KomplyaBack to blog

GDPR and the AI Act: Obligations for Businesses

Published 2026-08-08· 6 min readGDPR & AI

Your compliance lead has run a tight GDPR programme for years: a live record of processing, DPIAs on file for anything sensitive, breach procedures tested, a working relationship with the DPC. Then engineering ships an AI-driven credit scoring feature, or HR adopts an AI screening tool, and the working assumption is that the existing DPIA process already has it covered. It often doesn't. GDPR maturity buys you a head start on the AI Act, not a pass. This is a common pattern across Ireland's fintech and SaaS scale-up sector, where data protection programmes are usually years ahead of AI governance ones, and the gap between the two is exactly where the new obligations sit.

Two regulations, one system, different questions

GDPR governs personal data: is it processed lawfully, for a defined purpose, with appropriate safeguards. The AI Act, formally Regulation (EU) 2024/1689, governs AI systems by the risk they pose to health, safety, or fundamental rights, whether or not personal data is involved. A credit-scoring model or an AI-based fraud check sits inside both frameworks at once. For a fintech or SaaS business already fluent in GDPR, the instinct is to treat the AI Act as more of the same paperwork. It is a related but legally distinct regime, with its own scope, its own documentation set, and its own enforcement track.

Where GDPR work already does double duty

The overlap is real, and worth using. GDPR Article 35 requires a Data Protection Impact Assessment (DPIA) where processing is likely to result in high risk to individuals, which most AI systems touching personal data will trigger. The AI Act's Article 27 separately requires certain deployers of high-risk AI systems to run a Fundamental Rights Impact Assessment (FRIA) before deployment. Article 27(4) allows a FRIA to complement an existing DPIA rather than duplicate it. A fintech that already runs disciplined DPIAs on its scoring or onboarding systems has a genuine head start: the fact base, the stakeholder interviews, and the documented risk reasoning can largely carry over.

What a DPIA cannot do is substitute wholesale for a FRIA, because a FRIA is scoped to fundamental rights broadly, including non-discrimination and access to services, not only to personal data risk, and the FRIA duty applies to a narrower set of deployers than the DPIA duty does. A GDPR record of processing activities is similarly useful as a starting inventory of which systems touch personal data, but it was never built to capture AI-specific facts: whether a system falls under Annex III as high-risk, what the provider's instructions for use actually say, or what human oversight measures are in place day to day. Treat existing GDPR documentation as raw material for the AI Act work, not a finished answer to it.

Where the two regimes genuinely diverge

GDPR Article 22 gives people a right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects on them. Many teams read a human-in-the-loop step as closing that question and stop there. But the AI Act's Annex III separately classifies systems as high-risk based on the context of use, such as creditworthiness assessment, employment decisions, or access to essential services, regardless of how automated the final call is. A lending tool with a human reviewer can clear the Article 22 concern and still be a high-risk AI system under Annex III, which brings its own duties: a risk management system, technical documentation, logging, and human oversight designed into the system, not bolted on. None of these has a GDPR equivalent. They are new work, not a relabelled version of data protection tasks you already do.

The DPC's two distinct mandates

The Data Protection Commission is long established as Ireland's GDPR supervisory authority, and its role as lead authority for the one-stop-shop mechanism gives it an outsized part in enforcement against the multinational technology companies headquartered here, well beyond Irish borders alone. Under the AI Act, Ireland is also expected to designate market surveillance and notifying authorities for AI systems, and the DPC has a role in that emerging structure, particularly where AI systems process personal data. What we are not going to do is state a precise formal designation date or the exact boundaries of that AI Act role here, because the institutional detail is still settling and a business relying on it should confirm the current position directly rather than take a blog post's word for it. The one thing that is certain is that the DPC's GDPR mandate and its AI Act mandate are related but legally separate; a finding or engagement under one does not automatically extend to the other.

What it costs to get wrong

The two penalty regimes are close enough to be confused and different enough to matter. GDPR's maximum fine is up to €20 million or 4% of global annual turnover, whichever is higher, for the most serious infringements. The AI Act's Article 99 sets a higher ceiling for its most serious category, prohibited AI practices: up to €35 million or 7% of global annual turnover. Most other AI Act infringements sit at a lower tier, up to €15 million or 3%. Article 99(6) does provide for proportionate, reduced caps for SMEs and start-ups, which matters for an Irish scale-up, but it is a mitigating factor, not an exemption, and it does not remove the obligation to run the assessment in the first place.

What to check before assuming you're covered

A short, honest audit tells you more than re-reading the regulation text. Work through this against your actual AI use cases, not the theoretical version of your business:

  • Does any AI system you use touch credit decisions, employment, insurance, or another Annex III high-risk category, regardless of whether a human reviews the output?
  • Have you run the Article 22 question and the Annex III question separately for that system, rather than treating a human-in-the-loop as closing both?
  • Does an existing DPIA for that system have the fact base to extend into a FRIA, or would you be starting from a blank page?
  • Do you have technical documentation, logging, and a documented human oversight design for any high-risk system, distinct from your GDPR records of processing?
  • Has anyone confirmed, with the DPC or independent advice, what its current AI Act role means for your specific sector, rather than assuming its GDPR relationship covers it?
  • If your AI vendor is non-EU, have you separately checked GDPR's Chapter V transfer rules, which the AI Act does not address at all?

Everything above is general information to help you get oriented, not legal advice for your specific situation, particularly on institutional detail like the DPC's evolving AI Act role, which is still developing. Where Komplya publishes guidance like this, we are clear about which layers are legally reviewed and which are draft material, so you can weigh it accordingly.

If your GDPR programme is solid and you are not sure how far it actually extends into AI Act territory, the useful next step is not another read-through of the regulation. Answer a short questionnaire on your actual AI use cases and get a plain-language read on where the overlap already covers you and where it doesn't.