EU Regulation · source: EUR-Lex

With the AI Act, is the GDPR still in force for my SME?

In short: yes, and in full. The AI Act applies «without prejudice to» the GDPR: they are two cumulative tracks. Anyone processing personal data with AI systems must comply with both — complying with one does not exempt you from the other. Below are the facts verified on EUR-Lex, then our reading on how to coordinate them within a single governance framework.

The facts · fields 1–10

What the official source says.

Verified on EUR-Lex

01 · Name

Regulation (EU) 2016/679 — GDPR

«Regulation of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC». Common abbreviation: GDPR (in Italian RGPD).

EUR-Lex · ELI reg/2016/679

02 · Type of source

Regulation of the European Union

An EU legislative act of general application, adopted by the European Parliament and the Council. It repeals and replaces the previous Directive 95/46/EC. It comprises 99 articles and 173 recitals.

EUR-Lex · Reg. (EU) 2016/679

03 · Nature

Binding and directly applicable

As an EU regulation (Art. 288 TFEU) it is binding in its entirety and directly applicable in each Member State, without the need for national transposition. It is not soft law: it sets out specific obligations and a robust penalty regime (Art. 83).

Art. 288 TFEU + text of the Regulation on EUR-Lex

04 · Subject matter

Protection of personal data and free movement

It lays down the harmonised rules for the protection of natural persons with regard to the processing of personal data and for the free movement of such data within the EU. It governs principles (lawfulness, fairness, transparency, minimisation, purpose and storage limitation, integrity and confidentiality, accountability), legal bases, data subjects' rights, obligations of controllers and processors, transfers to third countries, security and personal data breaches.

EUR-Lex · Reg. (EU) 2016/679

05 · Who it applies to

Controllers and processors — with extraterritorial effect

  • Material scope: to the wholly or partly automated processing of personal data and to the non-automated processing of data contained in (or intended for) a filing system.
  • Personal scope: data controllers and data processors, public and private.
  • Territorial scope (Art. 3) — extraterritorial: it also applies to controllers/processors established outside the EU when they process the data of data subjects who are in the Union in order to offer them goods/services or to monitor their behaviour.

EUR-Lex · Reg. (EU) 2016/679 (Arts. 2 and 3)

06 · Key dates

From adoption to full application

  1. Adoption of the Regulation.

  2. Publication in the Official Journal of the European Union (OJEU L 119).

  3. Entry into force (20th day after publication — Art. 99(1)).

  4. Date of application (Art. 99(2)): from this date the GDPR is fully operational and replaces Directive 95/46/EC.

EUR-Lex · Reg. (EU) 2016/679, Art. 99 (dates corroborated by independent sources)

07 · Authorities / bodies

The Garante in Italy; the EDPB at EU level

  • At national level (Italy): the Italian Data Protection Authority (Garante per la protezione dei dati personali) — an independent supervisory authority (Arts. 51 et seq.), competent for supervision, investigation and penalties.
  • At EU level: the European Data Protection Board (EDPB), which ensures the consistent application of the Regulation, and the European Data Protection Supervisor (EDPS) for the EU institutions.

EUR-Lex · Reg. (EU) 2016/679 (Chapters VI and VII)

08 · Status

Fully applicable since 25 May 2018

In force since 24 May 2016 and fully applicable since 25 May 2018. Fully operational and binding. In Italy it is coordinated with the Privacy Code (Legislative Decree 196/2003 as amended by Legislative Decree 101/2018) for alignment. The penalty regime (Art. 83) is active.

EUR-Lex · Reg. (EU) 2016/679

09 · Relationship with other rules

«Without prejudice to» by the AI Act; reaffirmed by Law 132/2025

  • ↔ AI Act (Reg. EU 2024/1689) — «without prejudice to»: the AI Act applies without prejudice to the GDPR. The two regulations operate in parallel, cumulatively: the AI Act governs the AI system, while any processing of personal data involved remains fully subject to the GDPR. Points of contact: legal basis for training data, minimisation, automated decision-making (Art. 22), DPIA (Art. 35).
  • ↔ Law 132/2025 (Italy): the national law reaffirms that the processing of personal data connected with AI remains subject to the GDPR and to the Privacy Code, with the Garante as the competent authority.
  • ↔ ISO/IEC 42001: a voluntary standard; it may include safeguards useful for data protection, but it does not replace GDPR obligations.

EUR-Lex · «without prejudice to» the GDPR clause in Reg. (EU) 2024/1689 + GDPR text

10 · Official source

EUR-Lex — ELI identifier

Primary source to cite: EUR-Lex, ELI identifier. Official Italian text CELEX 32016R0679. Published in OJEU L 119 of 4 May 2016 (with a corrigendum in OJEU L 127 of 23 May 2018).

Open the official source on EUR-Lex

Primary source · EUR-Lex (ELI reg/2016/679)

NomotecnIA reading · interpretation, not a source

Fields 11–12 · our own synthesis

Our reading for an SME.

Synthesis

  • The GDPR is the pre-existing foundation on which the entire body of AI regulation is grafted: anyone processing personal data with AI systems must comply with both regimes. The AI Act adds to, rather than removes, privacy obligations.
  • The key formula is «without prejudice to the GDPR»: the AI Act does not affect the personal-data rules. An SME that thinks it can "cover" privacy by adopting AI Act measures makes a mistake: they are two cumulative tracks.
  • The penalty regime is severe and dual-threshold: GDPR penalties remain among the highest in the EU legal order and sit alongside (and may cumulate with) the further penalties provided for by the AI Act.
  • Practical junctions where AI and the GDPR intertwine: legal basis for training data, minimisation, automated decision-making and profiling (Art. 22), DPIA (Art. 35).
  • For an SME, the efficient path is a single governance framework that handles the GDPR, the AI Act and (if adopted) ISO/IEC 42001 together, avoiding duplicated obligations.

Practical obligations for an SME

  1. Record of processing activities (Art. 30): map the processing of personal data, including that carried out through AI systems.
  2. Legal basis (Art. 6) and transparency (Arts. 13-14): identify the legal basis for each AI processing operation and inform data subjects clearly.
  3. DPIA (Art. 35): carry out a data protection impact assessment where the processing (often through AI) presents high risks to data subjects' rights.
  4. Automated decision-making (Art. 22): safeguard cases of solely automated decision-making/profiling, ensuring human intervention, information and the right to contest.
  5. Security (Art. 32) and data breach (Arts. 33-34): adequate technical/organisational measures and a procedure for notifying breaches to the Garante within 72 hours.
  6. Contracts (Art. 28): set out in writing the relationship with processors (e.g. providers of AI models/services that process data on the company's behalf).
  7. Penalties — dual threshold (Art. 83): up to EUR 20 million or 4% of total worldwide annual turnover (whichever is higher) for the most serious infringements (Art. 83(5)); up to EUR 10 million or 2% for infringements under Art. 83(4).

Positioning note (NomotecnIA): NomotecnIA provides guidance and support towards readiness in coordinating the GDPR and the AI Act within a single governance framework; it is not a notified body and does not issue certifications. Formal privacy compliance (e.g. appointing a DPO where required) remains the controller's responsibility.

In depth

The articles that cite this regulation.

Editorial watch · dated

Meta · fields 13–15

Review, disclaimer, changelog, author and sources

Last updated · 2026-07-10

Disclaimer

This content is provided for information and general guidance purposes only; it does not constitute legal advice or an attestation of compliance. For any assessment, the official source (EUR-Lex) always prevails and, for Italy, coordination with the Privacy Code (Legislative Decree 196/2003 as amended by Legislative Decree 101/2018). NomotecnIA is not a notified body or a certification body under Arts. 42-43 GDPR.

  • #GDPR
  • #RGPD
  • #EURegulation
  • #DataProtection
  • #Garante
  • #EDPB
  • #Art83
  • #AIAct
  • #WithoutPrejudice
  • #DPIA
  • #SME

Changelog

Revision history

  1. 2026-07-06

    First publication — research verified against the official source and editorial review (CCO).

  2. 2026-07-10

    Editorial enrichment — added In-depth section, accredited author and list of sources.

Author

Matteo Colacchio

CEO · AI Governance, NomotecnIA

Author profile →

LinkedIn: to be linked

Official sources

Where we verified

Official source · EUR-Lex

From the rule to your company

How can you coordinate the GDPR and the AI Act without duplicating the work?

The AI Entry Assessment brings privacy and European compliance together into a single governance framework: record of processing activities and of AI systems, a DPIA that speaks to both regimes, and a prioritised roadmap.