resources

AI Act vs GDPR: comparison table

Detailed comparison between the EU AI Regulation (AI Act) and the GDPR: scope, obligations, penalties, authorities and intersection points. Reference for dual compliance.

AI Act vs GDPR · Comparison · Dual compliance · Penalties · Obligations

We help you simultaneously comply with the AI Act and GDPR for your AI systems.

The EU AI Regulation (AI Act) and the General Data Protection Regulation (GDPR) are the two European regulations that most affect technology companies. Although they regulate different objects (AI systems vs personal data), their scopes overlap significantly: most AI systems process personal data, and the GDPR regulates that processing.

This table compares both regulations on key aspects to facilitate your company's dual compliance.

Aspect AI Act (Regulation (EU) 2024/1689) GDPR (Regulation (EU) 2016/679)
Scope AI systems placed on the market or put into service in the EU, regardless of the provider's establishment Processing of personal data of natural persons within the European Economic Area, regardless of where processing takes place
Legal basis Regulation (EU) 2024/1689 of the European Parliament and of the Council, of 13 June 2024 Regulation (EU) 2016/679 of the European Parliament and of the Council, of 27 April 2016
Subject of regulation AI systems, models and practices (product) Personal data of natural persons (fundamental rights)
Regulatory approach Risk-based (prohibited → high-risk → limited transparency → minimal risk) Rights-based (consent, lawful basis, minimization, ARSULIPO rights)
Obligated entities Providers, deployers, importers, distributors, authorised representatives Controllers, processors, representatives
Main obligations Conformity assessment, technical documentation, EU database registration, human oversight, serious incident notification Consent/lawful basis, DPIA, record of processing, DPO appointment, 72-hour breach notification
Maximum penalties Up to €35 million or 7% of global annual turnover (whichever is higher) for prohibited practices Up to €20 million or 4% of global annual turnover (whichever is higher) for serious infringements
Competent authority National authorities designated by each Member State + European AI Office (coordination) Data protection authorities of each Member State + European Data Protection Board (EDPB)
Temporal application Entry into force: 2 August 2024. Staggered application (as amended by the 2026 AI Omnibus): prohibitions (Feb 2025), GPAI (Aug 2025), general application (Aug 2026), high-risk Annex III (Dec 2027), high-risk Annex I (Aug 2028) Applicable since 25 May 2018
Individuals' rights Right to explainability of high-risk decisions, right not to be subject to prohibited practices, right to lodge complaints with authorities ARSULIPO rights (access, rectification, erasure, restriction, portability, objection), right not to be subject to automated decisions
Relationship with data Requires governance and quality of training data (Art. 10) for high-risk systems; does not regulate personal data directly Regulates the processing of personal data, including data used to train AI systems
Impact assessment Ex ante conformity assessment (before market placement) for high-risk systems Ex ante Data Protection Impact Assessment (DPIA) when processing poses high risk to rights and freedoms
Transparency Obligation to inform users they are interacting with AI (Art. 50), identification mark on deep fakes Obligation to inform data subjects (Art. 13-14), right to be informed about automated decisions (Art. 22)
Representative function Authorised representative in the EU for providers not established in the EU (Art. 25) Representative in the EU for controllers/processors not established in the EU (Art. 27)

Key intersection points

1. Training data and data protection

The AI Act requires quality and governance of training data (Art. 10), but does not directly regulate the processing of personal data. However, when training data contains personal data, the GDPR applies in full: you need a lawful basis for processing, must comply with the minimization principle, and, where appropriate, conduct a DPIA. Compliance with the AI Act does not exempt you from GDPR compliance.

2. Automated decisions and explainability

The GDPR grants the right not to be subject to decisions based solely on automated processing (Art. 22) and the right to obtain explanation of decisions. The AI Act reinforces this approach by requiring human oversight and transparency in high-risk systems. Both regulations converge on the requirement for explainability.

3. Impact assessments: DPIA and conformity assessment

The GDPR DPIA and the AI Act conformity assessment are distinct but complementary processes. The DPIA assesses the impact on data subjects' rights and freedoms; the conformity assessment evaluates compliance with the system's technical requirements. For high-risk AI systems processing personal data, both assessments are necessary and can be integrated into a unified process.

4. EU representative for non-EU companies

Both regulations require the designation of an EU representative for companies not established in the Union. The AI Act requires an authorised representative (Art. 25) when the AI system provider is not established in the EU. The GDPR requires a representative (Art. 27) when the controller is not established in the EU but offers goods or services to data subjects in the EU. Learn about our representation service for non-EU companies.

5. Cumulative penalties

Infringements of the AI Act and the GDPR are sanctioned independently. A company breaching both regulations may face cumulative fines of up to €55 million or 11% of its global annual turnover. This underscores the importance of an integrated compliance approach.

Need dual AI Act + GDPR compliance?

We assess your AI system to simultaneously comply with both regulations, integrating impact assessments, technical documentation and data governance measures.

Request assessment
Contact us