Do data-protection rules specifically govern legal AI?
Data-protection authority guidance or rules specifically about AI processing that legal services must follow.
As of 2026-09-04, 11 of 130 countries and entities have a binding rule for data protection and legal AI, 34 have official guidance, 4 have a proposal, 0 are set by case law, 68 were checked with nothing found and 13 remain unclear. Binding countries: Bahrain, Colombia, Egypt, Indonesia, Kazakhstan, Kuwait, Malaysia, Nigeria, Philippines, Saudi Arabia, United Arab Emirates.
Binding ruleOfficial guidanceProposed / consultationSet by case lawNothing foundNot yet determined
Tap or hover a country. Faint land has no record yet. Miller projection; boundaries as published by Natural Earth (India point of view) — see the disclaimer.
Personal Data Protection Law No. 30 of 2018 governs automated processing and is named in the iGA AI policy as a compliance obligation for government AI use. No AI-specific guidance from the Personal Data Protection Authority, and nothing addressed to legal services, was located.
Circular Externa 002 of 21 August 2024 sets binding guidelines for processing personal data in AI systems, covering suitability, necessity, reasonableness and proportionality, risk identification and privacy by design. It is not legal-sector specific.
Personal Data Protection Law No. 151 of 2020 and its Executive Regulations (Minister of Communications Decree No. 816 of 2025, in force 2 Nov 2025, compliance by 1 Nov 2026) expressly address personal data used to train AI. Economy-wide, not legal-sector specific; official gazette text not opened.
The Personal Data Protection Law (UU No. 27 Tahun 2022) has been fully in force since October 2024, but its mandated implementing Government Regulation and the supervisory authority (Lembaga Pelindungan Data Pribadi) had still not been issued or established as of mid-2026, leaving AI-specific enforcement guidance absent.
The 2025 AI Law includes data protection and confidentiality as regulatory principles and gives users rights to information about automated processing affecting their rights. It is economy-wide, not legal-sector specific.
CITRA's Data Privacy Protection Regulation (2021) binds providers of communication and IT services and governs personal data used in AI systems by extension. Sources differ on the implementing resolution number and a 2024 update is reported; no AI-specific CITRA guidance and nothing addressed to legal services was located.
The Personal Data Protection Act 2010 (Act 709) as amended in 2024 applies. JPDP issued Automated Decision-Making and Profiling, DPIA and Data Protection by Design guidelines in April 2026; the ADMP guideline's Part E governs AI and generative AI in profiling, requiring human oversight, barring sole-factor automated decisions and mandating staff training and appointed reviewers.
NPC Advisory No. 2024-04 (19 December 2024) applies Republic Act 10173, its IRR and NPC issuances to AI systems processing personal data across development, training, testing and deployment. NPC Advisory No. 2026-01 covers scraping of publicly available personal data.
The Personal Data Protection Law, enforced by SDAIA, applies to AI processing of personal data by law firms and courts; SDAIA is simultaneously the data-protection authority and the AI regulator. No legal-sector-specific AI guidance.
DIFC Data Protection Regulation 10 on personal data processed through autonomous and semi-autonomous systems, in force 1 September 2023, is the first such rule in the MEASA region. It imposes notice, transparency, accountability, audit and certification duties on deployers and operators, including law firms in the DIFC.
The access-to-information agency's guide for public and private entities on transparency and personal-data protection for responsible AI covers privacy by design, impact assessment, bias testing, traceability and complaint channels across the AI lifecycle. It is not legal-sector specific.
OAIC guidance on privacy and the use of commercially available AI products (21 October 2024, updated 17 January 2025) applies the Australian Privacy Principles to AI inputs and outputs, requires product due diligence and accuracy steps, and advises against entering personal information into publicly available generative AI tools.
GDPR applies; the ÖRAK Leitfaden requires an Art. 28 GDPR processor agreement alongside the § 40(3) RL-BA undertaking. No Austrian Datenschutzbehörde guidance specific to AI in legal services was located.
The Belgian DPA publishes information brochures on AI systems and the GDPR and on the impact of AI on privacy, and points to EDPB Opinion 28/2024 on AI models and EDPB Guidelines 03/2026 on web scraping for generative AI. Nothing specific to legal services.
The Office of the Privacy Commissioner and provincial counterparts have published principles for responsible, trustworthy and privacy-protective generative AI; there is no legal-sector-specific AI privacy guidance. Source page not opened during this pass.
The data-protection agency's AI Regulation page states that every processing of personal data in AI systems at all phases must comply with the GDPR, that the AI Act and GDPR are complementary, and that deployers must ensure AI literacy. It is general rather than legal-sector specific.
Datatilsynet maintains an AI guidance hub and published 'Offentlige myndigheders brug af kunstig intelligens — Inden I går i gang' for public bodies; supervision of generative-AI use was a stated 2025 focus area.
Andmekaitse Inspektsioon maintains a standing 'Tehisaru' section covering AI and data protection, the AI Regulation, personal-data protection, awareness and human rights, and a page for AI adopters, plus 2026 opinions on general-purpose AI and AI documentation software in healthcare.
EDPB Opinion 28/2024 (17 Dec 2024) addresses AI-model anonymity, legitimate interest in development and deployment, and consequences of unlawful training data — supervisory authorities may order erasure or retraining. Applies to legal-sector deployers of AI.
CNIL has issued successive recommendations on applying the GDPR to AI system development and deployment, and renewed its partnership with the CNB on 17 July 2025 for three years specifically to support GDPR compliance of AI-equipped legal analysis tools in law firms.
The DSK's 'Künstliche Intelligenz und Datenschutz' Orientierungshilfe (v1.0, 6 May 2024) is the reference text: purpose definition, lawful basis, no automated final decision, closed vs open systems, transparency about training and prompt history, DPIA, work accounts for staff. BRAK §3.3 makes it the benchmark for law firms and flags that OpenAI is not on the EU-US Data Privacy Framework list.
Hellenic Data Protection Authority Opinion 8/2026, on a public authority's AI complaint-triage system, required explicit human approval before acting on AI outputs; Opinion 9/2026 addressed the authority's AI Act role. Neither is legal-sector specific and the official texts were not opened.
The strongest layer. PCPD published Guidance on the Ethical Development and Use of Artificial Intelligence (2021), the Artificial Intelligence: Model Personal Data Protection Framework (11 June 2024) covering AI strategy and governance, risk assessment and human oversight, model customisation and stakeholder communication, and a Checklist on Guidelines for the Use of Generative AI by Employees (31 March 2025).
NAIH publishes general generative-AI awareness material — a Hungarian adaptation of the CNIL/PIPC '6 questions' poster on generative AI — and relays EDPB guidelines, including 2/2026 on anonymisation and 3/2026 on web scraping for generative AI (July 2026). Nothing legal-sector specific.
Persónuvernd maintains 'Gervigreind' (artificial intelligence) as one of its main published subject areas, alongside surveillance, children and health data, advising awareness of one's own and others' privacy when using AI. The topic page is client-side rendered and its detailed content could not be captured.
No legal-AI-specific data-protection guidance exists at international level. CEPEJ(2025)18 requires pseudonymisation and judiciary-controlled infrastructure; the ICC Note to Parties of 1 June 2026 reminds tribunals that the GDPR and EU AI Act may apply. CETS 225 article 11 on privacy is not yet in force.
Privacy Protection Authority draft guidance on the application of the Privacy Protection Law to AI systems published 30 Apr 2025 (comments to 5 Jun 2025) and still in draft; a Privacy-Enhancing Technologies guide followed in late 2025. Amendment 13 to the Privacy Protection Law took effect in August 2025.
The Personal Information Protection Commission alert of 2 June 2023 on generative AI cautions on entering personal data into prompts and records a notice to OpenAI. It is general rather than legal-sector-specific.
The CNPD maintains thematic dossiers 'Intelligence artificielle et protection des données: une introduction' and 'La régulation de l'intelligence artificielle: AI Act', plus articles on prohibited AI systems and on how organisations keep AI under control. Nothing specific to legal services.
The Data Protection Office has an official publication titled “Artificial Intelligence, Human Intervention and Trust” applying data-protection concepts to AI processing; no legal-sector-specific guidance was found.
CNDP press release of 18 March 2025 states that AI processing of personal data is governed by Law 09-08, that automated decisions require integrity, transparency, fairness and legibility plus a route of recourse, and that work on a deliberation on AI processing has begun with stakeholder hearings. No AI deliberation adopted.
The AP supervises algorithms and AI alongside the GDPR and publishes ongoing guidance (e.g. on preparing for the fundamental-rights impact assessment/FRIA, Aug 2026). No AP guidance specific to legal services located; the NOvA recommendations carry the DPIA requirement into the profession.
The Office of the Privacy Commissioner publishes Artificial Intelligence and the Information Privacy Principles (from 21 September 2023) and a generative-AI page setting expectations for agencies under the Privacy Act 2020; it does not approve or endorse any AI tool or vendor and expects a privacy assessment before an agency uses AI on personal information.
Datatilsynet has run a regulatory sandbox for responsible AI since 2020, with generative AI a focus area, and publishes exit reports and guidance materials from sandbox projects plus its AI-and-privacy report.
MTCIT’s 2025 AI policy requires AI governance respecting privacy, data-misuse risk controls, decision documentation and compliance reports to regulators. It is cross-sector and not legal-sector specific.
The PDPC's Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems (issued 1 March 2024) apply the PDPA to AI development, testing, deployment and procurement, covering the business-improvement and research exceptions, consent and notification, and vendor obligations.
The Information Commissioner maintains an AI section with a frequently-asked-questions page updated in 2026 on the AI Act, its interplay with the GDPR and the Digital Omnibus. It is general rather than legal-sector specific.
The Personal Information Protection Commission publishes AI privacy guides, most recently a public-sector AI privacy protection guide posted on 31 August 2026. These are general rather than legal-sector-specific.
AEPD guidance on agentic AI of 18 February 2026 for controllers and processors deploying AI agents, plus its earlier guide on adapting AI processing to the GDPR. It is not legal-sector specific but is relied on by the Madrid Bar.
IMY published 'GDPR vid användning av generativ AI' (2024) and a two-part GDPR-and-AI guidance on its innovation portal; Digg and IMY jointly issued guidance on generative AI in public administration. IMY also runs a regulatory sandbox.
The FDPIC holds that the revised DSG (in force 1 Sep 2023) is technology-neutral and directly applicable to AI-based processing — statements of 9 Nov 2023 and 8 May 2025, plus 2023 guidance on ChatGPT-type applications and a 20 Mar 2025 position on X/Grok training data. Requirements: transparency about purpose, functioning and data sources; the right to object to an automated decision and to know one is dealing with a machine; DPIAs for high-risk uses.
The PDPA B.E. 2562 (2019) is the binding baseline. ETDA's AI Governance Practice Center publishes AI ethics and impact-assessment material, including an Ethical Impact Assessment playbook and an AI Job Redesign guideline. AI-specific PDPC guidance could not be verified because the regulator's site returned HTTP 403.
KVKK 'Generative AI and the Protection of Personal Data Guide (in 15 Questions)', Publication No. 113, published 24 Nov 2025, 64 pages, covering lawful basis, transparency, cross-border transfer, data-subject rights and security across the model lifecycle. It supplements KVKK's 2021 Recommendations on Personal Data Protection in the Field of AI.
Article 20 of the data-protection law, on the right to review of automated decisions, applies. The ANPD ran a public call for input on AI and automated-decision review from November 2024 to January 2025 as item 7 of its regulatory agenda; the resulting regulation has not been issued.
Public reports describe a Data Protection Bill to safeguard privacy and personal data, aligned with SADC model laws; no enacted data-protection law or AI-specific DPA guidance was located.
The Ministry says first-stage tools will include recommendations on personal-data processing. No final AI-specific guidance from a Ukrainian data-protection authority was located.
Zambia Monitor reports Cabinet approval in principle on 24 April 2025 for a Bill to repeal the 2021 Data Protection Act and expand data law to AI, machine learning and analytics. No bill text or enacted AI-data rule was located.
Law No. 124/2024 and Commissioner enforcement apply to automated processing and profiling generally. No AI-specific Commissioner guidance for legal services or lawyers was located.
The AI Strategy and ministry statements address privacy and standards, but no AI-specific data-protection authority guidance for legal services was located.
Belarus has a personal-data law and National Personal Data Protection Centre, but no AI-specific data-protection guidance for legal services was located.
General habeas-data and privacy remedies exist; no AI-specific data-protection authority guidance relevant to legal services found as of 4 September 2026.
Botswana’s data-protection regime covers processing by automatic means, but no Information and Data Protection Commission guidance applying it specifically to AI or legal services was located.
CPDP was checked as Bulgaria's data-protection authority. No AI-specific CPDP guidance for legal services or lawyers was located; GDPR and national data-protection rules apply generally.
No AI-specific data-protection guidance relevant to legal services found as of 4 September 2026; the new personal data protection agency created by Ley 21.719 is not yet operative.
No legal-sector-specific guidance. The Personal Information Protection Law of 2021 and the Cyberspace Administration interim measures, which protect user inputs and grant deletion rights, apply generally.
ÚOOÚ's site was checked on 4 September 2026 and carries no dedicated AI guidance section; its AI coverage relays EDPB output (e.g. a 9 July 2026 item on the EDPB anonymisation and generative-AI web-scraping guidelines). No legal-sector-specific AI guidance found.
The Organic Law on Personal Data Protection of 2021 applies; no AI-specific guidance from the data protection superintendence relevant to legal services found as of 4 September 2026.
The National AI Policy links data governance to the Personal Data Protection Proclamation, but no authority guidance applying data-protection rules specifically to AI in legal services was located.
The Data Protection Act 2012 (Act 843) applies generally; no Data Protection Commission guidance specific to AI was found on dataprotection.org.gh as of 4 September 2026.
No data-protection guidance specific to legal AI found as of 4 September 2026. The Digital Personal Data Protection Act 2023 is being commenced in phases and the Gujarat High Court policy is to be read with it once in force. MeitY's governance guidelines are non-binding and sector-agnostic.
No comprehensive data-protection law, data-protection authority or AI-specific privacy guidance for legal services was located; secondary legal material reports privacy rules remain underdeveloped.
No Garante guidance specific to AI in legal services found as of 4 September 2026; the GDPR and the Garante's general AI enforcement apply. The research budget was exhausted before the Garante site could be checked directly.
The 2023 Personal Data Protection Law applies generally, but no data-protection authority or MoDEE guidance applying it specifically to AI in legal services was located.
The Data Protection Act 2019 applies generally, including rights against solely automated decisions, but the ODPC has issued no AI-specific guidance note. Its published guidance-note list (checked 4 September 2026) covers DPOs, sectors, DPIAs, consent and biometrics only.
The Information and Data Protection Commissioner holds AI Act supervisory powers for certain high-risk and prohibited uses, but no guidance specific to legal AI was found as of 4 September 2026.
No data-protection authority guidance addressed to AI in legal services found as of 4 September 2026. General personal-data legislation applies; supervision was reorganised after the 2024-2025 constitutional reform abolished INAI.
The NCPDP is Moldova's data-protection authority, and the White Paper includes data privacy as an AI requirement. No AI-specific NCPDP guidance for legal services was located.
Montenegro's data-protection law applies generally. Schoenherr reported the data-protection agency had not officially addressed AI privacy concerns; no legal-sector AI guidance was located.
INTIC covers cyber and data-governance functions, but no AI-specific data-protection guidance or standalone data-protection authority guidance for legal AI was located.
The Law on Personal Data Protection regulates automated decision-making generally, but CMS found no AI-specific regulatory oversight or guidance, and no legal-sector AI guidance was located.
The Personal Data Privacy Protection Law (Law No. 13 of 2016) applies, but no AI-specific data-protection guidance relevant to legal services was found as of 4 September 2026.
Russia's personal-data and information laws are cited in the National AI Strategy, but no Roskomnadzor or legal-sector AI processing guidance for lawyers was located.
Rwanda has general data-protection law and justice-sector AI training, but no data-protection authority guidance specifically applying data rules to legal AI was located.
Serbia's GDPR-aligned Personal Data Protection Law applies generally. No Commissioner guidance specifically addressing AI processing in legal services was located.
The Personal Data Protection Act No. 9 of 2022 has been enforced since 18 March 2025; the Data Protection Authority has published no AI-specific or legal-sector-specific guidance as of 4 September 2026.
The PDPC homepage confirms general personal-data oversight under the Personal Data Protection Act, Chapter 44; no PDPC guidance on AI or legal-service AI processing was located.
Uganda’s Data Protection and Privacy Act applies generally, but no Data Protection and Privacy Office guidance on AI or legal-service AI processing was located.
There is no federal comprehensive data-protection statute and no federal DPA guidance addressed to AI in legal services; confidentiality of client data is handled through professional conduct rules (ABA Formal Opinion 512) rather than privacy regulation.
Zimbabwe’s cyber and data-protection framework applies generally, but no POTRAZ or legal-sector guidance applying it specifically to AI was found as of 4 September 2026.
A Personal Data Protection Ordinance was reported in 2025 but could not be verified within the research budget; no AI-specific regulator guidance was found.
The Data Protection Ombudsman's site (tietosuoja.fi) was unreachable throughout research, so the existence and scope of any Finnish DPA generative-AI guidance could not be confirmed. Treat as not yet researched.
Not researched — no Data Protection Commission guidance specific to AI in legal services was checked in this pass; the GDPR and the DPC's general AI work apply.
Whether Datu valsts inspekcija has issued generative-AI guidance could not be determined; its site surfaced no AI section during research and could not be searched.
UODO has commented on AI in public statements, but no dedicated UODO guidance on generative AI applicable to the legal sector was confirmed within the research budget.
The data-protection commission is reported to have warned in May 2025 about personal data in AI training and to lead an international generative-AI working group, but no document specific to legal services was located. CSM Recommendation 9 sets GDPR principles for judges' AI use.
The ANSPDCP homepage was checked on 4 September 2026 and showed no dedicated AI guidance or news; deeper sections could not be searched, so absence is not established.
Not researched — the Úrad na ochranu osobných údajov site could not be checked. The SAK rules themselves import GDPR Art. 28 processor requirements for legal AI.
POPIA applies to AI processing by firms and courts, but Information Regulator guidance specific to AI was not located within the research budget. Not fully checked as of 4 September 2026.
Ley 18.331 applies; whether the data-protection regulator has issued AI-specific guidance could not be checked against official sources in this research window.
Vietnam has a Law on Personal Data Protection (2025) and Decree 13/2023/ND-CP, but neither official text could be opened from this environment (moj.gov.vn returned HTTP 403 and the government gazette portal search could not be driven), so no AI-specific application is recorded.
Cite this page
SafeLegalAI Legal AI Regulation Tracker, "Data protection and legal AI" by country, https://safelegalai.com/regulation/category/data-protection (accessed 2026-09-04). Data: CC BY 4.0.
SafeLegalAI is a research publication by Cognesio LLP, not a law firm. Nothing here is legal advice, and no lawyer–client relationship arises from reading it. Rules change; always check the official document linked on each record and take advice on your own situation. Researched and drafted with AI assistance; verified against primary sources and edited by Cognesio LLP. The linked official documents are the record — our summaries are not the law and are not legal advice.