Controllers
Anyone deciding why and how personal data is processed — the company that deploys an AI system on customer, employee or applicant data is the controller of that processing.
The regulation binds by role, not by sector — and the EU AI Act's own roles do not change who is the controller.
Anyone deciding why and how personal data is processed — the company that deploys an AI system on customer, employee or applicant data is the controller of that processing.
Anyone processing on a controller's instructions — a provider that hosts or fine-tunes a model on its customer's data is usually a processor, bound by an Art. 28 contract.
Art. 3 reaches any organisation offering goods or services to people in the EU or monitoring their behaviour, wherever it is established; Art. 27 then asks for an EU representative.
No certificate is required. Art. 42 schemes exist, are voluntary, and are never issued by Veritome.
| Date | Event | What it means |
|---|---|---|
| 27.04.2016 | Adopted | Regulation (EU) 2016/679 adopted by the Parliament and the Council. |
| 24.05.2016 | In force | Entered into force twenty days after publication in the Official Journal. |
| 25.05.2018 | Applies | Applicable in every member state since this date — no transition remains. |
| 02.08.2026 | EU AI Act Art. 50 | The EU AI Act's transparency duties apply since 02.08.2026; they sit beside, not instead of, the GDPR's own Art. 13 and 14 notices. |
| 02.12.2027 | EU AI Act Annex III | From this date a deployer of a high-risk system uses the provider's Art. 13 information for its GDPR Art. 35 DPIA (EU AI Act Art. 26(9)). |
The catalogue behind the programme is the 61 articles and paragraphs the 19 steps close in the owner-verified matrix — not a claim to cover the whole regulation. It runs from the Art. 5 principles and Art. 6 and 9 lawful bases through the Art. 12–22 rights, Art. 24–32 accountability and security, Art. 33–36 breaches and impact assessments, to the Chapter V transfer rules. The titles on the page are the articles' own headings; the GDPR is public law.
GDPR is an accountability programme, not a management system, so the path is Establish · Map · Protect · Operate — 4 gate-locked phases with the same rule the EU AI Act journey uses: a phase opens when the one before it is complete. A fifth bucket, Conditional / specialist, sits outside the line: consent, the EU representative, transfers, authority cooperation, codes and certification. It is never locked and never blocks a later phase, and 3 of its steps start as not applicable until the fact holds on your register — for instance, a transfer step opens only once a system says personal data leaves the EU/EEA.
Conditional / specialist holds the 5 steps that are never gate-locked and never block a phase. 3 of them open on a fact from your register — until it holds, or a person flips the step, each stays marked not applicable:
Nothing in the GDPR programme is credited against another framework — the owner's verified matrix found no clause it could check as identical. What it carries is related links: steps whose record supports an EU AI Act, ISO or NIST requirement, shown in the drawer as supporting reading and never counted as coverage. The DPIA is the exception in practice — the FRIA and the DPIA share their parts, and Veritome maps one onto the other.
| With | Records credited in both | Related only — shown, never credited | Page |
|---|---|---|---|
| EU AI Act | 0 | 17 | EU AI Act → |
| ISO 42001 | 0 | 16 | ISO 42001 → |
| ISO 27001 | 0 | 11 | ISO 27001 → |
| NIST AI RMF | 0 | 4 | NIST AI RMF → |
10 of the 19 steps carry a related link to an EU AI Act article. A related link is a supporting candidate the owner's verified matrix did not check against source text; the product shows it beside the step and never counts it as coverage. The full matrix for all five frameworks is on the frameworks page; the EU AI Act itself, article by article, is at /eu-ai-act.
The answers below are the ones the page marks up for search engines and AI assistants — the same text, nothing hidden.
No. The EU AI Act applies without prejudice to the GDPR, so an AI system that processes personal data answers to both. The EU AI Act adds duties by role and risk tier; the GDPR keeps its lawful-basis, transparency, rights and security duties whatever the tier. The EU AI Act also points back to the GDPR — Art. 26(9) has a deployer use the provider's instructions for its Art. 35 DPIA.
When the processing is likely to result in a high risk to people — Art. 35 names systematic and extensive evaluation, decisions with legal or similarly significant effects, and large-scale special-category data. Most AI systems that profile, score or rank people meet that threshold. The FRIA the EU AI Act asks of some deployers shares its parts with the DPIA, and Veritome fills one from the other rather than asking twice.
Not a ban — a right. A person has the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, unless the decision is necessary for a contract, authorised by law or based on explicit consent, and then with safeguards such as human intervention and the right to contest. Whether a given decision is 'solely' automated is a question the record has to answer honestly.
One of the six in Art. 6 — most often legitimate interests, which needs a documented balancing test, or consent, which must be as easy to withdraw as to give. Special-category data needs an additional Art. 9 condition. Veritome's lawful-basis step records the basis and the reasoning per purpose; it does not decide the basis for you.
No certificate is required, and none makes you compliant. Art. 42 allows voluntary certification schemes approved by supervisory authorities, and a few exist. Veritome is not a certifier and never issues one; the programme produces the records an authority or a customer would ask to see.
Yes, when it offers goods or services to people in the EU or monitors their behaviour there (Art. 3(2)). Such a controller or processor usually has to designate a representative in the EU under Art. 27 — one of the conditional steps in the programme.
19 steps in 4 gate-locked phases plus the Conditional / specialist bucket, closing 61 article-level references. Every step produces a record, and 3 steps open only when the condition holds on your register. Programmes come with a workspace; the free check shows which EU AI Act and GDPR duties a system carries first.