GDPR vs EU AI Act: same words, different meanings

The two regimes share vocabulary — transparency, risk, documentation, automated decisions — but the words name different mechanisms. And because the GDPR follows the data while the AI Act follows the system, most real deployments sit under both at once. This page splits the pairs the exam most likes to blur.

1 · The regimes at a glance

GDPR (2016/679) EU AI Act (2024/1689)
What it regulates Processing of personal data — any operation on information about an identifiable person AI systems as products — their development, placing on the market and use
Legal tradition Fundamental-rights law (privacy/data protection) Product-safety law (CE marking, conformity, market surveillance) with fundamental-rights aims
Trigger Personal data is processed — with or without AI An AI system exists — with or without personal data
Regulated actors Controller (determines purposes and means) and processor (processes on the controller’s behalf) Provider, deployer, importer, distributor, authorized representative
Risk logic Principles + rights apply to all processing; extra duties for "high-risk" processing (DPIA) Four risk tiers — prohibited / high / transparency ("limited") / minimal — obligations scale by tier
Main assessments DPIA (Art. 35) Conformity assessment (provider, pre-market) + FRIA (certain deployers, Art. 27)
Oversight National supervisory authorities (DPAs), coordinated by the EDPB National market surveillance authorities + the Commission’s AI Office (GPAI), coordinated by the European AI Board
Top fines €20M / 4% (principles, rights, transfers — Art. 83(5)); €10M / 2% (controller/processor duties — Art. 83(4)) €35M / 7% (prohibited practices); €15M / 3% (most obligations); €7.5M / 1% (misleading information)

Note the fine logic runs opposite ways: under the GDPR the rights and principles tier (4%) outranks the operational duties tier (2%); under the AI Act the prohibited practices tier (7%) outranks everything else. See EU AI Act — what changed in 2026 for current application dates.

2 · The confusable pairs, one by one

1. Controller / processor vs provider / deployer

GDPR

Roles are assigned per processing operation: the controller decides why and how personal data is processed; the processor acts on instructions (Art. 4(7)–(8)).

EU AI Act

Roles are assigned per AI system: the provider develops/markets it under its own name; the deployer uses it under its own authority.

🎯 Trap: The frameworks are orthogonal and BOTH can apply at once. A company deploying a vendor’s HR tool is typically the AI Act deployer AND the GDPR controller of the candidate data; the vendor is the AI Act provider and often a GDPR processor for inference data — but a controller for its own training processing. Never map provider→controller or deployer→processor mechanically; assign each regime’s roles separately.

2. "Transparency" — three different duties

GDPR

Arts. 12–14: tell data subjects that and how their personal data is processed (identity, purposes, lawful basis, rights, meaningful information about automated-decision logic).

EU AI Act

Art. 13: providers give deployers instructions for use (capabilities, limitations, oversight measures) — business-to-business. Art. 50: disclose to people that they are interacting with AI, and label synthetic media — at the point of interaction.

🎯 Trap: When a question says "transparency," identify the audience first: data subjects (GDPR), deployers (Art. 13), or the public/affected people (Art. 50). An answer citing the right duty for the wrong audience is a classic distractor.

3. Automated decisions: Art. 22 vs Art. 14 vs Art. 86

GDPR

Art. 22 is a data-subject right: not to be subject to a solely automated decision with legal or similarly significant effect, unless an exception applies (contract, consent, law) — and then with safeguards: human intervention, the right to express a view and to contest.

EU AI Act

Art. 14 is a design obligation on providers: build high-risk systems so humans can effectively oversee, intervene and stop them. Art. 86 is a post-decision right: a person affected by a decision based on an Annex III high-risk system with legal or similarly significant adverse effect can demand from the deployer a clear, meaningful explanation of the AI’s role in the decision.

🎯 Trap: Three mechanisms, three moments: Art. 22 restricts the decision being solely automated at all; Art. 14 governs how the system is engineered; Art. 86 gives an explanation after the fact. "A human rubber-stamps every output" does not satisfy Art. 22 (the intervention must be meaningful) — and satisfying Art. 22 does not discharge Art. 14 or 86, or vice versa.

4. DPIA vs FRIA vs conformity assessment

GDPR

DPIA (Art. 35): the CONTROLLER assesses risks to individuals’ rights from high-risk processing (systematic profiling, large-scale special categories) before processing begins.

EU AI Act

Conformity assessment: the PROVIDER verifies pre-market that a high-risk system meets the Act’s requirements (then CE marking + registration). FRIA (Art. 27): certain DEPLOYERS — public bodies, public-service providers, and deployers of specific Annex III systems — assess fundamental-rights impact before first use.

🎯 Trap: Assign the assessment to the right actor: conformity = provider, FRIA = deployer, DPIA = controller (usually the deployer in practice). They complement rather than replace each other — a FRIA can build on an existing DPIA, but neither substitutes for the provider’s conformity assessment.

5. Personal-data breach vs serious incident

GDPR

Art. 33: notify the supervisory authority of a personal-data breach without undue delay and where feasible within 72 HOURS of awareness; notify individuals if high risk to them (Art. 34).

EU AI Act

Art. 73: providers of high-risk systems report SERIOUS INCIDENTS (death or serious harm to health, serious and irreversible disruption of critical infrastructure, infringement of fundamental-rights obligations, serious harm to property or environment) to the market surveillance authority — within 15 days of awareness, 10 days if death, immediately and no later than 2 days for widespread infringement or critical-infrastructure disruption.

🎯 Trap: Different triggers, clocks and recipients. A breach is about personal data being compromised (72 hours, DPA); a serious incident is about real-world harm from the system (15/10/2 days, market surveillance authority). One event can be both — then both notifications run in parallel.

6. Records: ROPA vs technical documentation and logs

GDPR

Art. 30: controllers and processors keep a Record of Processing Activities — purposes, categories, recipients, transfers, retention.

EU AI Act

Providers maintain technical documentation (Annex IV) proving compliance, and high-risk systems must log events automatically; deployers retain those logs and use systems per the instructions.

🎯 Trap: ROPA documents processing of personal data; Annex IV documents the system. An answer offering a ROPA to satisfy AI Act documentation duties (or vice versa) mixes regimes.

7. Special categories: Art. 9 vs the bias-debugging carve-out

GDPR

Art. 9 prohibits processing special categories (health, biometrics for identification, ethnicity…) unless a specific condition applies — consent, substantial public interest, etc.

EU AI Act

Art. 10(5): providers of high-risk systems may exceptionally process special categories of personal data strictly where necessary to DETECT AND CORRECT BIAS, under strict safeguards (necessity, security, no transfer, deletion when done).

🎯 Trap: The AI Act does not suspend Art. 9 — the carve-out is narrow, provider-side, bias-correction-only, and layered with safeguards. "We can use health data freely because the AI Act allows bias testing" overstates it badly.

8. "Meaningful information about the logic" vs Art. 86 explanation

GDPR

Arts. 13–15 (with Art. 22): the controller must proactively provide meaningful information about the logic involved in automated decision-making, plus its significance and envisaged consequences.

EU AI Act

Art. 86: on request, the deployer explains the role the AI system played in a specific decision already taken about the person.

🎯 Trap: GDPR’s duty is general and up-front (how the system works); Art. 86 is specific and after the fact (what it did in my case). Neither requires disclosing source code or the full model.

3 · Worked example: one HR tool, both regimes

A German employer licenses a vendor's CV-screening system. In one scenario, every concept above appears:

Sources

Test yourself

Five questions on what is above, with every option explained. Your score is kept in this browser and shown on your dashboard, and saved to your account if you are signed in.

Quick check: GDPR vs EU AI Act1 / 5 · score 0

A company is a GDPR controller for the personal data in its AI system and satisfies every GDPR obligation. What follows for the EU AI Act?

Study the whole syllabus free

Reference notes for all 13 competencies, 305 exam-style questions, flashcards and full-length timed mocks. Sign in with Google to save your progress across devices — which stores your email address and display name. See what is kept, and how to delete it.

Start studying free →