GDPR vs EU AI Act: same words, different meanings
The two regimes share vocabulary — transparency, risk, documentation, automated decisions — but the words name different mechanisms. And because the GDPR follows the data while the AI Act follows the system, most real deployments sit under both at once. This page splits the pairs the exam most likes to blur.
1 · The regimes at a glance
| GDPR (2016/679) | EU AI Act (2024/1689) | |
|---|---|---|
| What it regulates | Processing of personal data — any operation on information about an identifiable person | AI systems as products — their development, placing on the market and use |
| Legal tradition | Fundamental-rights law (privacy/data protection) | Product-safety law (CE marking, conformity, market surveillance) with fundamental-rights aims |
| Trigger | Personal data is processed — with or without AI | An AI system exists — with or without personal data |
| Regulated actors | Controller (determines purposes and means) and processor (processes on the controller’s behalf) | Provider, deployer, importer, distributor, authorized representative |
| Risk logic | Principles + rights apply to all processing; extra duties for "high-risk" processing (DPIA) | Four risk tiers — prohibited / high / transparency ("limited") / minimal — obligations scale by tier |
| Main assessments | DPIA (Art. 35) | Conformity assessment (provider, pre-market) + FRIA (certain deployers, Art. 27) |
| Oversight | National supervisory authorities (DPAs), coordinated by the EDPB | National market surveillance authorities + the Commission’s AI Office (GPAI), coordinated by the European AI Board |
| Top fines | €20M / 4% (principles, rights, transfers — Art. 83(5)); €10M / 2% (controller/processor duties — Art. 83(4)) | €35M / 7% (prohibited practices); €15M / 3% (most obligations); €7.5M / 1% (misleading information) |
Note the fine logic runs opposite ways: under the GDPR the rights and principles tier (4%) outranks the operational duties tier (2%); under the AI Act the prohibited practices tier (7%) outranks everything else. See EU AI Act — what changed in 2026 for current application dates.
2 · The confusable pairs, one by one
1. Controller / processor vs provider / deployer
GDPR
Roles are assigned per processing operation: the controller decides why and how personal data is processed; the processor acts on instructions (Art. 4(7)–(8)).
EU AI Act
Roles are assigned per AI system: the provider develops/markets it under its own name; the deployer uses it under its own authority.
🎯 Trap: The frameworks are orthogonal and BOTH can apply at once. A company deploying a vendor’s HR tool is typically the AI Act deployer AND the GDPR controller of the candidate data; the vendor is the AI Act provider and often a GDPR processor for inference data — but a controller for its own training processing. Never map provider→controller or deployer→processor mechanically; assign each regime’s roles separately.
2. "Transparency" — three different duties
GDPR
Arts. 12–14: tell data subjects that and how their personal data is processed (identity, purposes, lawful basis, rights, meaningful information about automated-decision logic).
EU AI Act
Art. 13: providers give deployers instructions for use (capabilities, limitations, oversight measures) — business-to-business. Art. 50: disclose to people that they are interacting with AI, and label synthetic media — at the point of interaction.
🎯 Trap: When a question says "transparency," identify the audience first: data subjects (GDPR), deployers (Art. 13), or the public/affected people (Art. 50). An answer citing the right duty for the wrong audience is a classic distractor.
3. Automated decisions: Art. 22 vs Art. 14 vs Art. 86
GDPR
Art. 22 is a data-subject right: not to be subject to a solely automated decision with legal or similarly significant effect, unless an exception applies (contract, consent, law) — and then with safeguards: human intervention, the right to express a view and to contest.
EU AI Act
Art. 14 is a design obligation on providers: build high-risk systems so humans can effectively oversee, intervene and stop them. Art. 86 is a post-decision right: a person affected by a decision based on an Annex III high-risk system with legal or similarly significant adverse effect can demand from the deployer a clear, meaningful explanation of the AI’s role in the decision.
🎯 Trap: Three mechanisms, three moments: Art. 22 restricts the decision being solely automated at all; Art. 14 governs how the system is engineered; Art. 86 gives an explanation after the fact. "A human rubber-stamps every output" does not satisfy Art. 22 (the intervention must be meaningful) — and satisfying Art. 22 does not discharge Art. 14 or 86, or vice versa.
4. DPIA vs FRIA vs conformity assessment
GDPR
DPIA (Art. 35): the CONTROLLER assesses risks to individuals’ rights from high-risk processing (systematic profiling, large-scale special categories) before processing begins.
EU AI Act
Conformity assessment: the PROVIDER verifies pre-market that a high-risk system meets the Act’s requirements (then CE marking + registration). FRIA (Art. 27): certain DEPLOYERS — public bodies, public-service providers, and deployers of specific Annex III systems — assess fundamental-rights impact before first use.
🎯 Trap: Assign the assessment to the right actor: conformity = provider, FRIA = deployer, DPIA = controller (usually the deployer in practice). They complement rather than replace each other — a FRIA can build on an existing DPIA, but neither substitutes for the provider’s conformity assessment.
5. Personal-data breach vs serious incident
GDPR
Art. 33: notify the supervisory authority of a personal-data breach without undue delay and where feasible within 72 HOURS of awareness; notify individuals if high risk to them (Art. 34).
EU AI Act
Art. 73: providers of high-risk systems report SERIOUS INCIDENTS (death or serious harm to health, serious and irreversible disruption of critical infrastructure, infringement of fundamental-rights obligations, serious harm to property or environment) to the market surveillance authority — within 15 days of awareness, 10 days if death, immediately and no later than 2 days for widespread infringement or critical-infrastructure disruption.
🎯 Trap: Different triggers, clocks and recipients. A breach is about personal data being compromised (72 hours, DPA); a serious incident is about real-world harm from the system (15/10/2 days, market surveillance authority). One event can be both — then both notifications run in parallel.
6. Records: ROPA vs technical documentation and logs
GDPR
Art. 30: controllers and processors keep a Record of Processing Activities — purposes, categories, recipients, transfers, retention.
EU AI Act
Providers maintain technical documentation (Annex IV) proving compliance, and high-risk systems must log events automatically; deployers retain those logs and use systems per the instructions.
🎯 Trap: ROPA documents processing of personal data; Annex IV documents the system. An answer offering a ROPA to satisfy AI Act documentation duties (or vice versa) mixes regimes.
7. Special categories: Art. 9 vs the bias-debugging carve-out
GDPR
Art. 9 prohibits processing special categories (health, biometrics for identification, ethnicity…) unless a specific condition applies — consent, substantial public interest, etc.
EU AI Act
Art. 10(5): providers of high-risk systems may exceptionally process special categories of personal data strictly where necessary to DETECT AND CORRECT BIAS, under strict safeguards (necessity, security, no transfer, deletion when done).
🎯 Trap: The AI Act does not suspend Art. 9 — the carve-out is narrow, provider-side, bias-correction-only, and layered with safeguards. "We can use health data freely because the AI Act allows bias testing" overstates it badly.
8. "Meaningful information about the logic" vs Art. 86 explanation
GDPR
Arts. 13–15 (with Art. 22): the controller must proactively provide meaningful information about the logic involved in automated decision-making, plus its significance and envisaged consequences.
EU AI Act
Art. 86: on request, the deployer explains the role the AI system played in a specific decision already taken about the person.
🎯 Trap: GDPR’s duty is general and up-front (how the system works); Art. 86 is specific and after the fact (what it did in my case). Neither requires disclosing source code or the full model.
3 · Worked example: one HR tool, both regimes
A German employer licenses a vendor's CV-screening system. In one scenario, every concept above appears:
- AI Act: the vendor is the provider (conformity assessment, technical documentation, Art. 13 instructions); the employer is the deployer of an Annex III high-risk system (use per instructions, human oversight, log retention, inform candidates, possibly a FRIA).
- GDPR: the employer is the controller of candidate data (lawful basis, Arts. 13–14 notices, DPIA for systematic evaluation, Art. 22 safeguards if decisions are solely automated); the vendor processing candidate data on its instructions is a processor (Art. 28 contract).
- A rejected candidate can invoke Art. 22 safeguards (GDPR, if solely automated) and request an Art. 86 explanation (AI Act) — different rights, different sources.
- If the system leaks candidate data → 72-hour breach clock (GDPR). If it systematically misgrades a protected group in a way that infringes fundamental-rights obligations → serious-incident reporting (AI Act Art. 73).
Sources
- GDPR — Regulation (EU) 2016/679 (Arts. 4, 5–9, 12–22, 25–35, 44–49, 83)
- EU AI Act — Regulation (EU) 2024/1689 (Arts. 3, 5, 10, 13–14, 16–27, 50, 72–73, 86, 99)
Test yourself
Five questions on what is above, with every option explained. Your score is kept in this browser and shown on your dashboard, and saved to your account if you are signed in.
A company is a GDPR controller for the personal data in its AI system and satisfies every GDPR obligation. What follows for the EU AI Act?
- AOnly the AI Act’s transparency duties remain, the rest being covered.
- BNothing — the two regimes apply cumulatively and are assessed separately.
- CIt is compliant, since the GDPR is the stricter of the two instruments.
- DThe AI Act applies only if the system processes no personal data.