AI Act vs GDPR: comparison table
Detailed comparison between the EU AI Regulation (AI Act) and the GDPR: scope, obligations, penalties, authorities and intersection points. Reference for dual compliance.
We help you simultaneously comply with the AI Act and GDPR for your AI systems.
The EU AI Regulation (AI Act) and the General Data Protection Regulation (GDPR) are the two European regulations that most affect technology companies. Although they regulate different objects (AI systems vs personal data), their scopes overlap significantly: most AI systems process personal data, and the GDPR regulates that processing.
This table compares both regulations on key aspects to facilitate your company's dual compliance.
| Aspect | AI Act (Regulation (EU) 2024/1689) | GDPR (Regulation (EU) 2016/679) |
|---|---|---|
| Scope | AI systems placed on the market or put into service in the EU, regardless of the provider's establishment | Processing of personal data of natural persons within the European Economic Area, regardless of where processing takes place |
| Legal basis | Regulation (EU) 2024/1689 of the European Parliament and of the Council, of 13 June 2024 | Regulation (EU) 2016/679 of the European Parliament and of the Council, of 27 April 2016 |
| Subject of regulation | AI systems, models and practices (product) | Personal data of natural persons (fundamental rights) |
| Regulatory approach | Risk-based (prohibited → high-risk → limited transparency → minimal risk) | Rights-based (consent, lawful basis, minimization, ARSULIPO rights) |
| Obligated entities | Providers, deployers, importers, distributors, authorised representatives | Controllers, processors, representatives |
| Main obligations | Conformity assessment, technical documentation, EU database registration, human oversight, serious incident notification | Consent/lawful basis, DPIA, record of processing, DPO appointment, 72-hour breach notification |
| Maximum penalties | Up to €35 million or 7% of global annual turnover (whichever is higher) for prohibited practices | Up to €20 million or 4% of global annual turnover (whichever is higher) for serious infringements |
| Competent authority | National authorities designated by each Member State + European AI Office (coordination) | Data protection authorities of each Member State + European Data Protection Board (EDPB) |
| Temporal application | Entry into force: 2 August 2024. Staggered application (as amended by the 2026 AI Omnibus): prohibitions (Feb 2025), GPAI (Aug 2025), general application (Aug 2026), high-risk Annex III (Dec 2027), high-risk Annex I (Aug 2028) | Applicable since 25 May 2018 |
| Individuals' rights | Right to explainability of high-risk decisions, right not to be subject to prohibited practices, right to lodge complaints with authorities | ARSULIPO rights (access, rectification, erasure, restriction, portability, objection), right not to be subject to automated decisions |
| Relationship with data | Requires governance and quality of training data (Art. 10) for high-risk systems; does not regulate personal data directly | Regulates the processing of personal data, including data used to train AI systems |
| Impact assessment | Ex ante conformity assessment (before market placement) for high-risk systems | Ex ante Data Protection Impact Assessment (DPIA) when processing poses high risk to rights and freedoms |
| Transparency | Obligation to inform users they are interacting with AI (Art. 50), identification mark on deep fakes | Obligation to inform data subjects (Art. 13-14), right to be informed about automated decisions (Art. 22) |
| Representative function | Authorised representative in the EU for providers not established in the EU (Art. 25) | Representative in the EU for controllers/processors not established in the EU (Art. 27) |
Key intersection points
1. Training data and data protection
The AI Act requires quality and governance of training data (Art. 10), but does not directly regulate the processing of personal data. However, when training data contains personal data, the GDPR applies in full: you need a lawful basis for processing, must comply with the minimization principle, and, where appropriate, conduct a DPIA. Compliance with the AI Act does not exempt you from GDPR compliance.
2. Automated decisions and explainability
The GDPR grants the right not to be subject to decisions based solely on automated processing (Art. 22) and the right to obtain explanation of decisions. The AI Act reinforces this approach by requiring human oversight and transparency in high-risk systems. Both regulations converge on the requirement for explainability.
3. Impact assessments: DPIA and conformity assessment
The GDPR DPIA and the AI Act conformity assessment are distinct but complementary processes. The DPIA assesses the impact on data subjects' rights and freedoms; the conformity assessment evaluates compliance with the system's technical requirements. For high-risk AI systems processing personal data, both assessments are necessary and can be integrated into a unified process.
4. EU representative for non-EU companies
Both regulations require the designation of an EU representative for companies not established in the Union. The AI Act requires an authorised representative (Art. 25) when the AI system provider is not established in the EU. The GDPR requires a representative (Art. 27) when the controller is not established in the EU but offers goods or services to data subjects in the EU. Learn about our representation service for non-EU companies.
5. Cumulative penalties
Infringements of the AI Act and the GDPR are sanctioned independently. A company breaching both regulations may face cumulative fines of up to €55 million or 11% of its global annual turnover. This underscores the importance of an integrated compliance approach.
Need dual AI Act + GDPR compliance?
We assess your AI system to simultaneously comply with both regulations, integrating impact assessments, technical documentation and data governance measures.
Request assessment →