NO AI ACT.

GDPR · AI Act · Roles · Assessments

The AI Act and the GDPR: when each applies, and when both

The most common question — “is it the AI Act now, or the GDPR?” — starts from a false premise. They are not two versions of one rule: they protect different things, and where they meet both apply, cumulatively. The AI Act does not replace the GDPR and does not soften it.

01They protect different things

The difference is not one of scope but of object. The GDPR protects a person with respect to the processing of their personal data; the AI Act protects people and society from the risks typical of AI systems — risks that exist even when no personal data is processed at all.

Two frameworks, two logics
GDPRAI Act
What it regulatesThe processing of personal data, with any technology.Placing on the market, putting into service and using AI systems.
Kind of ruleHorizontal and technology-neutral.Vertical, built closer to product-safety law.
What triggers the dutiesThe presence of personal data.The system's purpose and the risk tier it falls into.
Who carries the dutiesController and processor.Provider, deployer, importer, distributor.

02Three situations, not two

Keeping the two triggers apart — “is there personal data?” and “is this an AI system?” — produces three cases instead of the false either/or.

  • GDPR only. Processing personal data without AI: an archive, a spreadsheet, a manual procedure. The AI Act does not engage.
  • AI Act only. An AI system that processes no personal data — a model trained on technical data controlling an industrial process, say. The risk and transparency duties remain; the GDPR does not.
  • Both. The common case inside a company or a public body: an AI system processing data about people. Here the obligations add up — you do not choose between them.
The practical consequence. Being compliant with the AI Act does not make you compliant with the GDPR, or the other way round. Both assessments have to be done, and the second is not a chapter of the first.

03Where they overlap most

The overlaps are not random: they are the places where an AI system produces effects on identifiable people.

  • Biometrics. Biometric data is a special category under the GDPR; some biometric uses are prohibited or high-risk under the AI Act. The two classifications do not coincide and must be checked separately. See prohibited practices.
  • Recruitment and worker management. High-risk under the AI Act; under the GDPR, the territory of automated decisions and of informing workers. See AI at work and in hiring.
  • Access to essential services and creditworthiness. High-risk under the AI Act; under the GDPR, often an automated decision carrying specific rights for the data subject.
  • Generated or manipulated content. The AI Act requires it to be disclosed; if the content depicts real people, the GDPR engages on the processing of their images. See deepfakes and transparency.

04The roles do not map onto each other

This is the most frequent mistake: assuming a controller is also a provider, or that a deployer is automatically a processor. They are two independent taxonomies, and one organisation can sit in different places in each.

A public body that buys an AI system and uses it on its own users is normally a controller under the GDPR and a deployer under the AI Act. The system's supplier may be a processor and at the same time a provider under the AI Act — but not necessarily. The AI Act role map is on provider and deployer.

05A DPIA and a FRIA are not the same assessment

They resemble each other in form and diverge in object, and neither absorbs the other.

Two impact assessments asking different questions
DPIA (GDPR)Looks at the risks to people's rights and freedoms arising from the processing: which data, for what purpose, on what legal basis, with which safeguards.
FRIA (AI Act)Looks at the impact on fundamental rights arising from using the system in a given context: who can be harmed, how anyone would notice, how it is put right, who oversees it.

Where both are owed they can share material and be run together, but they remain two assessments with two questions. The detail on the second is on the FRIA.

06What the AI Act does not settle

Some questions stay entirely with the GDPR, and no AI Act step closes them.

  • The legal basis. Why may that data be processed at all? The AI Act does not supply one.
  • Data subject rights. Access, rectification, objection, and the safeguards around automated decisions remain the GDPR's.
  • Minimisation and retention. How much data is genuinely needed, and for how long.
  • Transfers outside the Union. Governed by the GDPR, wherever the model runs.

What NO AI ACT itself does not collect is set out in privacy by design.

07Try it on a case

“Faces in the crowd” stages a biometric system in a public space: the point where the two laws meet most deeply, because the same system has to be classified twice, with two different questions, and the answers need not agree.

08Official sources and transparency

Glossary · AI Act for business · AI Act penalties