# AI Act vs. GDPR: Overlapping Obligations, Differences, and Practical Management

> The GDPR and the AI Act often apply together to AI systems processing personal data. Each imposes specific obligations: data protection for the GDPR, AI risk management for the AI Act. It is essential to coordinate compliance efforts.

- Tags: AI Act vs RGPD, obligations conformité IA, sanctions RGPD AI Act, gouvernance des données IA, évaluations d'impact IA, autorités contrôle IA, transparence IA RGPD, conformité croisée IA
- Main keyword: AI Act vs RGPD

## Key points

- The AI Act and GDPR pursue distinct purposes: AI risk management and personal data protection.
- The majority of AI systems in companies are subject to both regulations simultaneously.
- Obligations overlap: data governance (Art. 10 AI Act, Art. 5/6 GDPR), impact assessments, transparency (Art. 50 AI Act, Art. 13/14 GDPR).
- Sanctions differ: GDPR up to €20 million or 4%, AI Act up to €35 million or 7% depending on severity.
- Competent authorities are distinct: CNIL for GDPR, DGCCRF for AI Act, with coordination on personal data.
- A coordinated approach helps avoid duplication, particularly for documentation and impact analysis.

## Introduction

Since May 2018, the GDPR has structured the protection of personal data in the European Union. The arrival of the AI Act (EU 2024/1689), applicable from August 2024 (progressive implementation until 2027), adds a level of regulation specific to artificial intelligence systems. These two texts do not replace each other: they often apply simultaneously, each with its own scope.

## Content

## Understanding the Coexistence of the AI Act and GDPR

### Two Frameworks, Two Objectives
- **GDPR**: Guarantees fundamental rights related to privacy and the processing of personal data.
- **AI Act**: Involves managing risks associated with AI systems, based on their risk level, without being limited to personal data.

In practice, most AI systems used in a business context process personal data. Therefore, they are subject to both regulations simultaneously.

## Overview of Differences and Overlaps

| Criterion | GDPR | AI Act |
| :--- | :--- | :--- |
| Subject | Protection of personal data | Regulation of AI systems by risk level |
| Trigger | Processing of personal data | Development, placing on the market, or use of an AI |
| Entry into force | May 2018 | August 2024 (progressive application until 2027) |
| Main Authority | CNIL (France) | DGCCRF (France), CNIL for personal data |
| Maximum Sanctions | €20M or 4% of global turnover | €35M or 7% for prohibited practices, €15M or 3% for high-risk, €7.5M or 1% for inaccurate information |

An AI system without personal data processing falls only under the AI Act. Conversely, data processing without AI is only concerned by the GDPR. However, as soon as an AI tool handles personal data, both frameworks must be applied.

## Actors Involved: Roles and Responsibilities

### GDPR Terminology
- **Data Controller**: Determines the purposes and means of processing.
- **Processor**: Acts on behalf of the controller, under contract (DPA).
- **Data Protection Officer (DPO)**: Advises and monitors compliance, sometimes mandatory.

### AI Act Terminology
- **Provider**: Develops or places an AI system on the market.
- **Deployer**: Uses an AI in a professional context.
- **Importer / Distributor**: Intervenes in the distribution chain.

A single actor can combine several functions: an HR software company integrating AI can be a provider (AI Act), a controller (GDPR), and a processor (GDPR) depending on the case.

## Main Obligations: Detailed Comparison

### 1. Documentation and Records
- **GDPR (Art. 30)**: Record of processing activities, maintained by the controller and processor. It must specify purposes, data categories, recipients, and retention periods.
- **AI Act (Art. 11 + Annex IV)**: Mandatory technical documentation for high-risk system providers, detailing architecture, training data, risk management, performance metrics, and post-market monitoring.
- **Overlap**: An AI system processing personal data must appear in both records. It is possible to integrate GDPR requirements into the AI Act documentation to limit redundancy.

### 2. Impact Assessments
- **GDPR (Art. 35) – DPIA**: Mandatory impact assessment in case of high risk to rights and freedoms (profiling, surveillance, sensitive data).
- **AI Act (Art. 27) – FRIA**: Mandatory assessment for public bodies, operators of essential services, and educational institutions using high-risk AI. It covers all fundamental rights.
- **Articulation**: Both analyses can be performed together, as their content is similar regarding rights protection and non-discrimination. The AI Act encourages this mutualization.

### 3. Transparency and Information
- **GDPR (Art. 13/14)**: Obligation to inform about data processing (controller, purpose, legal basis, duration, rights), upon collection or within a reasonable timeframe.
- **AI Act (Art. 50)**: Obligation to indicate to a person that they are interacting with an AI (chatbot), that content is AI-generated (deepfake), or that they are subject to emotion recognition.
- **Synergy**: For an AI system processing personal data, both information obligations apply. A single document can group the requirements of both regulations.

### 4. Data Governance
- **GDPR (Art. 5/6/9)**: Collection limited to the purpose, mandatory legal basis, data minimization, reinforced guarantees for sensitive data.
- **AI Act (Art. 10)**: Requirements on the quality of training, validation, and testing data (relevance, representativeness, completeness, bias correction).
- **Strong Overlap**: If training data is personal, both frameworks apply. A GDPR legal basis is required for training, and AI Act quality criteria must be met.

> Note: The Digital Omnibus proposes to authorize, under conditions, the processing of sensitive data to correct AI biases, creating a bridge between GDPR and AI Act.

### 5. Data Subject Rights
- **GDPR**: Rights of access, rectification, erasure, restriction, portability, and objection. Right not to be subject to automated decision-making without human intervention (Art. 22).
- **AI Act**: Right to be informed of AI usage (Art. 50), right to human oversight for high-risk AI (Art. 14/26), right to an explanation in certain cases.
- **Complementarity**: GDPR rights (Art. 22) and AI Act human oversight obligations (Art. 14) reinforce each other. The AI Act does not allow bypassing GDPR guarantees.

### 6. Sanctions
- **GDPR**: Up to €10 million or 2% of global turnover for organizational failures; up to €20 million or 4% for violations of fundamental rights.
- **AI Act**: Up to €35 million or 7% of global turnover for prohibited practices (Art. 5); up to €15 million or 3% for high-risk failures; up to €7.5 million or 1% for inaccurate information.
- **Possible Cumulation**: The same infringement can be sanctioned under both texts. For example, an AI system illegally processing personal data and violating the AI Act faces cumulative sanctions.

## Competent Authorities in France

- **GDPR**: The CNIL is the supervisory authority, with powers of investigation, injunction, and sanction.
- **AI Act**: The DGCCRF is designated as the single point of contact. The CNIL intervenes for aspects related to personal data in high-risk AI. Other authorities (ANSSI, HAS, ARCOM) are competent depending on the sector (cybersecurity, health, digital content).
- **Coordination**: The CNIL plays a central role whenever an AI system involves personal data.

## Organizing Cross-Compliance: Practical Method

Compliance steps can be harmonized to limit the burden and avoid duplication:

1. **Map systems**: Identify for each AI tool whether it processes personal data. If yes, GDPR and AI Act apply together.
2. **Merge records**: Add an "AI Act classification" column to your GDPR record for AI processing, rather than keeping two separate records.
3. **Mutualize impact assessments**: Perform a single analysis covering both DPIA (GDPR) and FRIA (AI Act) requirements when relevant.
4. **Unify information for individuals**: Your privacy policy can integrate the information required by Art. 50 of the AI Act (AI usage, chatbots, deepfakes).
5. **Clarify roles**: The DPO remains a key contact for cross-compliance, especially in case of personal data processing by AI. An AI compliance officer can complement this setup.

To facilitate the classification of your AI systems and the identification of AI Act obligations, the [free compaia diagnostic](https://compaia.eu/diagnostic) offers support complementary to your GDPR approach.

## To Go Further

- Consult the [AI Act glossary](https://compaia.eu/glossaire) to master the definitions and key concepts of the regulation.

## FAQ

### Does the AI Act replace the GDPR for AI systems?
No, these two regulations operate in parallel and apply jointly as soon as an AI system processes personal data. The GDPR remains mandatory, and the AI Act does not exempt from GDPR compliance.

### Are two separate impact assessments required - a DPIA and a FRIA?
Not necessarily. If both assessments are required for the same system, they can be merged into a single document provided it covers all requirements. The FRIA covers all fundamental rights, while the DPIA is centered on personal data.

### Does my DPO also have to handle AI Act compliance?
The AI Act does not impose the appointment of an equivalent DPO. However, the DPO naturally has a role to play for AI systems processing personal data. Some structures appoint an AI compliance officer as a supplement. It is essential to clarify responsibilities before August 2026.

### Does the GDPR legal basis also cover the training of AI models?
Not automatically. Training an AI model with personal data constitutes a distinct processing operation requiring its own GDPR legal basis. The Digital Omnibus proposes to relax this point, but each training process must currently be justified by a specific legal basis.

### Can GDPR and AI Act sanctions be combined?
Yes, the same infringement can lead to sanctions under each regulation, by different authorities. For example, illicit collection of personal data (GDPR) and lack of transparency (Article 50 AI Act) expose to cumulative sanctions. Consult the [AI Act glossary](https://compaia.eu/glossaire) for regulatory definitions.

## Official source
- [Source](https://www.aiacto.eu/fr/blog/ai-act-vs-rgpd-comparatif-obligations)
