Free Webinar

What the EU AI Act and GDPR require of EHS teams

Oct 8, 2026
10:00 am
UTC+2
On-demand webinar

Using AI responsibly in EHS: what applies now, and how to prepare for it

AI is already part of EHS work: embedded in software, used for risk and incident analysis, and increasingly applied through general-purpose AI tools. At the same time, EHS teams process some of the organisation’s most sensitive information, including accident reports, health data, workplace observations and information about employee conduct. This creates two connected compliance questions: Does the processing meet GDPR and national employment-law requirements, and how does the EU AI Act classify the AI use case? In this practical session, privacy lawyer and Group Data Protection Officer Inna Gendelman will explain what EHS teams need to recognise, document and challenge.
Key Insights
  • GDPR requirements in daily EHS work: Translate transparency, data minimisation, access control, retention, accountability and individual rights into practical EHS controls.
  • AI Act risk classification: Distinguish between limited-risk use cases, potentially high-risk worker-related systems and practices that may be prohibited.
  • Clear internal responsibilities: Understand how EHS, Legal, the DPO, IT Security, HR and employee representatives contribute to a compliant process.
  • AI in EHS: Identify AI already embedded in EHS software as well as the use of general-purpose AI outside approved systems.
  • denxpert enhanced with AI: What the platform does today, and what is coming next.
Webinar starts in:
00
days
00
hours
00
minutes
00
seconds
Free Webinar

The regulatory picture: GDPR, the EU AI Act and the EHS context

GDPR applies whenever an EHS process uses personal data. Depending on the use case, this may include employment data, health information, incident reports, witness statements, training records, location data, photographs or information generated by sensors and monitoring tools.

The EU AI Act adds a separate, risk-based layer. Many supportive uses of AI will not qualify as high-risk. However, AI that monitors or evaluates workers, influences working conditions, allocates tasks based on personal characteristics or acts as a safety component of a regulated product may require closer assessment. Certain uses, including emotion recognition in the workplace, may be prohibited except under narrow conditions.

For EHS teams, the practical challenge is therefore not simply determining whether a product contains AI. They need to understand the purpose, the affected people, the data involved and how the output influences real decisions.

The focus is not on turning EHS professionals into lawyers, but on helping them ask the right questions, involve the right experts and design processes that can withstand legal and operational scrutiny.

AI in denxpert

At the end of the session we will show how this works in practice. denxpert AI runs in a closed environment on our own AI setup, so your data stays inside your denxpert system, and answers draw on the EHS knowledge base we have been building for over 20 years.

What you will take away

Participants will leave with a practical framework for reviewing EHS processes involving personal data and AI. You will learn how to map the relevant data flow, identify the questions that require support from Legal, the DPO or IT Security, recognise potentially sensitive AI use cases and assess whether your existing documentation and controls are sufficient.

The session concludes with an EHS legal challenge checklist that teams can use when introducing new software, activating AI functionality or reviewing existing processes.

Who should join

EHS leaders and managers, compliance professionals, Data Protection Officers, privacy and employment-law specialists, HR professionals, IT and information-security decision-makers, AI governance teams and organisations introducing or operating AI-enabled EHS systems.

Experts

Our Experts

Join our leading sustainability experts and gain the insights, tools, and guidance needed to excel in ESG, EHS&S, and CSRD compliance.
Inna Gendelman
Privacy Lawyer | Group Data Protection Officer | Mentor for Privacy and AI Governance Leaders
Inna Gendelman is a German-trained privacy lawyer with 11 years of experience in data protection, digital business and organisational governance. As a Group Data Protection Officer, she has built and led privacy programmes across complex corporate structures, translating legal requirements into processes that work in daily operations. Through training and one-to-one mentoring, Inna supports Data Protection and AI Governance professionals in building effective management systems, leading internal coordinator networks and strengthening their role within the organisation. Her focus is on practical implementation: connecting legal requirements with business processes, technology and organisational responsibilities, and making privacy and responsible AI part of company culture rather than a compliance checkbox. More: gendelman.de
Szücs-Winkler Róbert
CEO, Denxpert
Robert, CEO and founder of Denxpert, has 20+ years of experience in sustainability, ESG, and EHS. He leads a team delivering tailored software to 2,000+ sites across industries, supporting compliance and performance with data-driven insights. His clients include Hungary’s top companies and multinationals in 30+ countries.