Inhalt Personal data

Encounters with AI

Personal data

The judgement

When AI use involves personal data, the GDPR is usually the practical instrument to use now. Article 2(7) of the AI Act preserves EU personal-data law rather than replacing it. AI Act authorities enforce the AI Act, while data-protection authorities and courts enforce the GDPR. That division has applied to the AI Act since 2 August 2026, and the GDPR itself has applied since 25 May 2018.12

What you need GDPR rule Who must act Enforcement and start
Know what personal data is used Articles 13 to 15 require information about purposes, categories, recipients, retention, available sources and relevant automated decision-making, plus a copy through access. The controller Data-protection authorities and courts, since 25 May 2018.2
Correct inaccurate personal data Article 16 requires inaccurate data to be corrected without undue delay and permits incomplete data to be completed. The controller Data-protection authorities and courts, since 25 May 2018.2
Seek erasure Article 17 requires erasure when a listed ground applies, but exceptions include legal retention duties and public-interest tasks. The controller Data-protection authorities and courts, since 25 May 2018.2
Obtain a response Article 12 requires facilitation of requests and normally a response within one month, usually free of charge. The controller Data-protection authorities and courts, since 25 May 2018.2

If the controller does not deal properly with personal data, GDPR Articles 77 and 79 permit a complaint to a data-protection authority or a court claim against a controller or processor. No EU-wide template was identified for combining that process with an AI Act complaint.2

Some AI-specific data rules already apply. Under Article 50(3), a deployer using emotion recognition or biometric categorisation must inform exposed people. AI market-surveillance authorities have enforced that disclosure duty since 2 August 2026, while data-protection authorities enforce the accompanying personal-data rules.1

Article 4a permits providers and deployers to process special-category data for strictly necessary bias work only with safeguards such as access controls, pseudonymisation, reuse limits and deletion. AI authorities and data-protection authorities have enforced those conditions since 2 August 2026. The permission does not require organisations to conduct that work.1

Later duties concern data quality. From 2 December 2027 for Annex III systems and 2 August 2028 for Annex I product systems, Article 10 requires providers to use specified data governance and relevant, sufficiently representative datasets. Article 26(4) requires a deployer that controls a high-risk system’s input data to ensure its relevance and sufficient representativeness for the intended purpose. National market-surveillance authorities will enforce those duties.1

Boundary. Those future company duties do not give a person direct power to edit an AI dataset. Subject to Article 16, GDPR correction applies when personal data relating to an identified or identifiable person is inaccurate or incomplete.

Quellen

Quizze
  1. A lender’s AI-assisted assessment used an incorrect salary figure that is personal data about you. Which action seeks correction of that figure?

    • Ask the lender, as controller, to correct it under the GDPR
    • Make an AI Act complaint about the system’s data quality
    • Ask the software provider to change its general model

    The GDPR already supports correction of inaccurate personal data. Future AI Act data-quality duties do not provide direct dataset-editing power.

  2. When a high-risk AI system uses inaccurate personal data about someone, its AI Act data-quality duties are the individual’s correction mechanism rather than the GDPR route.

    • True
    • False

    Those duties bind providers and deployers. A person seeking correction must generally rely on the GDPR when the disputed information is personal data.

Kommentare

Noch keine Kommentare. Fang das Gespräch an.