AI & data protection law

EU AI Act & GDPR

Spanish and EU legal advice on the EU AI Act, GDPR and AI-related data protection.

  • Spain-Licensed Attorney · ICATF nº 5961
  • Spanish · English · Romanian
  • Las Chafiras · Tenerife South
  • Online service where appropriate

Direct answer

Does the EU AI Act apply to my organisation or AI system?

The answer depends on the system, its intended use, the organisation's role, territorial scope and the specific obligation being analysed. A legal review should first establish scope and role, then determine whether the issue concerns the AI Act, GDPR or both.

EU AI Act & GDPR

Main legal questions we review

AI Act scope & roles

Assess whether the Regulation applies and identify the legally relevant role of the organisation or system.

Transparency & prohibited practices

Review current AI Act duties without treating guidance or best practice as if it were legislation.

High-risk classification

Analyse Article 6 and the relevant Annex route using the current amended application timeline.

GDPR + AI

Assess lawful basis, transparency, data minimisation, roles, rights and other GDPR duties where personal data is processed.

DPIA & automated decisions

Review whether a DPIA or Article 22 GDPR analysis is actually triggered by the facts.

AI Act

Role and classification come before the checklist.

Provider, deployer, importer and distributor obligations are not interchangeable. High-risk classification also depends on the legal route in Article 6 and the applicable Annex. The analysis should start there rather than with a generic compliance list.

GDPR

The AI Act does not replace data-protection law.

If an AI use involves personal data, GDPR questions may arise independently: lawful basis, transparency, minimisation, special-category data, international transfers, DPIA and automated decisions depending on the facts.

Current high-risk dates

The 2026 amendment changed part of the original implementation calendar.

Under the current amended Article 113, Chapter III Sections 1–3 apply from 2 December 2027 for systems classified as high-risk under Article 6(2)/Annex III and from 2 August 2028 for Article 6(1)/Annex I systems, subject to the exact current consolidated text and the obligation being analysed.

Legal scoping

Start by identifying the law, the role and the obligation.

A consultation can be used to determine whether the AI Act, GDPR or both apply to the specific system and organisation.

Request a Consultation