The most common mistake SMEs make with the EU AI Act is treating it as a separate project from GDPR. In practice the two overlap almost entirely: ChatGPT processing customer data is a GDPR matter and an AI Act matter at once. Run them separately and you double the work and risk records that contradict each other under audit. This guide shows how to run them as one workflow. It connects the two pillars - GDPR documentation and the EU AI Act.
- Most AI use is also personal-data processing - GDPR and the AI Act apply at the same time.
- Integrate three things: the ROPA, the DPIA + FRIA, and a single DPO function.
- One workflow avoids the contradictions two separate systems create.
Why You Shouldn't Run Two Separate Projects
What's the risk of keeping them apart?
Duplicated effort is the smaller problem; contradictory documentation is the bigger one. If your AI inventory says one thing and your ROPA another, an auditor sees an inconsistency - and inconsistency reads as a gap. Because the underlying facts (which tool, which data, which purpose) are identical, maintaining them twice is both wasteful and risky. One source of truth is safer and cheaper.
The Three Integration Points
Where exactly do GDPR and the AI Act connect?
1. The ROPA, extended for AI. Your Record of Processing Activities gains AI-specific fields: which model, which data, which purpose, which risk class. The AI inventory isn't a separate document - it's a view of the ROPA.
2. DPIA + FRIA together. For high-risk AI, the GDPR Data Protection Impact Assessment is supplemented by the AI Act's Fundamental Rights Impact Assessment. Run as one assessment, they share most inputs.
3. One DPO function. A single certified external DPO with AI Act competence reviews both, rather than splitting responsibility across two roles or vendors.
What This Looks Like in Practice
How do I actually combine them?
Start from the ROPA. For each entry, add the AI fields and classify the use case; where it's high-risk, run the combined DPIA + FRIA; reference the same TOM and the same training records (GDPR + AI literacy together). When a new AI tool appears, one process updates the ROPA, the privacy notice, the documentation and the classification at once. This is what keeps both regimes current without parallel tracking.
See how ETHYX maps GDPR + AI Act in one workflow
Timing: What Applies When
Does integrating change the deadlines?
No - it just lets you meet them efficiently. GDPR is fully in force; AI literacy is enforceable now; transparency duties apply from 2 August 2026; the high-risk obligations, for deployers as well as providers, were postponed to 2027-2028. Integrating means one set of work covers the live obligations of both regimes at once.