"We already have a privacy policy — doesn't that cover our AI?" It's one of the most common things we hear, and it's an understandable mistake. But a GDPR privacy notice and an AI transparency statement are two different documents doing two different jobs. Leaning on one to cover the other leaves a real gap.
This article explains what each document is for, where they overlap, and how to make sure they agree with each other. It's written for people who run organisations, not for lawyers.
This article is general information, not legal advice. It does not constitute legal advice, and Vedomia does not provide legal services. For legal questions about your specific situation, speak to a qualified solicitor.
Two documents, two questions
The simplest way to keep them straight is to notice that they answer different questions for the reader.
A privacy notice answers: "What do you do with my personal data?" It exists because of data-protection law (the GDPR). It's about information about people — what you collect, why, on what legal basis, how long you keep it, who you share it with, and the rights people have over it.
An AI transparency statement answers: "Where and how are you using AI, and who's responsible for it?" It sits closer to the EU AI Act and to plain trust. It's about the systems you use — where AI shows up in how you work and communicate, whether it makes decisions, who reviews its output, what its limits are, and how someone can reach a human.
A privacy notice is about your data. An AI transparency statement is about your machines. They meet in the middle, but neither replaces the other.
Where they overlap — and where they don't
They genuinely overlap in one important place: when AI is used to make or heavily influence a decision about a person using their personal data. That situation is covered from both directions — by data-protection rules on automated decision-making, and by the AI Act's transparency thinking. The overlap is real, but the rules are described as parallel but distinct: satisfying one does not automatically satisfy the other.
Now the parts that fall outside a privacy notice — and this is where the gap opens:
- A website chatbot that answers general questions. If it isn't processing personal data, your privacy notice may say nothing about it — yet a person still has an interest in knowing they're talking to a machine.
- AI that drafts your newsletters, reports or social posts. No personal data of service users need be involved, so the privacy notice is silent — but your funders and readers increasingly want to know whether a person stands behind what you publish.
- AI-generated images or video in a campaign. A data-protection document isn't the natural home for "this image was AI-generated."
- Who reviews the AI, and what its limits are. Human oversight and honest limits are the heart of an AI transparency statement. They have no obvious slot in a privacy notice at all.
So the privacy notice covers the data corner of your AI use. The transparency statement covers the whole picture — including all the AI that never touches personal data but still shapes what people see and trust.
The overlap you must not get wrong: automated decisions
There's one area where the two documents have to speak to each other carefully. Under data-protection law, decisions made solely by automated means that have a legal or similarly significant effect on a person are tightly restricted, and people have a right to meaningful information about the logic involved and to human intervention.
For most charities, the safe and honest position is simple: no decision about a person's services, eligibility or funding is made by AI alone — a person decides. If that's true for you, say it plainly in both documents. If it isn't — if AI is making or largely determining decisions about people — that is exactly the moment to get proper advice before you write anything, because you may be in the automated-decision-making territory that carries specific duties.
Rule of thumb: a chatbot that gives information is a transparency matter. An AI that decides who gets a service, a grant or a place is a data-protection and a transparency matter — and a "get advice" matter. Know which one you're dealing with.
The consistency trap
Here's the failure we see most often: the two documents exist, but they quietly contradict each other. The privacy notice, updated last year, says the organisation "does not use automated decision-making." The new AI page describes a screening tool that clearly does. Or the transparency statement promises "a human reviews every published text," while the privacy notice never mentions the drafting tool at all.
Inconsistency is worse than a gap, because it reads as either carelessness or concealment — the opposite of what either document is for. Whenever you touch one, check the other.
A practical four-step plan
Step 1 — Inventory your AI, once
List every place AI is used: one row per use, noting whether it touches personal data. This single list feeds both documents and saves you doing the work twice. It's also the same inventory you need for AI literacy and human-oversight duties.
Step 2 — Split each use into "data" and "system"
For each AI use, ask two questions. Does it process personal data? If yes, it needs to be reflected in your privacy notice. Does a person ever encounter it, or does it shape what we publish or decide? If yes, it belongs in your AI transparency statement. Many uses answer "yes" to both — and that's fine, as long as the two documents describe them the same way.
Step 3 — Write, or update, the AI transparency statement
If you don't have one yet, this is the document most organisations are missing. It should cover: where you use AI, why, what data it touches, who oversees it, its limits, and a contact point for questions — dated, and in plain language.
Step 4 — Reconcile the two documents
Read them side by side. Every claim about AI and personal data must match. Cross-link them: the privacy notice can point to the AI transparency statement for the fuller picture, and vice versa. Date both. Set a reminder to revisit whenever an AI tool changes.
A quick side-by-side
Privacy notice vs AI transparency statement
| Privacy notice | AI transparency statement | |
|---|---|---|
| Core question | What do you do with my personal data? | Where and how do you use AI, and who's responsible? |
| Driven by | Data-protection law (GDPR) | EU AI Act thinking + trust with your public |
| Covers | Data you collect, why, legal basis, retention, sharing, rights | AI uses, purpose, oversight, limits, contact — incl. AI that touches no personal data |
| Blind spot | AI that doesn't process personal data; human oversight; limits | Full detail of data rights and legal bases |
| They must agree on | Automated decision-making and any AI that processes personal data | |
How Vedomia can help
Vedomia is an Irish company focused on one thing: helping organisations make their processes and their use of AI visible, explainable and auditable. We work mainly with charities, nonprofits and publicly funded organisations.
The AI transparency statement is exactly the kind of document we help organisations build — clear, public, consistent with the rest of your governance, and grounded in what you actually do.
- Transparency Self-Audit (free). Around 20 questions across four pillars — Visibility, Sequence, Justification, Auditability. It helps you see where AI is used and where your public communication about it is thin.
- Free AI Transparency Statement template. A ready-to-fill statement built for Irish charities, with guidance on each section — a good companion to this article.
To be clear about what we do and don't do: Vedomia supports readiness, helps you document your AI use, and identifies transparency gaps. We do not certify compliance, and nothing we provide guarantees legal conformity. This is not legal advice — where automated decision-making about people is involved, get a legal opinion.
You probably already have a privacy notice. The document most organisations are missing is the one that tells people, in plain words, where their AI lives and who stands behind it.
This article is general information about data protection and the EU AI Act, and does not constitute legal advice.
Prepared with the help of an AI assistant, reviewed by Sandra Fedakova.
Not sure whether your AI is properly explained to the people you serve?
Take the Free Transparency Self-Audit