The AI Act and the GDPR apply at the same time to any artificial intelligence system that processes personal data. Regulation (EU) 2024/1689 governs the product, its risks and who is responsible for it, while Regulation (EU) 2016/679 governs the processing of the data. The AI Act does not displace the GDPR, except on two specific points. The Digital Omnibus on AI, in force since 27 July 2026, added the more important of them. It is a new Article 4a that allows sensitive data to be processed to detect and correct bias. For a business, the coexistence means two impact assessments that can share content and three layers of safeguards against automated decisions. And in Spain, different authorities depending on the type of system. Today it is mainly the GDPR that bites, because the AI Act’s high-risk rules do not arrive until December 2027.
If you need an AI lawyer in Spain for your business, request a free initial assessment.
The AI Act is a product safety law. It asks who places an AI system on the market or uses it, which risk level it falls into and which requirements it must meet. The GDPR is a data protection law. It asks who decides the purposes of the processing, on what legal basis and with what safeguards for the individual.
The roles do not necessarily coincide. The provider of an AI system may be its customer’s processor, and the deployer is usually the controller. But each role is decided with the criteria of its own law.
The Digital Omnibus on AI, Regulation (EU) 2026/1744, rewrote Article 2(7) of the AI Act. Union data protection law applies to personal data processed in connection with the AI Act. And the AI Act does not affect the GDPR, except as provided in its Articles 4a and 59. The latter governs data processing in regulatory sandboxes.
The GDPR in principle prohibits processing special categories of data, such as ethnic origin or health. The original AI Act allowed them to be processed to correct bias only by providers of high-risk systems, in Article 10(5). The Omnibus deleted that paragraph and replaced it with a broader Article 4a.
Providers of high-risk systems may exceptionally process such data where strictly necessary to detect and correct bias, if six conditions are met.
The novelty is in paragraph 2. On the same conditions, providers and deployers of other AI systems and models, and deployers of high-risk systems, may also do so. They must be addressing bias that could affect health, safety or fundamental rights, or lead to discrimination. The article makes clear that it creates no obligation to do so.
An AI system that processes personal data with high risk may need two different assessments. The GDPR one protects the data, and the AI Act one protects fundamental rights more broadly.
| Assessment | Who carries it out | Basis |
|---|---|---|
| Data protection impact assessment | The controller, if the processing is likely to result in a high risk | Article 35 GDPR |
| Fundamental rights impact assessment | Public bodies, private entities providing public services and those using AI to assess creditworthiness or price life and health insurance | Article 27 AI Act |
Article 26(9) of the AI Act requires the deployer of a high-risk system to use the provider’s information for its GDPR assessment. And the Omnibus rewrote Article 27(4), which now allows the fundamental rights assessment to include cross-references to the GDPR one, or the relevant parts of it. The AI Office must publish a model questionnaire, with an automated tool, that allows for that re-use.
The Article 27 assessment does not reach every company. A private company that uses AI to recruit needs the GDPR assessment, not the AI Act one.
When an AI system decides about a person, three rules with different scopes overlap.
The difference is one of scope. The GDPR protects against fully automated decisions. The AI Act also protects when a person decides with the help of the system. In employment, Spain adds a fourth layer, algorithmic transparency for workers, required by Royal Decree 723/2026.
The Spanish Data Protection Agency (AEPD) remains the GDPR authority for any AI system that processes personal data. It showed this on 23 September 2026 with a warning to a company that was about to use AI to screen CVs, based solely on the GDPR. We explain it in our AI Act compliance guide for businesses.
For the AI Act, the Organic Law bill on the proper use and governance of artificial intelligence gave general supervision to the Spanish Agency for the Supervision of Artificial Intelligence (AESIA). It reserved to the AEPD the supervision of certain biometric practices and of migration and border control systems. The bill lapsed when the Spanish Parliament was dissolved in October 2026 and will have to be reintroduced. If it keeps that allocation, the same company may have two supervisors for the same system.
This case is fictitious. Segura Salud Digital, S.A. sells health insurance online from Bilbao. It wants to use an AI model from an external provider to set each customer’s premium from a health and lifestyle questionnaire.
Under the GDPR, it processes health data, so it needs an exception under Article 9 and an impact assessment under Article 35. Under the AI Act, the use falls under point 5(c) of Annex III, so it is high-risk. As deployer, from 2 December 2027 it will also have to carry out the fundamental rights assessment. And it will have to tell customers that the system plays a part in setting their premium.
If it finds that the model raises premiums for certain groups without justification, Article 4a allows it to process sensitive data to correct this. It will have to meet the six conditions. It will be able to re-use the relevant parts of the GDPR assessment in the AI Act one. The high-risk obligations are set out in our guide to high-risk AI systems.
No. Article 2(7) of the AI Act, rewritten by the Digital Omnibus on AI, keeps data protection law in place for personal data processed in connection with AI. The AI Act does not affect the GDPR, except in its Article 4a, on sensitive data to correct bias, and in its Article 59, on regulatory sandboxes.
Yes, exceptionally and, since the Omnibus, also outside high risk. Article 4a allows it where strictly necessary to detect and correct bias and synthetic or anonymised data are not enough. It requires pseudonymisation, restricted access, no disclosure to third parties, subsequent deletion and a justification in the record of processing activities.
It depends. The GDPR assessment is mandatory if the processing is likely to result in a high risk. The AI Act fundamental rights assessment is only carried out by public bodies, entities providing public services and those using AI to assess creditworthiness or price insurance. If both are needed, the second can refer to the first.
Article 22 GDPR restricts decisions based solely on automated processing with significant effects. Article 86 of the AI Act grants a right to an explanation of decisions taken with Annex III high-risk systems, even where a person is involved. The second covers decisions the first does not reach.
Both, each in its own field. The Spanish Data Protection Agency supervises the GDPR in any system that processes personal data. For the AI Act, the Organic Law bill on the governance of AI, which lapsed in October 2026, gave general supervision to AESIA and reserved to the AEPD certain biometric practices and migration systems.
The AI Act does not lower any GDPR obligation, and the Omnibus only opens one specific door, that of sensitive data to correct bias. The practical approach is to handle both laws with a single inventory of systems, one assessment feeding the other and a clear allocation of roles with each provider. That way today’s GDPR compliance gets much of the 2027 AI Act work done in advance. At Innovatech we coordinate both layers as part of our AI legal advisory service. Write to us and we will give you a free initial assessment.
Marta Suárez-Mansilla is Managing Partner of Innovatech Legal and a Spanish lawyer (abogada), Madrid Bar (ICAM), working in technology law. She completed Harvard Law School's Copyright course and BerkeleyX's Blockchain programme, and has advised technology companies for more than eight years.
