For DPOs

The EU AI Act for privacy teams.

GDPR asks whether you may process the data. The AI Act asks whether you may put the system on the market and how it must behave. They overlap heavily in evidence and almost not at all in trigger.

Last updated 21 August 2026 · Regulation (EU) 2024/1689 as amended by the June 2026 Omnibus · Self-assessment, not legal advice

If you already run a GDPR programme, you have done more of the EU AI Act than you think - and the parts you haven't done are not the ones people warn you about. This page maps the two regimes against each other, so you can work out what genuinely needs new work and what is your existing evidence under a different heading.

The single most useful reframing: GDPR asks whether you may process the data. The AI Act asks whether you may put the system on the market and how it must behave. They overlap heavily in evidence and almost not at all in trigger.

What your GDPR work already covers

AI Act requirementYour GDPR equivalentGap
Article 10 - data governance for training and test setsArt 5 principles, records, minimisation, accuracyAdds bias examination and representativeness of datasets
Article 13 - transparency to deployersArts 13-14 transparency to data subjectsDifferent audience: your customer, not the data subject
Article 14 - human oversight designArt 22 safeguards on automated decisionsBroader - applies even where no Art 22 decision occurs
Article 12 - loggingAccountability, security loggingPrescribed retention and traceability for high-risk
Article 9 - risk management systemDPIAContinuous over the lifecycle, not a point-in-time assessment
FRIA for public-sector deployersDPIAGenuinely additional, and wider than data protection
Article 4 - AI literacyStaff training obligationsTrivially close - extend your existing programme

A DPIA is not a FRIA and does not discharge Article 27, but the underlying evidence - data flows, necessity and proportionality reasoning, safeguards, consultation - carries across substantially.

Four places DPOs consistently get caught

1. Scope has nothing to do with personal data. An AI system can be high-risk while processing no personal data at all - critical infrastructure safety components, for instance. Conversely, a system awash in personal data can be minimal risk. If you triage AI Act exposure by "does it touch personal data", you will miss things in both directions.

2. Role is a separate analysis from controllership. Provider/deployer under the AI Act does not map onto controller/processor. You can be a processor under GDPR and the provider under the AI Act simultaneously. Working out one does not tell you the other. The AI Act test.

3. The live obligations are not the high-risk ones. Everyone is planning for December 2027. Meanwhile Article 50, Article 4 and Article 5 have been enforceable since 2 August 2026, and they apply to organisations with no high-risk systems whatsoever.

4. Article 5 is not a risk to be mitigated. Prohibited practices cannot be documented, consented or DPIA'd into acceptability. Emotion inference in the workplace is the one that turns up in ordinary organisations - usually bundled into an HR analytics or productivity tool nobody flagged.

A triage order that works

The mistake worth avoiding is running the AI Act as a second, parallel programme. Most of the cost is duplication: two inventories, two risk assessments, two sets of records describing the same systems. One register with both lenses is materially cheaper to maintain and easier to defend.

Reglynn's reports flag GDPR overlaps explicitly for this reason - where one control satisfies both regimes, the report says so rather than presenting it as new work. The methodology is published, so you can check the reasoning rather than take the output on trust.

Triaging an AI inventory?

The free check runs role, GPAI status, tier and the Article 6(3) exemption per system - in the order that actually saves work.

Start the free scan

No card, no account. Full gap report from €59. See a real report first.

Self-assessment, not legal advice. This page and the Reglynn report are a structured self-assessment based on the EU AI Act (Regulation 2024/1689, as amended by the June 2026 Omnibus). They indicate where you likely stand and what to verify with a qualified advisor. Reglynn is not a notified body and issues no certification.

How this was made. Reglynn reports are generated by an AI system built on Anthropic's Claude and reviewed before delivery. Reglynn is a Limited Risk AI system under Article 50; we disclose AI involvement wherever it occurs, including in our chat assistant. Our own self-assessment.