The General Data Protection Regulation (GDPR) and the EU Artificial Intelligence Act (AI Act) are two important European laws that shape how organisations handle data and technology, but they approach personal data from different angles.
The GDPR remains the fundamental personal data protection regime in the EU, focusing on rights, fairness and transparency. The AI Act complements this by incorporating AI-specific risks and safeguards into the regulatory mix, ensuring the protection of personal data and the individuals behind it as the technology evolves.
Together, these laws reflect Europe’s dual commitment to protect privacy and promote trustworthy innovation in a world increasingly shaped by AI.
GDPR: Personal Data is a Fundamental Right
Under GDPR, the protection of personal data is a human right. This law applies whenever an organisation processes information that could identify an individual — this could include names, email addresses, location data, and even IP addresses. The core objectives of GDPR are:
- To ensure personal data is processed lawfully, fairly, and transparently
- To protect individual rights such as access, rectification, erasure, and objection
- To enforce principles such as data minimisation, purpose limitation, and security
- To require organisations to demonstrate accountability through documents such as Data Protection Impact Assessments (DPIAs)
The scope of the GDPR is broad and technology-neutral. It regulates personal data regardless of whether it is processed in AI systems or manual systems, such as paper files.
EU AI Act: Personal Data in the Context of AI Risk
The European Union AI Act is primarily an AI safety and governance law. It does not primarily focus on personal data protection; rather, it regulates AI systems based on the level of risk they pose to people’s rights and safety, regardless of whether they use personal data.
The fundamental differences in how the AI Act handles personal data are as follows:
- It applies to AI systems (e.g., tools, models, algorithms) regardless of whether they use personal data.
- It uses a risk-based approach — higher compliance obligations (including documentation, testing, human oversight and monitoring) apply to high-risk AI systems that could impact fundamental rights or safety.
- It adds AI-specific transparency obligations, such as informing users that they are interacting with AI or making content generated by AI clearly identifiable.
- If an AI system contains personal data, organisations must still comply with the GDPR; the AI Act does not replace the GDPR’s data protection rules.
Thus, while the GDPR focuses on how personal data is used, the AI Act focuses on what the AI system does with this data and whether it poses a risk to users.
Integrated Compliance
Organisations are advised to align their Data Protection Impact Assessments (GDPR) with the risk assessments and documentation required by the AI Act. This reduces duplication and makes compliance more efficient.
Importance in Terms of Personal Data Rights
For citizens and consumers, the combined effect of the GDPR and the AI Act means:
- Personal data is protected as a fundamental right under the GDPR whenever it is processed.
- AI systems that use personal data must be transparent, fair and secure, and if they pose significant risks, they must have additional accountability and oversight layers.
- If AI systems are poorly designed, non-transparent or discriminatory, organisations may be held liable under both data protection and AI security standards.
CFECERT provides IT-based audit and training services. The standards we work with most frequently are as follows:
- ISO 27001 Information Security Management System
- ISO 27701 Privacy Information Management System
- ISO 42001 Artificial Intelligence Management System
- ISO 22301 Business Continuity Management System
- ISO 20000-1 IT Service Management System
- DORA, NIS2, GDPR Compliance
- SOC2, HIPAA, PCI DSS
For more information, please contact us at sales@cfecert.co.uk.
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.