The OECD.AI Policy Navigator

Our policy navigator is a living repository from more than 80 jurisdictions and organisations. Use the filters to browse initiatives and find what you are looking for.

Guidance on Generative Artificial Intelligence and the Protection of Personal Data (in 15 Questions)


Added by:   OECD analyst
Added on:   06 Oct 2026
Updated by:   OECD analyst
Updated on:   06 Oct 2026

This initiative provides guidance on how personal data should be handled throughout the lifecycle of generative AI systems. It is intended for organisations and individuals who develop, deploy or use generative AI systems that may process personal data. The guideline was developed to address privacy risks arising from the adoption of generative AI systems and to promote responsible and rights-respecting use of these technologies.

Name in original language

Üretken Yapay Zekâ ve Kişisel Verilerin Korunması Rehberi (15 Soruda)

Initiative overview

The rapid spread of generative AI systems has increased the scale and complexity of data processing across many sectors. These systems often rely on large and diverse datasets and generate new content in ways that may affect privacy, transparency and accountability. This raises considerations about how personal data should be protected when generative AI systems are developed and used.

The objective of the initiative is to support the protection of personal data in the context of generative AI systems by providing practical guidance. It aims to promote a privacy-respecting approach throughout the lifecycle of generative AI, and to help organisations and other actors understand how to apply data protection regulations when developing, deploying or using these systems.

In the future, the guideline is expected to remain available as a general reference for understanding data protection considerations related to generative AI systems. It may be used by interested stakeholders as a non-binding source of information when considering privacy issues throughout the lifecycle of generative AI systems.

This document does not establish new obligations and is intended to complement the existing data protection framework.

About the policy initiative


Category:

  • Regulations, guidelines and standards

Initiative type:

  • Guidance document (instructions on how to implement a law, regulation, policy or other rule)

Status:

  • Inactive – initiative complete

Start Year:

  • 2024

End Year:

  • 2025

Binding:

  • Non-binding

Target Sectors:


Other relevant urls:

—