The Spanish Data Protection Authority's January 2026 notice and the European Commission's draft Code of Practice on AI transparency mark a regulatory shift. If your organization views these as distant obligations, you'll be scrambling by August 2026 when the AI Act's transparency requirements take effect. This checklist helps you establish defensible practices now.
Prerequisites
Before you begin, ensure you have:
- Inventory of AI tools in use: Document every generative AI tool that processes images, video, or voice data across your organization. You can't protect what you don't know exists.
- Designated accountability: Assign clear ownership for AI compliance, typically with your Privacy Officer, but ensure coordination with Legal, IT, and Communications.
- Basic GDPR compliance foundation: If you're behind on data processing registers and legal basis documentation, address that first. AI compliance builds on these fundamentals.
Data Protection Safeguards for AI Image Processing
1. Establish a legal basis before any image upload
Requirement: GDPR Article 6(1)
Action: Document your lawful basis before uploading any person's image to an AI system. Consent is suitable for marketing campaigns, while legitimate interest may cover internal process improvement. Mistakes here mean unlawful processing from the start.
What good looks like: Your data processing register includes a specific entry for each AI tool, naming the legal basis, data categories processed, and retention period. Your team can explain the basis without checking documentation.
2. Map data flows to external AI providers
Requirement: GDPR Article 28
Action: Identify where image data goes when using third-party AI tools. Are images stored, used for model training, or accessible to the provider's staff? Demand answers in writing.
What good looks like: You have Data Processing Agreements with every AI provider. You can trace what happens to an uploaded image from entry to deletion and have documented any sub-processors.
3. Implement upload controls for sensitive images
Requirement: GDPR Article 9
Action: Block or flag uploads of intimate, compromising, or special category data (health information, biometric data for identification). Build technical controls where possible; require manual approval where you can't.
What good looks like: Your AI tools reject uploads of images containing visible health data or biometric identifiers without explicit authorization. Staff understand which images require heightened scrutiny.
4. Document metadata handling practices
Requirement: GDPR Article 5(1)(a) (transparency)
Action: Understand what metadata your AI tools generate. Location data, facial recognition tags, and processing timestamps can enable re-identification even when images seem anonymized.
What good looks like: You've tested your AI tools to see what metadata they create. You've documented retention periods for metadata separately from images. You can demonstrate how you prevent unintended re-identification.
5. Create rights exercise procedures for AI-processed images
Requirement: GDPR Articles 15-22
Action: Build processes to handle data subject requests when images have been processed by AI. Can you identify all instances where someone's image was used? Can you delete copies, including from AI training sets?
What good looks like: You can respond to a deletion request within 30 days. You've negotiated deletion rights in your AI provider contracts. You've tested the process at least once.
AI Act Transparency Requirements (Effective August 2026)
6. Classify your AI-generated content
Requirement: AI Act Article 50; EU draft Code of Practice
Action: Determine whether your output is fully AI-generated or AI-assisted (where AI substantially influences the result). This classification drives your labeling obligations.
What good looks like: You've documented decision criteria for each content type your organization produces. Marketing, Legal, and Communications teams apply the same classification standards.
7. Implement labeling for fully AI-generated content
Requirement: AI Act Article 50(2); EU draft Code of Practice
Action: Apply clear, machine-readable labels to all fully AI-generated images, video, and audio. Use the interim two-letter acronym ("AI", "IA", or "KI") until the official EU icon is released.
What good looks like: Every piece of fully AI-generated content displays the label prominently. Your content management system tags AI-generated files automatically. External audiences can identify AI content without technical knowledge.
8. Mark AI-assisted content appropriately
Requirement: EU draft Code of Practice
Action: Label content where AI substantially influenced the output, even if a human made final edits. This includes AI-enhanced photos, AI-suggested copy with human approval, and AI-generated drafts that humans refined.
What good looks like: Your content creation guidelines define "substantial influence" with examples. Creators know when to apply AI-assisted labels. You can audit compliance through your content management system.
9. Build deepfake disclosure controls
Requirement: EU draft Code of Practice (sector-specific rules)
Action: For real-time deepfake video, display continuous on-screen indicators plus an initial notice. For recorded deepfakes, choose from fixed icons, opening notices, or credits-based disclosure. Document your choice and apply it consistently.
What good looks like: You've banned certain deepfake applications outright. Approved uses include technical controls that prevent content distribution without proper labeling. Legal has reviewed your disclosure language.
10. Document your labeling practices
Requirement: EU draft Code of Practice (internal mechanisms)
Action: Create written procedures explaining when and how to apply AI content labels. Include screenshots, examples, and edge cases. Update the documentation as you encounter new scenarios.
What good looks like: New staff can apply labels correctly after reading your documentation. You can demonstrate consistent labeling practices to regulators. You've version-controlled the procedures and dated each update.
11. Train staff on transparency obligations
Requirement: EU draft Code of Practice (internal mechanisms)
Action: Run training for everyone who creates, edits, or publishes content. Cover classification criteria, labeling requirements, and the consequences of mislabeling. Track completion.
What good looks like: Training completion rates exceed 95% for in-scope roles. Staff can explain why labeling matters. You've built training into onboarding for new hires.
12. Establish a mislabeling correction channel
Requirement: EU draft Code of Practice (internal mechanisms)
Action: Create a process for reporting and correcting labeling errors. Set response time targets. Track reports and resolutions.
What good looks like: Anyone can report a mislabeling concern through a single channel. You correct confirmed errors within 24 hours for external content. You've documented every correction and root cause.
Common Mistakes
Treating internal-only content as exempt: The Spanish DPA explicitly warned that uploading images to AI tools triggers GDPR obligations even when you don't share the output. Internal process improvement doesn't eliminate compliance requirements.
Waiting for the official EU icon: The August 2026 deadline is firm. Use the interim two-letter acronym now rather than waiting for final guidance. You can swap icons later; you can't retroactively label content.
Ignoring AI-assisted content: Organizations focus on fully AI-generated material and miss the substantial-influence threshold. If AI suggested the composition, adjusted the lighting, or generated the first draft, it likely qualifies as AI-assisted.
Assuming consent covers everything: Consent for one purpose (using a photo on your website) doesn't automatically extend to AI processing (generating variations of that photo). Reassess your legal basis for each new use.
Next Steps
Start with items 1-5 this quarter. These data protection safeguards apply immediately under GDPR and address the Spanish DPA's concerns. Build your transparency infrastructure (items 6-12) by June 2026, giving yourself two months to test before the August deadline.
Organizations that treat this as a documentation exercise will struggle. Those that build AI literacy across their teams, embed compliance into content workflows, and document everything they do will be ready when enforcement begins.





