is urgently needed.
3. What Does European AI Legislation (the AI Act) Add to Existing Rules Such as the GDPR, and Why Is This Supplement Important?
The digital landscape evolves at a rapid pace. While the GDPR entered into force in 2016, the explosive rise of AI systems largely occurred over the past few years, kicked off by the launch of ChatGPT in 2022. Existing laws like the GDPR already safeguard personal data and cover scenarios where AI processes personal information. However, the GDPR alone cannot mitigate every risk unique to artificial intelligence. Consequently, the European AI Act builds upon existing regulations to establish dedicated legal frameworks specifically tailored to artificial intelligence.
The AI Act is vital because artificial intelligence develops at breakneck speed, introducing systemic risks such as algorithmic bias, privacy violations, and a lack of human oversight over autonomous systems. The legislation compels developers and deployers to proactively address and monitor these risks. By establishing robust legal frameworks, the AI Act guarantees that AI is deployed safely, transparently, and ethically across the EU without stifling innovation.
4. Why Is It Essential for Organizations to Re-examine Their Data Policy Now?
Key factors driving this urgency include:
- With the rollout of the AI Act alongside stricter GDPR enforcement, organizations particularly those managing high-risk AI systems face stringent demands for transparency, data protection, and ethical data governance. Non-compliance risks severe reputational damage, substantial regulatory fines, and costly legal claims.
- Regulatory bodies such as the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and other European supervisory authorities are intensifying enforcement efforts and levying harsher financial penalties. Organizations processing personal data without adequate safeguards or a valid legal basis face the greatest scrutiny.
- AI systems rely heavily on continuous data processing; however, lacking clear policy frameworks, these tools risk propagating algorithmic discrimination, personal data misuse, and unlawful decision-making. Establishing clear governance rules for ethical and compliant AI utilization is now a business critical requirement.
- As cyber threats and data breaches escalate globally, organizations must actively bolster their security postures. An updated data policy ensures compliance with legal security standards while minimizing operational and financial damage when incidents occur.
- Data transparency is vital to maintaining customer trust. Consumers increasingly demand full sovereignty over their personal data and expect companies to handle it with care. Organizations that demonstrate robust data management enhance their brand reputation and gain a distinct competitive advantage.
5. What Legal Traps Do You Often See When Working With External Data or Marketing Partners?
A major issue is the lack of clear contractual agreements. Without precise terms covering data usage, roles, and liability, organizations expose themselves to disputes when problems arise. It is critical to establish robust contracts that explicitly address these responsibilities. Furthermore, if a third-party marketing partner processes personal data without complying with the GDPR, the hiring organization can still be held jointly liable for non-compliance and resulting damages. Organizations must therefore vet partners thoroughly for GDPR compliance before sharing any data.
Organizations also frequently lack control over data transfers, sharing information without baseline security measures. This oversight dramatically increases the risk of data breaches and unauthorized usage. Companies must implement strict controls, including end-to-end encryption and role-based access limits. Additionally, some marketing agencies source data through questionable means. Unknowingly utilizing illicitly obtained data can expose your organization to liability for privacy and intellectual property violations, making thorough provenance checks essential.
Finally, organizations regularly confuse pseudonymized data with truly anonymized data, incorrectly assuming it can be shared freely with partners. This misunderstanding risks regulatory fines from supervisory bodies and claims for damages. Data is only exempt from the GDPR if anonymization is completely irreversible. If any mechanism exists to re-identify individuals, the dataset remains pseudonymized and stays subject to full GDPR compliance. Organizations must rigorously verify dataset status before executing external data transfers.
Do You Want to Dive Deeper Into This Matter and Learn How to Use AI and Data in a Legally Responsible Way Within Your Organization? Then Sign Up for Our Joint Webinar With AKD. During the Session, We Will Cover:
- The impact of emerging European laws and regulations on data usage and algorithms (AI Act)
- Key principles of GDPR transparency, data minimization, and control
- How to set up a future-proof opt-in strategy
- First-party vs. third-party data