EU AI Act for the DPO
The AI Act will land on your desk because you are the nearest existing function. Four parts of it genuinely belong to you. The rest is product, engineering and quality work with no privacy analogue, and accepting it anyway is the most common way an AI Act programme fails.
What lands on you, and what does not
Ownership boundaries are the most useful thing to settle early. Expert analysis: the Regulation names organisations, not job titles.
| Obligation | Yours? | Note |
|---|---|---|
| Art. 27 FRIA | Yes: you will run it | Deployer obligation. Complements a DPIA; does not replace it |
| Art. 10(5) special category data for bias testing | Yes | The conditions are privacy conditions |
| Art. 86 right to explanation | Shared with legal | Sits alongside GDPR Art. 22 |
| Art. 50 transparency | No: advise only | A product-surface obligation. A privacy notice does not satisfy it |
| Arts. 9, 11, 15, 17, 43 | No | Risk, documentation, security, quality, conformity. No privacy analogue |
| Art. 49 registration | No | Provider or public-authority deployer function |
| Art. 73 incident reporting | Advise | Different authority, different deadlines from a personal data breach |
Where this usually goes next
Three situations account for most people reading this page. Each has a different answer.
A deal is blocked on an AI questionnaire
Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.
You need ISO/IEC 42001 documentation
23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.
You are not sure what reaches you
Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.
This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →
Accepting the whole Act is how it fails
AI Act work lands on privacy teams because they are the closest thing most organisations have to a horizontal compliance function. That works for the four overlaps and fails everywhere else.
Conformity assessment, CE marking, Annex IV technical documentation, post-market monitoring and the Article 17 quality management system are product safety obligations. They are executed by engineering and quality functions and they have no privacy analogue. A DPO who accepts ownership of them will be held accountable for work they cannot perform and cannot resource.
Practical recommendation. Take the four overlaps explicitly and in writing. Name an owner for everything else, in the same document. The value you add here is the accurate scoping, not the heroics.
FRIA complements a DPIA: it does not discharge it
Article 27(4) says that where FRIA obligations are already met through a DPIA under GDPR Article 35, the FRIA complements that DPIA. That is duplication avoidance, not substitution.
What a DPIA will not have produced: the description of the deployer’s processes in which the system is used, the period and frequency of intended use, the categories of persons and groups likely to be affected, the human oversight implementation, and the measures if risks materialise. Nor will it have been notified to a market surveillance authority, which is a different regulator from your DPA.
Run one assessment producing two outputs. Full comparison →
Your first 30 days
- Write the scoping memo. Four overlaps yours, everything else named to an owner. Get it signed.
- Identify who owes an Article 27 FRIA: public bodies, private entities providing public services, and deployers of Annex III 5(b) credit and 5(c) life and health insurance.
- Check Article 50 on the product surface, not in the privacy notice. It has applied since 2 August 2026.
- Review the Art. 10(5) position if any team is testing for bias using special category data: the conditions are strict and the deletion duty is real.
- Map your DPIA template to the Article 27 elements so the second output is generated rather than rewritten.
Questions worth asking
- Who owns conformity assessment, and do they know?
- Which deployments trigger Article 27, and has anyone told the deployer?
- Does the product actually disclose it is AI, at first interaction?
- Are we processing special category data for bias testing, and under what conditions?
Status labels on this page
Verified fact: Article references, dates and penalty tiers cited above, checked against the consolidated Regulation and the Commission's AI Act Service Desk.
Expert analysis: The ownership allocation, the failure modes, and the 30-day sequence — all our practice rather than the text.
Unsettled: Harmonised standards remain in development, and the Commission's Annex III guidelines are in draft. Both affect how these obligations will be evidenced.
One assessment, two outputs
The efficient structure produces the GDPR Article 35 elements and the Article 27 elements from a single evidence base, then generates two documents for two authorities.
Start with the inventory
Every role guide on this site converges on the same first step: a list of the AI systems, their intended purpose, their role and their tier.
Frequently asked
Is the EU AI Act a privacy law?
No. It is a product safety regulation that classifies AI systems by risk and imposes obligations on providers and deployers. It applies whether or not personal data is involved. It intersects with the GDPR at specific points, impact assessments, bias testing using special category data, automated decision-making and explanation rights, and transparency, but most of its obligations, including conformity assessment, technical documentation and quality management, have no privacy analogue.
Does a DPIA satisfy the Article 27 FRIA?
No. Article 27(4) provides that where FRIA obligations are already met through a DPIA under GDPR Article 35, the FRIA complements that DPIA. It avoids duplicated work but does not discharge the FRIA, which has its own prescribed contents and is notified to the market surveillance authority rather than the data protection authority.
Should the DPO own EU AI Act compliance?
Owning the whole Act is usually a mistake. Impact assessments, bias-testing conditions, explanation rights and transparency advice fit the role. Conformity assessment, CE marking, Annex IV technical documentation, post-market monitoring and quality management are product and engineering obligations that a privacy function cannot execute or resource.