EU AI Act and Data Privacy: GDPR Intersection Explained

By Recording Law Editorial Team18 min read
EU AI Act and Data Privacy: GDPR Intersection Explained

Frequently Asked Questions

Does the EU AI Act replace the GDPR for AI systems?

No. Recital 10 of Regulation (EU) 2024/1689 states expressly that the AI Act does not affect the application of existing EU data protection law, including the GDPR. AI systems that process personal data must independently satisfy both the AI Act and the GDPR. They are separate and overlapping regimes: GDPR governs how personal data is processed; the AI Act governs the risks posed by the AI system itself.

Which Article 5 prohibited practices are already in force?

All eight prohibited practices under Article 5 have been in force since 2 February 2025. These are: (a) subliminal or manipulative techniques that materially distort behaviour causing significant harm; (b) AI exploiting vulnerabilities of specific groups such as children or people with disabilities; (c) social scoring by public or private actors leading to detrimental treatment in unrelated contexts; (d) criminal risk assessment based solely on profiling or personality traits without objective factual grounding; (e) untargeted scraping of facial images to build or expand recognition databases; (f) emotion recognition in workplaces and educational institutions, except for medical or safety purposes; (g) biometric categorisation to infer protected characteristics such as race, religion, or sexual orientation; and (h) real-time remote biometric identification in public spaces for law enforcement, with narrow judicial-authorisation exceptions for serious crime, imminent terrorism, or victim searches.

What is a Fundamental Rights Impact Assessment (FRIA) and how does it differ from a GDPR DPIA?

A FRIA under Article 27 of the AI Act assesses the risks that a high-risk AI system poses to the full range of fundamental rights protected by the EU Charter, including privacy, data protection, non-discrimination, and rights in justice proceedings. A GDPR Data Protection Impact Assessment (DPIA) under Article 35 GDPR focuses specifically on risks to data subjects arising from personal data processing. Both are triggered by high-risk AI deployments involving personal data, but they are separate documents with different legal bases and different required content. Deployers that are public bodies or equivalent private operators may need to complete both before deploying a high-risk AI system.

When do the high-risk AI obligations actually apply?

Most high-risk AI obligations, including Article 10 data governance, Article 26 deployer duties, and Article 27 FRIAs, apply from 2 August 2026 for standalone high-risk systems listed in Annex III. High-risk AI systems embedded in regulated products covered by Annex I sectoral legislation (medical devices, machinery, etc.) have an extended transition until 2 August 2027. As of June 2026, these rules are not yet in force but organisations should be preparing actively.

How do AI Act penalties compare to GDPR fines?

The AI Act's highest penalty tier, for violations of the Article 5 prohibited practices, reaches EUR 35,000,000 or 7% of global annual turnover. The GDPR's highest tier reaches EUR 20,000,000 or 4% of global annual turnover. Both use the higher of the absolute and percentage figure. The AI Act also has a middle tier of EUR 15,000,000 or 3% for high-risk system non-compliance, and a lower tier of EUR 7,500,000 or 1% for misleading authorities. Organisations that violate Article 5 prohibitions will typically face concurrent GDPR enforcement as well, since those practices almost always involve large-scale biometric or behavioural data processing.

What does Article 10 of the AI Act require for training data?

Article 10 requires providers of high-risk AI systems to document and govern their training, validation, and testing datasets. This includes recording selection criteria and collection methodologies, examining data for potential biases, identifying data gaps, and ensuring data is free from errors and complete to the extent possible. Article 10(5) creates a narrow exception permitting the processing of GDPR special-category personal data in training sets strictly to detect and correct biases. These obligations apply from 2 August 2026 and complement, but do not replace, GDPR data minimisation and purpose-limitation requirements.

Who enforces the AI Act for law enforcement and justice AI systems?

Article 74(8) of the AI Act designates national data protection authorities as the competent market surveillance authorities for high-risk AI systems used in law enforcement, migration and asylum processing, and the administration of justice. For other high-risk sectors, member states designate separate national competent authorities. At the EU level, the EU AI Office oversees GPAI models, while the EDPB and EDPS provide advisory guidance on the intersection of the AI Act and data protection law.

Do General-Purpose AI providers like large language model developers have to comply now?

Yes. GPAI obligations under Articles 51 to 55 of the AI Act have been in force since 2 August 2025. All GPAI providers must publish training-data summaries, implement a copyright compliance policy, and publish technical documentation. Providers of models assessed as posing systemic risk (those trained on more than 10^25 FLOPs) face additional safety evaluation, incident reporting, and cybersecurity requirements. GDPR obligations for training data processing continue to apply alongside these AI Act requirements.

Sources and References

  1. Regulation (EU) 2024/1689 of the European Parliament and of the Council (EU AI Act) — Official Text, EUR-Lex(eur-lex.europa.eu)
  2. Regulation (EU) 2016/679 (GDPR) — Official Text, EUR-Lex(eur-lex.europa.eu)
  3. European Commission — AI Act Regulatory Framework Overview (digital-strategy.ec.europa.eu)(digital-strategy.ec.europa.eu)
  4. European Data Protection Board (EDPB) — Guidelines and Opinions on AI and Biometrics(edpb.europa.eu)
  5. European Data Protection Supervisor (EDPS) — Artificial Intelligence Supervision Page(edps.europa.eu)
  6. European AI Office — Official EU AI Office Portal (digital-strategy.ec.europa.eu)(digital-strategy.ec.europa.eu)
Share: