Treat translation and localisation as an explicit part of your governance: record per jurisdiction which language version of policies, notices, DPIAs and AI output is in use, who approves them and how the legal meaning is preserved. An English-language policy does not equal compliance in countries with a different language and legal culture.
The occasion is a DPO-oriented resource from the International Association of Privacy Professionals (IAPP), titled The AI you didn't build: From black box to defensible risk. That piece describes how data protection officers have to make AI systems they did not build themselves defensible after all towards supervisory authorities and data subjects — documentation, risk narratives and interfaces that often arrive in one language and have to be understood per country. In our assessment, that makes multilingual communication a structural governance question, not an operational side matter.
Why does multilingual communication pose a governance risk with AI you did not build yourself?
Anyone deploying an external AI system inherits not only the model but also the documentation around it. The IAPP points out that a DPO has to be able to explain output to a local supervisory authority, a works council or a data subject. If the policy is in English, the privacy statement in the local language and the AI interface uses a mixed form, the risk arises that consent, transparency and risk assessment start to diverge per jurisdiction.
This is our editorial analysis, not a source claim: the problem is not the translation itself, but the absence of a recorded chain. Without a register of which language version is in use where and who approved it, you cannot demonstrate afterwards that the meaning remained consistent. This plays out more strongly the more transparency obligations from both the GDPR and the EU AI Act (Regulation (EU) 2024/1689) have to be understandable in different languages for data subjects. Anyone linking this to the question of where the prompts from your AI workflow go sees that language and data flow share the same control problem.
How do the EDPB and CNIL treat language and accessibility as part of compliance?
Supervisory authorities now treat understandable communication as core to compliance. In its work programme 2026-2027 the European Data Protection Board announces it will ease compliance with templates, examples, checklists, FAQs and "how-to" guides for non-experts, spread across the languages of the EU. The underlying idea: if data subjects and local staff do not understand the obligations, compliance effectively does not exist, however good the central policy may look in a single language.
That multilingual character also sits in the structure of the guidelines themselves. The EDPB documents portal publishes core guidelines in several EU languages. National authorities build on top of that: the French CNIL describes its own Guidelines and recommendations expressly as a complement to the EDPB guidelines, with interpretation elements and practical recommendations in the local language. For an organisation operating in several countries, this means that an EDPB guideline on consent and a CNIL recommendation on cookies have to be reconciled with one another — in different languages and legal cultures.
Which governance controls do I need for multilingual privacy documents?
In its Global Legislative Predictions 2026, the IAPP points out that AI and privacy rules are spreading across, among others, Latin America and Asia-Pacific, each with its own language and legal conceptual framework. Our recommendation is therefore to treat multilingualism as an explicit governance object. Specifically:
- Authorised translation and localisation workflows for privacy statements, DPIAs, records of processing and AI governance documents: who may translate, how versions are approved and how the legal meaning is preserved.
- Multilingual training so that front-line staff understand the privacy and AI obligations in their working language, not only through central English-language material.
- Language-aware incident and DPIA processes in which risks are recorded consistently across languages and in which translation errors count as a governance issue.
- A register per jurisdiction of which language version of which document is in use, with translation and approval history.
This logic aligns with recording GDPR responsibilities per phase of your generative-AI workflow. Anyone who includes language in that avoids a well-considered framework being correct only in the source language. You will find more background on this subject in the topic hub on AI privacy and GDPR in professional practice.
How do I keep multilingual AI output and verification consistent per jurisdiction?
A particular point of attention is the AI output itself. Privacy statements, consent dialogues and explanations that an AI system generates must be correctly localised and must not acquire different meanings per language. That also touches on the transparency requirements the EU AI Act places on AI systems, which after all have to be understandable in the data subject's language. Anyone who has AI process confidential documents without losing the context otherwise runs the risk that the meaning falls away precisely at the translation step.
A verification layer can support this without taking over the responsibility. IamVera.ai is not a chatbot and not its own language model, but a privacy-focused verification layer that can, per workflow and jurisdiction, give more insight into which language versions of policies, notices and AI configurations are in use, and where translation and approval steps are recorded. The pre-processing and anonymisation via the Semantic Privacy Shield take place on EU infrastructure; the workflow is designed to send only anonymised content to the selected models, and when a privacy check fails nothing is forwarded. Such tools make control possible, but do not verify correctness on your behalf and do not take over the final judgement: that remains with the professional who has to be able to defend the multilingual governance.
Sources and references
Sources: The article draws on the EDPB work programme 2026-2027, the EDPB documents portal, the CNIL guidelines and the Global Legislative Predictions 2026 and a DPO resource from the IAPP.