Skip to content
Amended. Regulation (EU) 2026/1744 entered into force 27 July 2026. See what moved →
EU AI Act ChecklistIndependent reference
Role guide · DPO

EU AI Act for the DPO

The AI Act will land on your desk because you are the nearest existing function. Four parts of it genuinely belong to you. The rest is product, engineering and quality work with no privacy analogue, and accepting it anyway is the most common way an AI Act programme fails.

Arts. 10(5), 27, 50, 86GDPR Arts. 9, 22, 35

What lands on you, and what does not

Ownership boundaries are the most useful thing to settle early. Expert analysis: the Regulation names organisations, not job titles.

ObligationYours?Note
Art. 27 FRIAYes: you will run itDeployer obligation. Complements a DPIA; does not replace it
Art. 10(5) special category data for bias testingYesThe conditions are privacy conditions
Art. 86 right to explanationShared with legalSits alongside GDPR Art. 22
Art. 50 transparencyNo: advise onlyA product-surface obligation. A privacy notice does not satisfy it
Arts. 9, 11, 15, 17, 43NoRisk, documentation, security, quality, conformity. No privacy analogue
Art. 49 registrationNoProvider or public-authority deployer function
Art. 73 incident reportingAdviseDifferent authority, different deadlines from a personal data breach

Where this usually goes next

Three situations account for most people reading this page. Each has a different answer.

A deal is blocked on an AI questionnaire

Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.

How this works for AI companies →

You need ISO/IEC 42001 documentation

23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.

Free gap assessment →
See the three tiers →

You are not sure what reaches you

Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.

Book a free 20-minute call →

This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →

Accepting the whole Act is how it fails

AI Act work lands on privacy teams because they are the closest thing most organisations have to a horizontal compliance function. That works for the four overlaps and fails everywhere else.

Conformity assessment, CE marking, Annex IV technical documentation, post-market monitoring and the Article 17 quality management system are product safety obligations. They are executed by engineering and quality functions and they have no privacy analogue. A DPO who accepts ownership of them will be held accountable for work they cannot perform and cannot resource.

Practical recommendation. Take the four overlaps explicitly and in writing. Name an owner for everything else, in the same document. The value you add here is the accurate scoping, not the heroics.

FRIA complements a DPIA: it does not discharge it

Article 27(4) says that where FRIA obligations are already met through a DPIA under GDPR Article 35, the FRIA complements that DPIA. That is duplication avoidance, not substitution.

What a DPIA will not have produced: the description of the deployer’s processes in which the system is used, the period and frequency of intended use, the categories of persons and groups likely to be affected, the human oversight implementation, and the measures if risks materialise. Nor will it have been notified to a market surveillance authority, which is a different regulator from your DPA.

Run one assessment producing two outputs. Full comparison →

Your first 30 days

  1. Write the scoping memo. Four overlaps yours, everything else named to an owner. Get it signed.
  2. Identify who owes an Article 27 FRIA: public bodies, private entities providing public services, and deployers of Annex III 5(b) credit and 5(c) life and health insurance.
  3. Check Article 50 on the product surface, not in the privacy notice. It has applied since 2 August 2026.
  4. Review the Art. 10(5) position if any team is testing for bias using special category data: the conditions are strict and the deletion duty is real.
  5. Map your DPIA template to the Article 27 elements so the second output is generated rather than rewritten.

Questions worth asking

  • Who owns conformity assessment, and do they know?
  • Which deployments trigger Article 27, and has anyone told the deployer?
  • Does the product actually disclose it is AI, at first interaction?
  • Are we processing special category data for bias testing, and under what conditions?

Status labels on this page

Verified fact: Article references, dates and penalty tiers cited above, checked against the consolidated Regulation and the Commission's AI Act Service Desk.

Expert analysis: The ownership allocation, the failure modes, and the 30-day sequence — all our practice rather than the text.

Unsettled: Harmonised standards remain in development, and the Commission's Annex III guidelines are in draft. Both affect how these obligations will be evidenced.

Next step

One assessment, two outputs

The efficient structure produces the GDPR Article 35 elements and the Article 27 elements from a single evidence base, then generates two documents for two authorities.

Start with the inventory

Every role guide on this site converges on the same first step: a list of the AI systems, their intended purpose, their role and their tier.

Run the classifier →

Frequently asked

Is the EU AI Act a privacy law?

No. It is a product safety regulation that classifies AI systems by risk and imposes obligations on providers and deployers. It applies whether or not personal data is involved. It intersects with the GDPR at specific points, impact assessments, bias testing using special category data, automated decision-making and explanation rights, and transparency, but most of its obligations, including conformity assessment, technical documentation and quality management, have no privacy analogue.

Does a DPIA satisfy the Article 27 FRIA?

No. Article 27(4) provides that where FRIA obligations are already met through a DPIA under GDPR Article 35, the FRIA complements that DPIA. It avoids duplicated work but does not discharge the FRIA, which has its own prescribed contents and is notified to the market surveillance authority rather than the data protection authority.

Should the DPO own EU AI Act compliance?

Owning the whole Act is usually a mistake. Impact assessments, bias-testing conditions, explanation rights and transparency advice fit the role. Conformity assessment, CE marking, Annex IV technical documentation, post-market monitoring and quality management are product and engineering obligations that a privacy function cannot execute or resource.