The AI Act and the GDPR. The newer one didn't cancel the older one, and neither absorbs the other.
The question always comes in the same form: now that the AI Act is here, does the GDPR still matter? The regulation answers it itself, in one line of Article 2, and the answer is that the two add up.
The two regulations sit side by side. Article 2(7) of the AI Act states that it doesn't affect the GDPR. Complying with one tells you nothing about the other.
In Italy, two different authorities are in charge. The Garante on data processing, ACN on the AI Act, under Article 20 of Law 132/2025. The Garante only comes into the AI Act for certain high-risk systems.
There are two impact assessments, and they aren't the same thing. The DPIA under Article 35 of the GDPR looks at data; the one under Article 27 of the AI Act looks at fundamental rights and applies to very few.
For an ordinary SME there's little new work. If you already keep a record of processing and have your supplier contracts in order, you're most of the way there.
This piece belongs to the guide on AI Act obligations for businesses and SMEs and takes just one side of it: the relationship with data protection. It's written for people running a business, and it stops where a lawyer's work begins.
What the AI Act says about the GDPR, word for word
The answer is in Article 2(7) of Regulation (EU) 2024/1689, and it leaves no room for interpretation. EU data protection law continues to apply to personal data processed in connection with the rights and obligations laid down in the AI Act.
“This Regulation shall not affect Regulation (EU) 2016/679 or (EU) 2018/1725, or Directive 2002/58/EC or (EU) 2016/680.”
Regulation (EU) 2024/1689, Article 2(7)
The same line mentions two exceptions, and both concern cases far removed from a small business: processing special categories of data to correct bias in high-risk systems, and regulatory sandboxes. Beyond those, the GDPR stays whole.
The practical consequence is unwelcome but worth knowing straight away. Compliance with one doesn't buy compliance with the other: a company can have its record of processing in order and breach the AI Act, or disclose its systems correctly and process data without a legal basis.
Who enforces what in Italy
The authorities are separate. For the AI Act, Article 20 of Law 132/2025 designates AgID and ACN as national authorities, and gives ACN the supervisory role, including inspections and penalties. For personal data processing, the Garante, Italy's data protection authority, remains in charge.
The Garante does come into the AI Act, but within narrow limits. Article 74(8) asks Member States to designate data protection authorities as market surveillance authorities for the high-risk systems under point 1 of Annex III used for law enforcement, border management, justice and democracy, and for those under points 6, 7 and 8.
For a business selling products, serving customers or taking bookings, those limits never come into play. ACN oversees the assistant on its website, the Garante oversees its customers' data, and both can happen on the same day for the same system.
The two impact assessments almost everyone mixes up
They are different tools, with different triggers and different addressees. The confusion comes from the similar names, and it leads small businesses to fear a requirement that in almost every case doesn't apply to them.
| Tool | When it applies | Who has to do it |
|---|---|---|
| DPIAArticle 35 GDPR | When processing is likely to result in a high risk to people's rights and freedoms. The trigger is the processing, not the technology: it existed before AI and still applies without it. |
The controller, so a small business too, when the conditions in the law are met. |
| Fundamental rights assessmentArticle 27 AI Act | Before using certain high-risk systems. It looks at processes, period of use, categories of people affected, risks of harm, human oversight and complaint mechanisms. |
Bodies governed by public law, private entities providing public services, and deployers of the systems in Annex III, point 5, (b) and (c). |
| Where they meetArticle 26(9) AI Act | When a deployer of a high-risk system has to carry out a DPIA, it uses the information the provider gave it under Article 13 of the AI Act. |
Anyone who falls under both. The two assessments feed each other, and don't replace each other. |
A small business using an assistant on its website or a model that writes copy normally sits outside Article 27 and inside the ordinary GDPR analysis. The right question isn't whether AI is involved, but which data about which people ends up in the system.
If you give customer data to a third-party model
This is the most common case and the most underestimated. When you paste a customer's details, an email you've received or a list of orders into a generative model, that provider is processing personal data on your behalf, and you need the agreement required by Article 28 of the GDPR, with the written terms the law requires.
Then there are three things to check, always the same ones. Where the data is stored, and whether it leaves the European Economic Area. What legal basis you process it on, which is hardly ever consent. What your privacy notice says, which needs updating if the processing changes.
There's a practical rule that covers ninety per cent of everyday situations, and you don't need a lawyer to apply it: if you wouldn't have pasted it into an email to an outside supplier, it doesn't go into a prompt. The duty to explain this to the people who work with you comes from the training obligation in Article 4.
What Italian law adds, and it's not nothing
Law 132/2025, in force since 10 October 2025, places some principles on top of the European regulation. Article 4 requires the use of AI systems to ensure lawful, fair and transparent processing of personal data, compatible with the purposes for which the data was collected.
The same article requires information about processing to be given in clear and simple language, so that people can understand the risks and exercise their right to object. It's a demand for readability, and it hits privacy notices written not to be read.
There's also a line on minors that concerns anyone with a young audience: access to AI technologies by under-fourteens, and the data processing that goes with it, requires the consent of the person with parental responsibility.
The special-category exception is for builders
The idea going round is that the AI Act has opened an exemption for sensitive data. The exemption exists, in the new Article 4a introduced by Regulation (EU) 2026/1744, and it's tightly drawn: it applies only to providers of high-risk systems, and only to detect and correct bias.
The conditions are cumulative and strict. The result must not be achievable with other data, including synthetic or anonymised data; pseudonymisation, technical limits on re-use, state-of-the-art security measures, and strict controls and documentation of access are all required.
For a business that buys tools rather than building them, the practical reading is simple: that door doesn't open. Articles 9 onwards of the GDPR still apply to your customers' special-category data, as before.
The penalties are two separate frameworks
Both can apply to the same case, because they punish different things. The GDPR, in Article 83, goes up to €10 million or 2% of worldwide annual turnover for some infringements, and up to €20 million or 4% for the most serious, including the basic principles of processing and the conditions for consent.
The AI Act, in Article 99, goes up to €35 million or 7% for the prohibited practices in Article 5, and up to €15 million or 3% for a list of obligations that includes transparency under Article 50. For SMEs, the same article says the lower of the two figures applies.
The figures are there to show the scale, not to frighten anyone. For an ordinary business the realistic risk is a long way from the statutory maximum, and it takes one form: a complaint from a customer or employee that opens an investigation. At that point all that counts is what you can show.
The five things to put in order
Theory aside, the work a small business needs comes down to five points, and none of them calls for a project. If you already keep a record of processing, three of them are half done.
One: the list. Which AI systems run, who switched them on, what data they work on and where that data is stored. Two: the contracts. For every supplier processing data for you, the Article 28 agreement and a check on where the data ends up.
Three: the privacy notice. Updated if the processing has changed, and written to be readable, as Italian law requires. Four: the people. Everyone using those systems needs to know what doesn't go into them, and that's also the Article 4 obligation.
Five: the human checkpoint. On every automated process that touches a customer, money or an outgoing message, a person approves before it goes out. In the systems we build the rule is written exactly like that, and replies drawing on information the owner has already approved can go out on their own, saying they come from a system, as Article 50 requires from 2 August 2026. The full scope is in our AI principles, and the list of systems we actually use is on the AI transparency page.
Questions and answers
Does the AI Act replace the GDPR?
No, the two add up. Article 2(7) of Regulation (EU) 2024/1689 says the regulation doesn't affect the GDPR, and that EU data protection law continues to apply to data processed in connection with the AI Act's obligations.
A business using an AI system on people's data answers to two sets of rules at once, and complying with one doesn't prove compliance with the other.
Does the Italian data protection authority also enforce the AI Act?
For an ordinary SME, no. Article 74(8) designates data protection authorities as market surveillance authorities only for certain high-risk systems: point 1 of Annex III used for law enforcement, borders, justice and democracy, and points 6, 7 and 8.
Outside those, AI Act enforcement in Italy lies with ACN, under Article 20 of Law 132/2025. The Garante keeps its full powers over the GDPR, and those powers haven't been touched.
Do I need an impact assessment if I use artificial intelligence?
There are two separate assessments. The DPIA under Article 35 of the GDPR is needed when processing is likely to result in a high risk to people's rights, AI or no AI.
The fundamental rights assessment under Article 27 of the AI Act applies only to deployers of certain high-risk systems: bodies governed by public law, private entities providing public services, and the systems in Annex III, point 5, (b) and (c). A small business with an assistant on its website almost never falls under it.
If I use ChatGPT on my customers' data, what do I have to do?
The provider processes that data on your behalf, so you need the Article 28 GDPR agreement, appointing it as processor with the written terms the law requires. Then check where the data is stored, what legal basis you process it on, and whether your privacy notice is still accurate.
The practical rule that covers most everyday situations: if you wouldn't have pasted it into an email to an outside supplier, it doesn't go into a prompt.
What penalties do I face, and from whom?
Two separate frameworks, and both can apply to the same case. The GDPR (Article 83) goes up to €10 million or 2% of worldwide annual turnover, and €20 million or 4% for the most serious infringements.
The AI Act (Article 99) goes up to €35 million or 7% for prohibited practices, and €15 million or 3% for a list that includes transparency under Article 50. For SMEs, the AI Act applies the lower of the two figures.
Notes on sources
- Regulation (EU) 2024/1689 (AI Act), EUR-Lex: Article 2(7) on the relationship with the GDPR; Article 26(9) on the link with the DPIA; Article 27 on the fundamental rights impact assessment; Article 74(8) on data protection authorities; Article 99 on penalties.
- Regulation (EU) 2016/679 (GDPR), EUR-Lex: Article 28 on processors, Article 35 on impact assessments, Article 83(4) and (5) for the two penalty bands.
- Regulation (EU) 2026/1744, the digital omnibus on AI, published on 24 July 2026: the new Article 4a on processing special categories of data to detect and correct bias.
- Law no. 132 of 23 September 2025, Gazzetta Ufficiale no. 223 of 25 September 2025 (in Italian), in force from 10 October 2025: Article 3 on general principles, Article 4 on information and data confidentiality, Article 20 on the national authorities.
- This page doesn't list the cases where a DPIA is mandatory, because that list also depends on decisions by the national authority and has to be checked case by case. That's where the answer comes from a professional, not a web page.
This article is a practical overview, not legal advice. For specific situations, and in particular on legal bases and data transfers outside the Union, the answer has to come from a professional who looks at your business.
Two regulations, one question: what data goes into your systems.
The list of systems in use and the data passing through them is the document you need on both sides, and you can write it yourselves. If you're about to put something live that touches customer data, it's worth designing it with the human checkpoint and the disclosures built in rather than patching them on later. It's fifteen minutes on a call, with the Cruscotto open.