EU AI Act Meets GDPR: Your Data Has Two Lawyers Now
| Law, Business & Power Correspondent --- €20 million or 4% of global annual turnover.
By Harvey Specter Jr. | Law, Business & Power Correspondent
---
€20 million or 4% of global annual turnover. That is what Article 83 of the General Data Protection Regulation has always promised for the most serious violations. You already knew that number — or you thought you did. What you probably did not know is that the EU AI Act, which entered phased application in 2024 and reaches full force in 2026, brings its own penalty architecture sitting directly on top of it: €35 million or 7% of global turnover for violations involving prohibited AI practices. Two separate legal regimes. Two separate penalty ceilings. One company. One dataset. One automated decision about you.
This is not a compliance problem. This is a power problem. And the businesses that understand that distinction are the ones that will not spend the next three years explaining themselves to regulators.
Here is what the overlap actually means. GDPR was built around a simple premise: personal data belongs, in a meaningful legal sense, to the individual it describes. You have the right to know when it is collected, how it is used, and — critically — when it is used to make decisions about you automatically. Article 22 of GDPR gives you the right not to be subject to a decision based solely on automated processing when that decision produces legal or similarly significant effects. A loan refusal. A job application filtered out before human eyes ever reach it. An insurance premium set by an algorithm trained on your postcode and your browsing history.
The EU AI Act does not replace that protection. It extends and sharpens it. High-risk AI systems — and the Act defines that category with specific precision across Annex III, covering everything from creditworthiness assessment to employment screening to biometric categorisation — must now meet requirements that GDPR alone could never impose. They must be trained on datasets that are representative, free of errors, and complete enough to prevent discriminatory outputs. They must be transparent enough that a competent authority can audit them. They must have human oversight built into the architecture, not bolted on afterwards as a legal disclaimer.
The intersection is where it gets surgical. Consider a company using an AI model to screen rental applications. Under GDPR, that company already had obligations — consent, transparency, the right to explanation. Under the EU AI Act, the same system is now potentially a high-risk AI application operating in the domain of access to private services, which means conformity assessments, technical documentation, post-market monitoring, and registration in the EU database before deployment. The GDPR obligation says: tell the applicant what you did. The AI Act obligation says: prove to a regulator, before you do anything, that what you built is fit to do it.
I have seen versions of this situation in Malta — not in the rental screening context specifically, but in the broader pattern of small and medium businesses adopting AI tools built by third parties without asking the question that actually matters: who is the provider under this Act, and am I the deployer, and do I know what that makes me legally responsible for. The Act distinguishes between providers — the ones who build and place AI systems on the market — and deployers — the ones who use those systems in a professional context. If you are a Maltese HR firm using an automated CV screening tool built by a vendor in Amsterdam, you are a deployer. That comes with obligations. Fundamental rights impact assessments for high-risk systems. Transparency to the people whose data flows through the model. Cooperation with supervisory authorities.
Years before I understood any of this formally, I understood something adjacent to it: systems built by people with more information than you are designed to produce outcomes that favour them. That lesson did not come from a law school lecture. It came from watching someone I cared about get denied something they were entitled to because the process was designed to be opaque. The law caught up with that reality eventually. The AI Act is that catching up, compressed into regulation.
The practical territory for Malta is specific. The Malta Digital Innovation Authority has been building the regulatory architecture since the Virtual Financial Assets framework era. The AI Act now requires member states to designate national competent authorities — Malta will be no exception. What that means for businesses operating here is that the enforcement layer is coming closer, not further. And the companies that will survive that proximity are the ones that have already done the internal audit: what automated systems are we using, what decisions do they influence, and have we mapped those systems against the risk categories in Annex III.
One move you can make tomorrow, for free.