Regulation EU 2024/1689, Post-Omnibus Edition

EU AI Act vs GDPR: Differences, Overlaps, and Integrated Compliance

The EU AI Act and GDPR operate in parallel and frequently intersect. Most high-risk AI systems process personal data, creating dual compliance obligations that must be addressed together.

→ Not sure how this affects your AI system?

Take the free 5-minute Risk Classifier, article-grounded scoring against Article 5, 6, Annex III, and Article 50.

Run the classifier →

Two Frameworks, One Compliance Challenge

The EU AI Act (Regulation EU 2024/1689) and the General Data Protection Regulation (GDPR, Regulation EU 2016/679) are the two most consequential digital regulations for organisations operating in the EU. They operate in parallel, distinct in scope and obligations, but intersect significantly when AI systems process personal data, which in practice means most commercially deployed AI systems. Running them as separate workstreams risks compliance gaps and wastes resources through duplication.

DimensionEU AI ActGDPR
Legal basisRegulation EU 2024/1689 (2024)Regulation EU 2016/679 (2016)
Primary focusAI system risks, safety, fundamental rights, market integrityPersonal data protection, privacy rights and lawful processing
ScopeAll AI systems (not only those processing personal data)All processing of personal data (not only AI)
Risk frameworkTiered: Prohibited / High-Risk / Limited / MinimalAccountability-based: appropriate technical and organisational measures
Key assessmentFRIA, Fundamental Rights Impact Assessment (Art. 27)DPIA, Data Protection Impact Assessment (Art. 35)
Maximum fine€35M or 7% global annual turnover€20M or 4% global annual turnover
EnforcerNational Competent Authorities + EU AI OfficeData Protection Authorities (DPAs)
Enforcement startPhased: Feb 2025 → Aug 2025 → Aug 202625 May 2018 (fully enforceable)

Five Key Intersections

1. High-Risk AI Processing Personal Data

Most Annex III high-risk AI systems process personal data: credit scoring, recruitment AI, biometric systems, law enforcement tools, and benefit eligibility AI all rely on personal data processing. For these systems, both GDPR and the EU AI Act apply simultaneously. An integrated compliance programme covering both frameworks is substantially more efficient than parallel workstreams, and reduces the risk of gaps at the interface between the two regimes.

2. FRIA vs DPIA: Related but Distinct

The Fundamental Rights Impact Assessment (FRIA) under Article 27 of the AI Act is mandatory for public sector deployers of high-risk AI and specific private sector contexts (credit, insurance, recruitment). The DPIA under GDPR Article 35 is mandatory where personal data processing is likely to result in high risk to individuals, which will typically include any high-risk AI deployment.

Both assessments are required but they are not identical. The FRIA addresses a broader range of fundamental rights, not only privacy, but dignity, non-discrimination, access to justice, and democratic rights. Best practice is to run them as complementary exercises sharing data and analysis. The AI Act explicitly acknowledges DPIAs conducted under GDPR and permits their results to inform FRIA processes.

3. Automated Decision-Making

GDPR Article 22 grants data subjects rights regarding solely automated decisions with legal or similarly significant effects, including the right to human review and an explanation. The AI Act's human oversight requirements (Art. 14) and transparency provisions (Art. 13) address similar concerns from a different angle. Together, the two regimes create layered requirements for AI-driven decisions affecting individuals, and organisations must ensure both sets of rights are honoured.

4. Data Governance Requirements

Article 10 of the AI Act requires AI providers to document data governance practices covering training, validation, and testing datasets. Where those datasets contain personal data, GDPR's requirements for lawful basis, data minimisation, purpose limitation, and accuracy also apply. The AI Act data governance documentation and GDPR Records of Processing Activities (RoPAs) should be developed in coordination to capture all required information without duplication.

5. Supervisory Authority Jurisdiction

Data Protection Authorities have existing GDPR jurisdiction over AI systems processing personal data. National Competent Authorities designated under the AI Act may be the same body as the DPA (as in some member states) or a different body. Coordination mechanisms between these authorities are being established, but organisations should anticipate potentially managing dual supervisory relationships for AI systems that process personal data in high-risk contexts.

What the EU AI Act Adds Beyond GDPR

  • Non-personal data AI: The AI Act covers AI systems regardless of whether they process personal data. GDPR does not govern AI decisions based solely on anonymised or non-personal data.
  • Absolute prohibitions: Article 5 categorical prohibitions, social scoring, emotion inference, most biometric surveillance, have no GDPR equivalent.
  • Technical documentation (Annex IV): Requirements for documenting training methodology, model architecture, testing results, and post-market monitoring plans go substantially beyond GDPR processing records.
  • Conformity assessment: A formal pre-market compliance gate (Art. 43) with no GDPR equivalent, AI systems cannot be deployed until conformity is assessed and documented.
  • AI supply chain obligations: Explicit obligations on providers, importers, distributors, and deployers throughout the AI value chain, GDPR's controller/processor model does not fully address this.

Practical Integrated Compliance

  1. Joint AI inventory: Single inventory capturing both AI Act classification data and GDPR-relevant data (lawful basis, data categories, data subjects).
  2. Coordinated FRIA/DPIA: Run as complementary exercises for high-risk AI, sharing analysis and documenting both outputs in one process.
  3. Aligned documentation: Coordinate Annex IV technical documentation with GDPR RoPAs.
  4. Cross-regime incident response: AI Act incident reporting (Art. 73) and GDPR breach notification (Arts. 33–34) have different timelines and addressees, coordinate both in incident response plans.
  5. Dual supervisory engagement: Where your DPA and AI Act NCA are different bodies, proactively manage both supervisory relationships from the outset.

No. The EU AI Act and GDPR are independent frameworks with distinct obligations. Compliance with one does not imply compliance with the other. For AI systems processing personal data, both must be assessed and satisfied independently, although an integrated compliance programme significantly reduces duplication of effort and documentation.

The EU AI Act carries a higher maximum penalty (€35M or 7% of global annual turnover) versus GDPR (€20M or 4%). However, the actual penalty in any given case depends on the specific violation, the competent authority's assessment of aggravating and mitigating factors, and the organisation's global revenue. For the largest technology companies, both regimes' turnover-based calculations produce fines substantially above the fixed euro caps.

← Complete EU AI Act Guide

Free Resource

Where Does Your AI Stand Against the New Phased Timeline?
Find Out in 5 Minutes

Download our EU AI Act 5-Point Express Compliance Check, a structured self-assessment covering risk classification, Annex III applicability, documentation gaps, and board-level exposure. Delivered as a PDF immediately after submit.

No spam. No marketing lists. PDF delivered immediately after submit. Privacy Policy

✓   Your checklist is downloading now. Check your inbox for a copy.