| Scope | The GDPR text and guidance cited on this page support concrete privacy obligations for AI-enabled personal-data processing. | The AI Act governs the placing on the market, putting into service, and use of AI systems in the Union. It also reaches specified providers and deployers outside the Union when system output is used in the Union, subject to its exclusions and special scope rules. | Run GDPR scope on each personal-data operation and AI Act scope on the system and operator. Either regime can apply without the other. |
|---|
| Who must act | GDPR work belongs to the controller or processor role for the AI processing activity, with input from product, privacy, legal, security, procurement, support, and the DPO where designated. | AI Act duties attach to roles such as provider, deployer, importer, distributor, product manufacturer, and authorised representative. A provider develops or has a system developed and places it on the market or puts it into service under its name or trademark; a deployer uses a system under its authority outside personal non-professional activity. | Record both role maps. A company may be a deployer under the AI Act and a controller under GDPR, or a provider under the AI Act and a processor for a customer's personal data. |
|---|
| Trigger | GDPR is triggered when the AI workflow processes personal data within GDPR scope, including collection, storage, use, disclosure, profiling, retention, transfer, or deletion. | AI Act duties depend on the system and use: prohibited practices under Article 5, high-risk classification under Article 6 and Annexes I and III, transparency duties under Article 50, or rules for general-purpose AI models under Chapter V. | Start with two triggers: whether personal data is processed and which AI Act category applies. Do not infer one answer from the other. |
|---|
| Core obligations | Each AI processing purpose needs an Article 6 lawful basis, privacy information, rights handling, Article 22 analysis where relevant, DPIA screening or DPIA, RoPA coverage, processor controls, security measures, retention, and transfer safeguards where applicable. | High-risk AI providers face requirements for risk management, data and data governance, technical documentation, logs, transparency to deployers, human oversight, accuracy, robustness, cybersecurity, quality management, conformity assessment, registration, and post-market monitoring. Deployers have separate instructions, oversight, monitoring, logging, and other duties. Other systems may have narrower transparency or model-provider duties. | Build the AI Act obligation list from the role and category. Keep the GDPR lawful-basis, notice, rights, DPIA, processor, security, retention, and transfer record alongside it. |
|---|
| Evidence and records | GDPR evidence should include a lawful-basis note, privacy notice text, RoPA entry, DPIA or DPIA screening, Article 22 assessment where relevant, rights workflow, processor terms, security control record, transfer safeguard, retention rule, and breach triage record. | AI Act evidence can include classification rationale, quality and risk-management records, data-governance decisions, technical documentation, automatically generated logs, instructions for use, human-oversight design, conformity records, registration, post-market monitoring, and serious-incident records, depending on role and category. | Reuse inventories, security records, vendor files, and logs only where they contain the information required by both regimes. A GDPR DPIA is not automatically an AI Act conformity assessment or fundamental-rights impact assessment. |
|---|
| Timing and cadence | GDPR timing is tied to the processing lifecycle: lawful basis and notice before processing, DPIA before high-risk processing, Article 22 and rights handling before automated decisions affect people, breach assessment without undue delay and where feasible within 72 hours for notifiable breaches, and RoPA updates when the processing changes. | The AI Act entered into force on 1 August 2024. Definitions, the original prohibitions, and AI-literacy duties applied from 2 February 2025; specified governance, penalties, and GPAI duties applied from 2 August 2025; and Article 50 applies from 2 August 2026. Regulation (EU) 2026/1744 entered into force on 27 July 2026, made its added Article 5 provisions applicable from 2 December 2026, and amended Article 113 so that Chapter III, Sections 1, 2, and 3, except Article 6(5), apply from 2 December 2027 for Article 6(2) and Annex III high-risk systems and from 2 August 2028 for Article 6(1) and Annex I high-risk systems. | Calendar GDPR controls around the processing lifecycle. For each AI Act obligation, record the applicable article, transition rule, source date, current legal status, and any amending act. |
|---|
| Enforcement or assurance route | GDPR supervisory authorities can impose Article 58 corrective measures and Article 83 fines. The lower ceiling is EUR 10 million or 2 percent of worldwide annual turnover for an undertaking, whichever is higher; the upper ceiling is EUR 20 million or 4 percent, whichever is higher. The amount remains case-specific and requires an intentional or negligent infringement. | The AI Act uses national competent and market-surveillance authorities, while the Commission and AI Office enforce GPAI-provider duties. Article 99 ceilings include EUR 35 million or 7 percent for prohibited-practice infringements, EUR 15 million or 3 percent for specified other infringements, and EUR 7.5 million or 1 percent for incorrect, incomplete, or misleading information, with special undertaking and SME rules. Article 101 allows GPAI-provider fines up to 3 percent of total worldwide annual turnover in the preceding financial year. | Open separate regulator and sanctions tracks. Identify the exact infringement, authority, legal ceiling, undertaking rule, and applicable transition date under each regime; the same conduct can engage both without one fine automatically displacing the other. |
|---|
| Overlap and reuse | GDPR evidence can overlap with AI governance records when the same inventory, vendor file, security control, log, or transfer record describes personal-data processing. | AI Act records can reuse factual material from GDPR inventories, DPIAs, vendor reviews, security controls, and logs when the material also meets the relevant AI Act content and retention rule. | Article 2(7) preserves EU privacy and data-protection law, and Article 27(4) says an AI Act fundamental-rights impact assessment complements a GDPR DPIA where both are required. Reuse verified facts, but preserve each assessment's trigger, content, owner, outcome, authority route, and update rule. |
|---|
| Practical decision rule | For every operation involving personal data, issue a GDPR processing finding that names the controller and processor, purpose, Article 6 basis, Article 9 condition where needed, notice, rights and Article 22 result, DPIA result, RoPA entry, retention, security, processors, transfers, and launch conditions. | For every candidate AI function, issue an AI Act classification finding that applies the Article 3 AI-system definition, maps provider and deployer roles, tests Article 5 prohibitions, applies Article 6 and the relevant annex, tests Article 50 and GPAI duties, and records the controlling application date and transition rule. | The approval record contains two conclusions and two owners. Link shared facts and evidence by identifier, list unresolved assumptions, and block launch when either finding has an unmet legal condition; do not merge the conclusions into a generic 'AI compliant' status. |
|---|