En este modulo

  1. Two regulatory frameworks, one system
  2. Legal bases for AI with personal data
  3. Coordinated DPIA: GDPR + AI Act
  4. Data subject rights before AI systems
  5. Article 22 GDPR and AI Act human oversight
  6. Data governance: Article 10 AI Act and GDPR principles
  7. Integrated documentation
  8. DPO and AI Officer: practical coordination
  9. International transfers and AI
  10. Ejercicio practico
  11. Puntos clave

Two regulatory frameworks, one system

Most AI systems process personal data. This means that both the GDPR and the AI Act apply simultaneously. They are not alternatives nor mutually exclusive: they are cumulative. A high-risk system that processes personal data must comply with all Title III requirements of the AI Act and all principles and obligations of the GDPR.

Article 2(7) of the AI Act expressly states: "This Regulation shall be without prejudice to Union law on the protection of personal data, privacy and confidentiality of communications." There is no precedence of one regulation over the other. Both apply in full.

Critical intersection points

Common mistake

Many organizations assume that "if I comply with the GDPR, I already comply with the AI Act regarding data". This is incorrect. The AI Act has its own data governance requirements (Art. 10) that go beyond the GDPR. And the GDPR has transparency requirements for automated decisions that go beyond the AI Act.

All processing of personal data needs a legal basis under Article 6 of the GDPR. AI systems are no exception. These are the most relevant bases:

Consent (Art. 6(1)(a) GDPR)

For use of data in model training: consent must be specific (not generic), informed (including the nature of AI processing), freely given (not conditional on a service) and revocable (with clear practical consequences). The challenge with AI: revoking consent may not be feasible if the model was already trained with that data. The EDPB has indicated that revocation of consent does not require "unlearning" a model if it is technically and proportionately unfeasible, but it does require ceasing the future use of that data.

Legitimate interest (Art. 6(1)(f) GDPR)

A frequent basis for AI systems in areas such as fraud prevention, network security, product improvement. Requires the three-part test: real legitimate interest, necessity of processing, and balancing against the data subject's rights. The necessity assessment is particularly demanding for AI: you must demonstrate that there are no less intrusive means to achieve the same objective.

Performance of a contract (Art. 6(1)(b) GDPR)

Applicable when AI is necessary to deliver a contracted service (for example, a support chatbot for a service the user has contracted). Not valid for inferences about the user that go beyond what is necessary for the service.

Legal obligation (Art. 6(1)(c) GDPR)

If a law requires the processing (for example, anti-money laundering detection), this basis may cover the use of AI. But the legal obligation must be sufficiently specific: "we have to comply with anti-fraud regulation" is not enough.

Special category data (Art. 9 GDPR)

AI systems that process biometric data, health data, genetic data, data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership or sexual orientation additionally need an exception under Article 9(2) GDPR. Explicit consent is the most common pathway, but not always possible (especially in the employment context where consent is not freely given).

Coordinated DPIA: GDPR + AI Act

Article 27(4) of the AI Act expressly states that the fundamental rights impact assessment (FRIA) may be integrated with the DPIA under Article 35 GDPR. This integration is the recommended approach: it avoids duplication and generates a holistic view of the system's impact.

Structure of an integrated DPIA/FRIA

Part 1: System and processing description

Part 2: Necessity and proportionality (GDPR)

Part 3: Risk assessment for rights and freedoms (GDPR + AI Act)

Part 4: Mitigation measures

Part 5: Conclusion and action plan

Data subject rights before AI systems

GDPR rights apply in full when an AI system processes personal data. But their exercise poses specific challenges:

Right of access (Art. 15 GDPR)

The data subject has the right to know whether their data is processed by an AI system, the purpose of processing, the categories of data and, in the case of automated decisions, "meaningful information about the logic involved". This last point is the most complex: what does "logic involved" mean when the system is a neural network with millions of parameters? The majority position of data protection authorities: it is not required to reveal the algorithm, but to explain the main factors influencing the decision and their relative weight.

Right to rectification (Art. 16 GDPR)

If the data used by the system is inaccurate, the data subject can demand its rectification. In AI systems, this raises the question of whether rectifying the input data produces a change in the system's decision. The controller must be able to demonstrate that corrected data is reflected in future inferences.

Right to erasure (Art. 17 GDPR)

The right to be forgotten applies to personal data processed by AI. The challenge: if the data was used to train a model, "deleting" the data does not undo the model's learning. The EDPB has indicated that deletion of training data is sufficient if retraining the model is disproportionate, provided that the model does not allow reconstruction of the original data.

Right to object (Art. 21 GDPR)

Especially relevant when the legal basis is legitimate interest. The data subject may object to processing on grounds relating to their particular situation. The controller must demonstrate "compelling legitimate grounds" to continue processing. In the AI context, mere operational convenience is usually not a sufficient ground.

Article 22 GDPR and AI Act human oversight

Article 22 GDPR grants the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects the individual. Article 14 of the AI Act requires effective human oversight.

Key differences

Joint practical implementation

For a high-risk system that processes personal data and makes decisions with significant effects:

  1. The decision cannot be "solely" automated: meaningful human intervention is needed (not rubber-stamping).
  2. The human overseeing must have the competence, authority and access to the information necessary to modify or reverse the decision.
  3. The data subject must be able to request human intervention, express their point of view and contest the decision (Art. 22(3) GDPR).
  4. The system must be designed to enable all of the above (Art. 14 AI Act).

Real vs. fictitious human oversight

An operator who approves 99.8% of the system's decisions without substantive review is not "human oversight". It is rubber-stamping. Both the GDPR and the AI Act require effective oversight: the operator must be able to understand the system's recommendation, evaluate alternatives, and have real authority to modify the decision. If the volume of decisions prevents individual review, mechanisms must be established for sample review, automatic alerts for anomalous cases and periodic audits.

Data governance: Article 10 AI Act and GDPR principles

Article 10 of the AI Act establishes specific requirements for training, validation and testing data of high-risk systems. These requirements interact with (and sometimes conflict with) GDPR principles.

Representativeness vs. minimisation

The AI Act requires data to be "representative" of the system's context of use. To avoid bias, this may require collecting data from protected groups (racial or ethnic origin, gender, age, disability). The GDPR requires minimisation: only the data strictly necessary. Article 10(5) of the AI Act partially resolves this tension: it allows the processing of special category data (Art. 9 GDPR) "to the extent strictly necessary" for bias detection and correction, with appropriate safeguards. This is a legal basis from the AI Act that complements the GDPR.

Data quality vs. storage limitation

The AI Act requires data to be "free from errors, complete and up to date". Maintaining this quality may require retaining data for long periods. The GDPR requires that data not be kept longer than necessary for the purpose. The practical solution: documentedly justify that extended retention is necessary for AI system quality, with periodic reviews of whether retention remains proportionate.

Integrated documentation

Maintaining separate documentation for GDPR and AI Act generates duplication, inconsistencies and maintenance costs. The recommended approach is an integrated documentation system:

Document map

DPO and AI Officer: practical coordination

The GDPR requires a DPO in certain organizations. The AI Act does not formally create an "AI Officer", but practice and AI Office guidance recommend designating a person responsible for AI governance. Coordination between both roles is essential.

Coordination model

Mandatory coordination points

International transfers and AI

International transfers of personal data in the AI context present specific challenges:

AI as a Service (AIaaS) models

When your organization uses an AI model hosted outside the EEA (for example, OpenAI in the US, DeepSeek in China), the input data sent to the model is an international transfer. You need a valid mechanism under GDPR Chapter V: adequacy decision (Data Privacy Framework for the US), standard contractual clauses (SCCs) or Article 49 GDPR derogations.

Training with European data outside the EEA

If a provider trains their model with European personal data on servers outside the EEA, the GDPR applies. This includes web scraping of European data. The provider needs a legal basis for the processing and a mechanism for the transfer.

Practical implication

For organizations subject to ENS Alto, NIS2 or with sensitive data: the preferred solution is to use models hosted in the EU (self-hosted models, providers with EU regions) to avoid the complexity of international transfers and the risk of access by third-country authorities.

Ejercicio practico

Ejercicio TG03: Integrated DPIA/FRIA
  1. Select a high-risk AI system that processes personal data (or use this example: candidate scoring system for recruitment).
  2. Identify the applicable GDPR legal basis. Justify why that basis and not another.
  3. Draft Part 3 of the integrated DPIA/FRIA: risk assessment for rights and freedoms. Identify at least 5 specific risks.
  4. For each identified risk, propose at least 2 mitigation measures (one technical, one organisational).
  5. Assess whether Article 22 GDPR applies. If so, describe how you would implement human oversight to comply with both Art. 22 GDPR and Art. 14 AI Act.
  6. Draft the privacy notice you would provide to candidates, integrating the information required by Articles 13-14 GDPR and Article 13 AI Act.

Output: a partial integrated DPIA/FRIA and a model privacy notice for a high-risk system with personal data.

Puntos clave

Puntos clave from TG03

  1. GDPR and AI Act are cumulative, not alternative. A high-risk system with personal data must comply with both in full.
  2. The GDPR DPIA and the AI Act FRIA can (and should) be integrated into a single document. It reduces duplication and provides a holistic view.
  3. Article 10(5) of the AI Act permits processing special category data for bias detection, with safeguards. It is a complementary legal basis to the GDPR that resolves the representativeness/minimisation tension.
  4. AI Act human oversight (Art. 14) and the GDPR's automated decision prohibition (Art. 22) complement each other but are not identical. Both must be complied with simultaneously.
  5. The DPO and the AI governance officer must coordinate systematically. They are not redundant roles: they cover different perspectives of the same system.
Guia de estudio — Conceptos clave de TG03

Dos marcos regulatorios, un mismo sistema

  • Gobernanza de datos:el articulo 10 del AI Act exige datos representativos, completos y estadisticamente adecuados para entrenamiento. El RGPD exige minimizacion, limitacion de finalidad y limitacion del plazo de conservacion. Estas exigencias pueden entrar en tension.
  • Transparencia:el AI Act (art. 13) exige informacion sobre capacidades y limitaciones del sistema. El RGPD (arts. 13-14) exige informacion sobre el tratamiento de datos, incluida la logica aplicada en decisiones automatizadas.
  • Supervision humana:el AI Act (art. 14) exige supervision humana efectiva. El RGPD (art. 22) otorga el derecho a no ser objeto de decisiones basadas unicamente en tratamiento automatizado.
  • Evaluacion de impacto:el AI Act exige evaluacion de impacto en derechos fundamentales (FRIA, art. 27). El RGPD exige evaluacion de impacto en proteccion de datos (DPIA, art. 35). En muchos casos, ambas son obligatorias para el mismo sistema.
  • Error comun: Muchas organizaciones asumen que "si cumplo RGPD, ya cumplo AI Act en lo relativo a datos". Esto es incorrecto. El AI Act tiene requisitos propios sobre gobernanza de datos (art. 10) que van mas alla del RGPD. Y el RGPD tiene requisitos sobre transparencia en decisiones automatizadas que van mas alla del AI Act.

DPIA coordinada: RGPD + AI Act

  • Descripcion del sistema de IA: proveedor, funcionalidad, tipo de modelo, datos de entrada/salida.
  • Descripcion del tratamiento de datos: finalidad, categorias de datos, categorias de interesados, destinatarios, plazos de conservacion.
  • Rol en la cadena de valor: proveedor o implementador a efectos del AI Act; responsable o encargado a efectos del RGPD.
  • Base de legitimacion y justificacion.
  • Principio de minimizacion: se procesan solo los datos necesarios?
  • Limitacion de finalidad: los datos se usan solo para la finalidad declarada?

Articulo 22 RGPD y supervision humana del AI Act

  • Ambito:art. 22 RGPD aplica a todas las decisiones automatizadas con efectos juridicos o significativos. Art. 14 AI Act aplica solo a sistemas de alto riesgo.
  • Enfoque:art. 22 RGPD es un derecho del interesado (prohibicion con excepciones). Art. 14 AI Act es una obligacion del proveedor/implementador (diseno del sistema).
  • Excepcion:art. 22.2.c RGPD permite decisiones automatizadas con consentimiento explicito. El AI Act no tiene esta excepcion: la supervision humana es obligatoria para alto riesgo independientemente del consentimiento.
  • La decision no puede ser "unicamente" automatizada: se necesita intervencion humana significativa (no rubber-stamping).
  • El ser humano que supervisa debe tener competencia, autoridad y acceso a la informacion necesaria para modificar o revertir la decision.
  • El interesado debe poder solicitar intervencion humana, expresar su punto de vista y impugnar la decision (art. 22.3 RGPD).

Documentacion integrada

  • Registro de actividades de tratamiento (art. 30 RGPD):extender con campos adicionales: clasificacion AI Act, tipo de sistema de IA, nivel de riesgo, fecha de clasificacion.
  • Documentacion tecnica (Anexo IV AI Act):incluir una seccion de cumplimiento RGPD: base de legitimacion, DPIA integrada, medidas de proteccion de datos.
  • DPIA/FRIA integrada:como se ha descrito anteriormente.
  • Informacion al interesado (arts. 13-14 RGPD + art. 13 AI Act):un unico aviso de privacidad que incluya tanto la informacion RGPD como la informacion del AI Act (capacidades, limitaciones, supervision humana).
  • Contratos con proveedores:clausulas RGPD (encargado del tratamiento) + clausulas AI Act (obligaciones del proveedor/importador).

DPO y AI Officer: coordinacion practica

  • Opcion 1: el DPO asume governance de IA.Viable en organizaciones pequenas/medianas con pocos sistemas de IA. Ventaja: vision unificada. Riesgo: sobrecarga del DPO, falta de competencia tecnica en IA.
  • Opcion 2: AI Officer separado con reporte al DPO.El AI Officer gestiona clasificacion, documentacion tecnica, conformidad. El DPO supervisa la dimension de datos personales. Se reunen periodicamente (recomendado: quincenal).
  • Opcion 3: comite de IA con participacion del DPO.Un comite multidisciplinar (legal, tecnico, negocio, DPO) gobierna la IA en la organizacion. El DPO tiene voz y voto en todas las decisiones que afecten a datos personales.
  • Toda nueva adquisicion o desarrollo de sistema de IA que procese datos personales.
  • DPIAs/FRIAs integradas.
  • Incidentes que afecten tanto a datos personales como a la seguridad del sistema de IA.

Siguiente: TG04 - Practical AI Ethics

With the legal framework covered, the next step is to operationalise ethics: ethical impact assessments, bias protocols, fairness audits and ethics by design methodology.

Ir al modulo TG04