The GDPR governs the management of personal data, while the AI Act regulates AI systems, whether or not they process personal data. Both regulations often apply together and require distinct but coordinated compliance for European organizations.
In brief
- The GDPR and the AI Act target different regulatory objects but can apply simultaneously.
- The GDPR is triggered as soon as personal data is processed; the AI Act concerns any AI system placed on the market or used in the EU.
- Three major areas trigger both texts together: biometrics, automated decisions, and profiling.
- The roles of controller (GDPR) and provider/deployer (AI Act) are independent and sometimes cumulative.
- Distinct and cumulative sanctions apply: up to 4% of global turnover (GDPR) and 7% (AI Act).
- DPIA and AI Act assessment are two separate processes, but coordination allows for the optimization of documentation compliance.
Since the GDPR came into force in **May 2018**, the management of personal data has become a pillar of compliance in Europe. The **AI Act (Regulation EU 2024/1689)**, which will apply progressively starting in 2025-2026, introduces a new framework for artificial intelligence systems. The GDPR and the AI Act do not replace each other: they add to one another. Mastering their boundaries and overlaps is now essential for any organization developing, deploying, or operating AI solutions in the EU.
GDPR and AI Act: Distinct objects and purposes
Confusion between the two regulations is common because they share a European origin and a goal of protecting individuals. However, their scopes are clearly differentiated.
**GDPR** governs all **processing of personal data**: as soon as information allows for the identification of a natural person (name, email, photo, etc.), the GDPR applies, whether or not AI is involved. This applies equally to a paper form, a CRM database, or an Excel file containing contact details.
The **AI Act** targets **artificial intelligence systems**: design, commercialization, deployment, and operation within the EU. It applies to any AI system placed on the European market, whether or not it processes personal data. For example, an industrial AI tool processing only anonymized technical data falls under the scope of the AI Act if it is classified as high-risk, even if the GDPR does not apply.
In summary: **the GDPR regulates the use of personal data; the AI Act regulates AI systems**. They can apply simultaneously to the same device but remain independent.
Comparison of scopes and responsibilities
Territorial and personal scope
The GDPR targets any entity (public or private), whether established in the EU or not, as soon as it processes personal data of European residents (extraterritoriality principle, **Article 3**). The AI Act applies to any organization that places on the market or uses an AI system in the EU, regardless of location. Thus, a non-European company marketing an AI solution in Europe falls under the AI Act. If this solution also processes personal data of European citizens, it is also subject to the GDPR.
Roles and functions
The GDPR distinguishes between the **controller** (who decides the purposes and means) and the **processor** (who acts on behalf of the controller). The AI Act defines the **provider** (who designs and places the system on the market) and the **deployer** (who uses it professionally).
These categories do not systematically overlap. An AI Act deployer may be a GDPR controller or processor depending on the control of data flows and purposes. A single company can combine multiple roles: for example, a company that develops and operates an AI system will be both an AI Act provider and deployer, and likely a GDPR controller.
Typology of obligations
GDPR requirements are **data-centric**: lawfulness (Article 6), minimization, purpose limitation, data subject rights (access, rectification, erasure, portability), appointment of a DPO if necessary, and notification of breaches within 72 hours. The AI Act imposes **system-centric** obligations: risk level categorization, risk management (**Article 9**), technical documentation (**Annex IV**), transparency (**Article 50**), human oversight (**Article 14**), robustness and cybersecurity (**Article 15**), and CE marking and registration for high-risk systems.
Competent authorities
GDPR compliance is monitored by **national data protection authorities** (CNIL in France, AEPD in Spain, etc.). The AI Act will be monitored by **national AI authorities** designated by each Member State, which are different from GDPR authorities. These two types of authorities can intervene separately, on distinct legal bases, and open parallel procedures.
Applicable sanctions
The GDPR provides for fines of up to **20 million euros** or **4%** of annual global turnover for major infringements. The AI Act provides for sanctions of up to **35 million euros** or **7%** of global turnover for prohibited practices, **15 million or 3%** for non-compliance of high-risk systems, and **7.5 million or 1%** for inaccurate information. Both types of sanctions are **cumulative**: the same organization can be sanctioned under both regulations.
Overlap zones: when GDPR and AI Act apply together
Many AI systems process personal data, which triggers dual application. Here are the main cases of intersection.
Biometric recognition
A facial recognition system processes biometric data, considered **sensitive data** by the GDPR (**Article 9**), the processing of which is in principle prohibited except for specific exceptions. This same system is classified as **high-risk** by the AI Act (**Annex III**, biometric identification). Both texts impose cumulative requirements: legal basis and DPIA on the GDPR side, technical documentation, CE marking, and human oversight on the AI Act side. The AI Act also prohibits real-time biometric identification in public spaces for law enforcement purposes, except for strict exceptions (**Article 5**).
Automated decisions
**Article 22 of the GDPR** governs decisions based solely on automated processing that have a significant impact (credit refusal, recruitment, pricing, etc.). It imposes the right to human intervention, explanation, and contestation. **Article 14 of the AI Act** requires, for high-risk systems, human oversight allowing for understanding and neutralizing the system if necessary. Both requirements must be met: systems must be designed to be truly supervisable.
Profiling and personalization
AI systems dedicated to **behavioral profiling**, content personalization, or evaluating individuals activate both GDPR rules on profiling (**Articles 4 and 22**) and, depending on their impact, transparency obligations (**Article 50** AI Act) or risk management. Credit scoring or individual rating systems are explicitly listed in **Annex III** as high-risk.
Impact analysis: possible synergies
The GDPR requires a **Data Protection Impact Assessment (DPIA)** for high-risk processing (**Article 35**). The AI Act requires a **conformity assessment** for high-risk systems, including technical documentation (**Annex IV**), a risk management system (**Article 9**), and, for the public sector, a fundamental rights impact assessment (**Article 27**).
Although distinct, these processes address similar issues. It is advisable to coordinate them to identify overlaps, streamline documentation, and ensure consistency in assessments. Some organizations are developing joint GDPR/AI Act models.
Contracts with AI providers
If you use an AI provider that processes personal data on your behalf, the GDPR requires a **data processing agreement** (**Article 28**) specifying the obligations. The AI Act also imposes requirements on the deployer regarding system supervision. Both contractual components must be harmonized: an AI provider cannot promise human oversight in the AI Act contract while disclaiming its GDPR responsibilities in the DPA.
> Do you want to assess your cross-GDPR/AI Act exposure? The compaia diagnostic provides a quick analysis of your risks and compliance priorities.
Towards coordinated GDPR and AI Act compliance
The AI Act complements the GDPR within the European regulatory architecture. While the GDPR established a culture of data protection, the AI Act adds requirements specific to AI: robustness, explainability, human oversight, and risk management, which the GDPR did not cover.
For effective management of dual compliance, adopt three essential reflexes:
1. **Map data processing and AI systems together**: for each system, determine if it processes personal data, under what role (controller, processor), and its AI Act classification. This cross-mapping is the foundation of a solid compliance strategy.
2. **Coordinate impact assessments**: if a DPIA is required (GDPR) and a conformity assessment (AI Act), conduct them in parallel with the same teams to pool documentation and avoid inconsistencies.
3. **Align governance**: the DPO (if appointed) and the AI compliance officer must collaborate. Design choices for AI systems have repercussions on both texts.
Tools like the compaia documentation module facilitate this integrated compliance approach.