AI Act and GDPR. The second didn't cancel the first, and neither absorbs the other.
The question always arrives in the same form: now that there is the AI Act, does the GDPR still count? The regulation answers on its own, in one line of Article 2, and the answer is that the two add up.
The two regulations coexist. Article 2(7) of the AI Act states that it leaves the GDPR unaffected. Being compliant with one says nothing about the other.
In Italy two different authorities supervise. The Data Protection Authority on data processing, ACN on the AI Act, under Article 20 of Law 132/2025. The Data Protection Authority enters the AI Act only for certain high-risk systems.
There are two impact assessments, and they aren't the same thing. The DPIA under Article 35 GDPR looks at data, the one under Article 27 of the AI Act looks at fundamental rights and concerns few parties.
For the ordinary SME the new work is little. Whoever already has a record of processing and their supplier contracts in order finds most of the road already travelled.
This piece sits within the guide to the AI Act obligations for companies and SMEs and takes only one side of it, the relationship with data protection. It is written for whoever runs a business, and it ends where a lawyer's work begins.
What the AI Act says about the GDPR, verbatim
The answer is in Article 2(7) of Regulation (EU) 2024/1689, and it leaves no room for interpretation. Union data protection law continues to apply to personal data processed in connection with the rights and obligations laid down by the AI Act.
«This Regulation shall not affect Regulation (EU) 2016/679 or (EU) 2018/1725, or Directive 2002/58/EC or (EU) 2016/680.»
Regulation (EU) 2024/1689, Article 2(7)
The exceptions cited by the same line are two and concern cases far from a small business: processing special categories of data to correct bias in high-risk systems, and regulatory sandboxes. Outside those, the GDPR remains whole.
The practical consequence is unpleasant but useful to know straight away. One compliance doesn't buy the other: a company can have its record of processing in order and breach the AI Act, or disclose its systems correctly and process data without a legal basis.
Who supervises what, in Italy
The authorities are separate. On the AI Act, Article 20 of Law 132/2025 designates AgID and ACN as national authorities, and gives ACN supervision, including inspection and penalty activities. On the processing of personal data, the Italian Data Protection Authority (Garante per la protezione dei dati personali) remains competent.
The Data Protection Authority enters the AI Act, but within a narrow scope. Article 74(8) asks Member States to designate data protection authorities as market surveillance authorities for the high-risk systems of Annex III point 1 used for law enforcement, border management, justice and democracy, and for those of points 6, 7 and 8.
For a business that sells products, serves customers or manages bookings, that scope isn't touched. ACN supervises its website assistant, the Data Protection Authority supervises its customers' data, and both can happen on the same day for the same system.
The two impact assessments, which almost everyone confuses
They are different tools, with different conditions and different addressees. The confusion comes from the similar name, and leads small businesses to fear an obligation that in almost every case doesn't concern them.
| Tool | When it kicks in | Who has to do it |
|---|---|---|
| DPIAArticle 35 GDPR | When processing presents a high risk to the rights and freedoms of people. The trigger is the processing, not the technology: it existed before AI and continues to apply without AI. |
The data controller, so a small business too, when the conditions of the rule are met. |
| Fundamental rights assessmentArticle 27 AI Act | Before using certain high-risk systems. It looks at processes, period of use, categories of people affected, risks of harm, human oversight and complaint mechanisms. |
Bodies governed by public law, private entities providing public services, and deployers of the systems in Annex III point 5, points (b) and (c). |
| The point of contactArticle 26(9) AI Act | When a deployer of a high-risk system has to carry out the DPIA, it uses the information the provider gave it under Article 13 of the AI Act. |
Whoever falls under both. The two assessments feed each other, and don't replace each other. |
A small business using an assistant on its website or a model that writes texts is, as a rule, outside Article 27 and inside the ordinary GDPR reasoning. The right question to ask isn't whether there is AI, but which data of which people ends up in the system.
If you give customer data to a third-party model
It is the most frequent and most underrated case. When you paste a customer's details, an email you received or a list of orders into a generative model, that provider processes personal data on your behalf, and you need the agreement provided for by Article 28 of the GDPR, with the written conditions the rule requires.
Then three things should be checked, always the same. Where the data sits and whether it leaves the European Economic Area. On what legal basis you process it, which is almost never consent. What your privacy notice says, which must be updated if the processing changes.
There is a practical rule that covers ninety per cent of everyday situations, and it needs no lawyer to apply: what you wouldn't have pasted into an email to an external supplier isn't pasted into a prompt. On the duty to explain this to those who work with you, the training obligation of Article 4 comes into play.
What the Italian law adds, and it isn't little
Law 132/2025, in force since 10 October 2025, places principles on top of the European regulation. Article 4 requires the use of AI systems to ensure lawful, fair and transparent processing of personal data and compatibility with the purposes for which the data was collected.
The same article requires information on processing to be given in clear and plain language, so as to ensure that the risks are knowable and the right to object can be exercised. It is a demand for readability, and it hits privacy notices written not to be read.
Then there is a line on minors that concerns anyone with a young audience: access to AI technologies under the age of fourteen, and the resulting processing of data, require the consent of whoever holds parental responsibility.
The exception on special data concerns those who build
The debate circulates the idea that the AI Act has opened a derogation on sensitive data. The derogation exists, in the new Article 4a introduced by Regulation (EU) 2026/1744, and it is narrowly written: it applies only to providers of high-risk systems, and only to detect and correct bias.
The conditions are cumulative and strict. The result must not be achievable with other data, including synthetic or anonymised data; pseudonymisation, technical limits on re-use, state-of-the-art security measures, and rigorous access controls and documentation are needed.
For a business that buys tools instead of building them, the practical reading is just one: that door doesn't open. For your customers' special category data, Articles 9 onwards of the GDPR continue to apply, as before.
The penalties are two separate frameworks
Both can be triggered by the same fact, because they punish different things. The GDPR, in Article 83, goes up to €10 million or 2% of worldwide annual turnover for some infringements, and up to €20 million or 4% for the most serious, including the basic principles of processing and the conditions for consent.
The AI Act, in Article 99, goes up to €35 million or 7% for the prohibited practices of Article 5, and up to €15 million or 3% for a list of obligations that includes the transparency of Article 50. For SMEs, the same article provides that the lower of the two amounts applies.
The figures serve to give the scale, not to frighten anyone. The realistic risk for an ordinary business is very far from the statutory maximum, and it takes one form only: a complaint from a customer or an employee that opens an investigation. At that point only what you can show counts.
The five things to put in order
Setting theory aside, the work a small business needs comes down to five points, and none requires a project. Whoever already keeps a record of processing has three of them half done.
One, the list. Which AI systems run, who activated them, what data they work on and where that data sits. Two, the contracts. For every supplier that processes data for you, the Article 28 agreement and a check on where the data ends up.
Three, the privacy notice. Updated if the processing has changed, and written readably as the Italian law requires. Four, the people. Whoever uses those systems must know what doesn't go into them, and that is also the Article 4 obligation.
Five, the human step. On every automated process that touches a customer, money or an outgoing communication, a person approves before it goes out. In the systems we build the rule is written like that, and replies on information already approved by the owner can go out on their own while stating that they are a system, as Article 50 requires, applicable from 2 August 2026. The extended scope is in the AI principles, the list of systems we actually use on the AI transparency page.
Questions and answers
Does the AI Act replace the GDPR?
No, they add up. Article 2(7) of Regulation (EU) 2024/1689 says the regulation shall not affect the GDPR, and that Union data protection law continues to apply to data processed in connection with the obligations of the AI Act.
A business using an AI system on people's data answers to two bodies of rules at once, and compliance with one doesn't prove compliance with the other.
Does the Italian Data Protection Authority also check the AI Act?
For an ordinary SME, no. Article 74(8) designates data protection authorities as market surveillance authorities only for certain high-risk systems: Annex III point 1 used for law enforcement, borders, justice and democracy, and points 6, 7 and 8.
Outside that, in Italy the AI Act is supervised by ACN, under Article 20 of Law 132/2025. The Data Protection Authority remains fully competent for the GDPR, and that competence hasn't been touched.
Do I need an impact assessment if I use artificial intelligence?
The assessments are two and distinct. The DPIA under Article 35 GDPR kicks in when processing presents a high risk to people's rights, regardless of AI.
The fundamental rights assessment under Article 27 of the AI Act concerns only deployers of certain high-risk systems: bodies governed by public law, private entities providing public services, and the systems in Annex III point 5, points (b) and (c). A small business with an assistant on its website almost never falls within it.
If I use ChatGPT on my customers' data, what do I have to do?
The provider processes that data on your behalf, so you need the Article 28 GDPR agreement, that is, appointment as data processor with the written conditions the rule requires. Then you check where the data sits, on what legal basis you process it, and whether the privacy notice is still true.
The practical rule that covers most everyday situations: what you wouldn't have pasted into an email to an external supplier isn't pasted into a prompt.
What penalties do I risk, and from whom?
Two separate frameworks, both of which can be triggered by the same fact. The GDPR (Article 83) goes up to €10 million or 2% of worldwide annual turnover, and to €20 million or 4% for the most serious infringements.
The AI Act (Article 99) goes up to 35 million or 7% for prohibited practices, and to 15 million or 3% for a list that includes the transparency of Article 50. For SMEs the AI Act applies the lower of the two amounts.
Notes on sources
- Regulation (EU) 2024/1689 (AI Act), EUR-Lex: Article 2(7) on the relationship with the GDPR; Article 26(9) on the link with the DPIA; Article 27 on the fundamental rights impact assessment; Article 74(8) on data protection authorities; Article 99 on penalties.
- Regulation (EU) 2016/679 (GDPR), EUR-Lex: Article 28 on the processor, Article 35 on the impact assessment, Article 83(4) and (5) for the two penalty bands.
- Regulation (EU) 2026/1744, the digital omnibus on AI, published on 24 July 2026: the new Article 4a on processing special categories of data for detecting and correcting bias.
- Law No 132 of 23 September 2025, Italian Official Gazette No 223 of 25 September 2025, in force since 10 October 2025: Article 3 on general principles, Article 4 on information and confidentiality of data, Article 20 on the national authorities.
- This page doesn't list the cases in which a DPIA is mandatory, because that list also depends on the national authority's decisions and should be checked on the specific case. It is the point where a professional gives the answer, not a web page.
This article is an operational overview, not a legal opinion. On specific situations, and in particular on legal bases and transfers of data outside the Union, the answer comes from a professional who looks at your company.
Two regulations, one question: which data goes into your systems.
The list of systems in use and of the data passing through them is the document that serves on both sides, and you can make it yourselves. If you are about to put into production something that touches customer data, it pays to design it with the human step and the disclosures already inside instead of fixing it afterwards. It is fifteen minutes on a call, with the Cruscotto open.