Back to the blog
gdprai actpersonalisatie
New

Email, AI and the law: what AI-generated content and personalisation mean under GDPR and the AI Act

Having a newsletter written by an AI model is not in itself a problem under the GDPR or the AI Act. What does matter is what you feed the model (customer data?), how you automate decisions about individual recipients (profiling) and whether you are transparent about what happens. In practice it comes down to three questions: which personal data goes to which system, on what basis do you personalise, and can a recipient understand and object. This article gives the practical side; it is not legal advice, and the precise obligations depend on your situation.

Two laws, two questions

The GDPR is about personal data: everything you process about an identifiable person. The AI Act is about AI systems themselves, classified by risk. Writing marketing copy and recommending products falls, as far as we understand it, into the category with limited or minimal obligations. For email, therefore, the GDPR is usually the law that does the work, with the AI Act as a supplement for transparency.

AI-generated content

What does not change

A subject line or a product description written by a model is simply your text. You are responsible for it, as for text from a copywriter. No law obliges you to state under a newsletter that a model helped write it, as long as a human reviewed the text and the message comes from you. The transparency rules of the AI Act are mainly aimed at systems that interact directly with people (a chatbot must identify itself as such) and at synthetic images, audio and video.

What does change

The input. Whoever asks an external AI service "write an email for this customer" and pastes in the name, purchase history and address is passing personal data to a processor. That is only allowed with a data processing agreement, a lawful basis and, if that service processes outside the EU, a valid transfer basis. Many AI services also use input by default to train their models unless you switch that off. The practical rule: write copy with AI without customer data (use placeholders), and let personalisation happen in your own campaign tool, which already processes the data under an agreement.

Automatic personalisation

This is where the real work is. As soon as a system decides per recipient which content, which offer or which price they see based on their behaviour, that is profiling in the sense of the GDPR. That is not forbidden, but it requires:

  1. A lawful basis. For existing customers and simple segmentation (bought garden furniture, gets garden news), legitimate interest is usually defensible. For deep profiles that combine behaviour across channels, consent probably becomes the safer route.
  2. Transparency. Your privacy statement must say that you profile, for what purpose, and that the recipient can object. For marketing that right to object is absolute: whoever says "stop profiling me for marketing" must be followed.
  3. Limits on fully automated decisions. The GDPR protects people against decisions without human involvement that significantly affect them. A different product recommendation in a newsletter usually does not significantly affect anyone; a system that automatically shows certain customers a higher price or no credit option might. When in doubt: have a human approve the rule, not every individual mail.

Special category data: this is where it stops

Never let a model segment on what the GDPR calls special categories: health, religion, political opinion, sexual orientation, ethnicity. Not indirectly either: a pharmacy that lets a segment "probably diabetic" be derived from purchases is processing health data without the customer knowing. AI models are good at precisely this kind of inference, and that is the reason to deliberately limit the input.

A workable approach for an average business

  • Write with AI, but without personal data in the prompt. Placeholders such as {first_name} and {last_product} are only filled in at send time, inside your campaign tool.
  • Have a human review every text before sending. Models invent product features, prices and conditions.
  • Limit personalisation to segments you can explain to a customer: "you bought X, so you get news about X". Our page on list segmentation describes how to set that up without a black box.
  • Update the privacy statement: which data, which purpose, which processors, which right to object.
  • Choose processors that process within the EU and offer a data processing agreement. For the sending itself, a European email platform is the simplest way to avoid the transfer question.

An example

A webshop for bicycle parts wants a different opening paragraph per customer. The wrong way: send every customer with name and order history to an external AI service and generate a text per person. The workable way: write five variants with AI (road bike, mountain bike, city bike, electric, unknown), have a human review them, and let the campaign tool pick the variant per customer based on the segment they are in. No personal data leaves the building, an explainable rule, and an opt-out for personalised content in the preferences.

Frequently asked questions

Do I have to state that an AI wrote the mail?

For ordinary marketing copy reviewed by a human, that is not mandatory as we understand it. You are free to do so. For a chatbot that talks to customers, it is different.

Does the AI Act change anything about my newsletter tool?

Insofar as that tool helps write text or suggests segments, it falls into the light category. Do ask your supplier which data its AI features use and where that is processed. Read more about responsible campaign management on our page about email marketing.

#ai act email#gdpr email marketing ai#ai generated email#personalisation gdpr#ai and newsletters
Call us
Send an email