AI Act scope & roles
Assess whether the Regulation applies and identify the legally relevant role of the organisation or system.
AI & data protection law
Spanish and EU legal advice on the EU AI Act, GDPR and AI-related data protection.
Direct answer
The answer depends on the system, its intended use, the organisation's role, territorial scope and the specific obligation being analysed. A legal review should first establish scope and role, then determine whether the issue concerns the AI Act, GDPR or both.
EU AI Act & GDPR
Assess whether the Regulation applies and identify the legally relevant role of the organisation or system.
Review current AI Act duties without treating guidance or best practice as if it were legislation.
Analyse Article 6 and the relevant Annex route using the current amended application timeline.
Assess lawful basis, transparency, data minimisation, roles, rights and other GDPR duties where personal data is processed.
Review whether a DPIA or Article 22 GDPR analysis is actually triggered by the facts.
AI Act
Provider, deployer, importer and distributor obligations are not interchangeable. High-risk classification also depends on the legal route in Article 6 and the applicable Annex. The analysis should start there rather than with a generic compliance list.
GDPR
If an AI use involves personal data, GDPR questions may arise independently: lawful basis, transparency, minimisation, special-category data, international transfers, DPIA and automated decisions depending on the facts.
Current high-risk dates
Under the current amended Article 113, Chapter III Sections 1–3 apply from 2 December 2027 for systems classified as high-risk under Article 6(2)/Annex III and from 2 August 2028 for Article 6(1)/Annex I systems, subject to the exact current consolidated text and the obligation being analysed.
Primary sources
Legal scoping
A consultation can be used to determine whether the AI Act, GDPR or both apply to the specific system and organisation.