Insights
Updated September 2026

GDPR, FADP and the EU AI Act for Professional Services

How legal and professional-service teams can handle overlapping GDPR, Swiss FADP and EU AI Act duties when they use AI in sensitive or client work.

10 min read

General information, not legal advice. Legal position as of . Limitations in the Legal Notice

Review status: legal and language review by a named human reviewer is pending.

In this article

Substantive update

Regulation (EU) 2026/1744 of 8 July 2026 amended the AI Act and has been in force since 27 July 2026. The relevant Annex III high-risk duties apply from 2 December 2027; the corresponding Annex I product-related duties from 2 August 2028. Article 50 transparency duties generally apply from 2 August 2026. Article 111(4) allows providers of systems already placed on the market before that date until 2 December 2026 to meet Article 50(2).

New prohibitions in Article 5(1), points (ba) and (bb), apply from 2 December 2026. They cover AI systems that generate or manipulate realistic intimate images, videos or audio of an identifiable person without that person’s freely given, specific, informed, unambiguous and explicit consent, and AI systems that generate or manipulate child sexual abuse material. Article 5(1a) limits both prohibitions. Placing such a system on the market or putting it into service is prohibited only where that generation or manipulation is its intended purpose, or where it is a reasonably foreseeable and reproducible outcome without significant technical modification and the system lacks reasonable and adequate safeguards against it. Using such a system is prohibited only where the deployer uses it for that purpose. Under Article 5(1b), manipulation that neither increases the exposure of depicted intimate parts nor alters the nature of depicted sexually explicit activities is not manipulation within point (ba). Point (bb) does not apply where a “without right” defence applies under national law. Labelling content under Article 50 does not make a prohibited practice lawful.

Article 4 on AI literacy has applied since 2 February 2025. Until 26 July 2026 it required providers and deployers to take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and of others operating or using AI systems on their behalf. Since 27 July 2026 it requires them to take measures to support the development of that AI literacy; it does not require them to guarantee a specific level of AI literacy of any individual. Check the specific provision, role and transition, rather than using one deadline for the whole Act. Consolidated AI Act, Articles 4, 5, 111 and 113; Commission timeline.

GDPR and the AI Act answer different questions. GDPR regulates personal-data processing; the AI Act regulates specified AI practices, systems and operator roles. They can apply together in many sectors, not only legal services.

Separate decisions, connected evidence

Privacy and AI governance need separate scope and role decisions. Keep their evidence together.

Scroll horizontally to view all columns.

DecisionPrivacy reviewAI Act review
ScopePersonal-data processing and territorial scopeIntended purpose, territory and role
AssessmentDPIA where the conditions are metFRIA only for the specified deployers and uses
EvidenceLegal basis, safeguards and data-subject rightsApplicable duties, oversight and system documentation

The practical difficulty of human oversight is illustrated by Buçinca and colleagues’ 2021 experiment: interventions requiring deliberate thought reduced overreliance in the tested task, with usability trade-offs. This supports testing how review actually works. It does not determine whether a process satisfies GDPR Article 22 or a particular AI Act duty; those remain separate legal assessments.

Start with separate scope decisions

For GDPR, identify personal data, the purpose of processing, the controller and any processor. Check territorial scope under Article 3 and a lawful basis under Article 6. Special-category data requires an applicable Article 9 condition; data relating to criminal convictions and offences have a separate Article 10 regime. Financial information is not automatically an Article 9 special category.

For the AI Act, document intended purpose, territorial connection, operator role and classification. Routine private legal research is not automatically an Annex III administration-of-justice use. Being a deployer does not automatically transfer the provider’s documentation and conformity duties to your firm.

The July 2026 amendment added Article 4a, which sits exactly where the two regimes meet. Paragraph 1 allows providers of high-risk AI systems, exceptionally and only to the extent strictly necessary for bias detection and correction under Article 10(2), points (f) and (g), to process special categories of personal data, subject to listed safeguards such as pseudonymisation, access controls and deletion once the bias is corrected. Paragraph 2 gives providers and deployers of other AI systems and models, and deployers of high-risk AI systems, a comparable exceptional permission where strictly necessary to detect and correct biases likely to affect health and safety, harm fundamental rights or lead to discrimination prohibited under Union law, subject to all the conditions and safeguards of paragraph 1. It states that it creates no obligation to carry out bias detection and correction. Article 4a applies in addition to the GDPR, not instead of it: the processing must also meet the GDPR’s other requirements, and the records of processing must explain why special-category data were strictly necessary.

Add the Swiss layer

Swiss work also needs the Federal Act on Data Protection (FADP). It applies to situations that have an effect in Switzerland, even if they originate abroad (Article 3). Its sensitive personal data (Article 5 letter c) are data on religious, ideological, political or trade union views or activities; health, the intimate sphere or racial or ethnic origin; genetic data; biometric data that uniquely identify a person; administrative and criminal proceedings or sanctions; and social assistance measures. The controller must inform a person of a decision based exclusively on automated processing that has a legal effect on them or significantly affects them and, on request, let them state their point of view and have the decision reviewed by a natural person. These duties do not apply where the decision is directly connected with the conclusion or performance of a contract with the person and their request is granted, or where the person has explicitly consented to the automated decision (Article 21). A data protection impact assessment is required where processing may lead to a high risk to the person’s personality or fundamental rights; the FADP names extensive processing of sensitive personal data as one such case (Article 22). Check the GDPR’s territorial scope separately: an answer under one law does not settle the other.

Swiss regulatory status, checked 26 September 2026

On 12 February 2025 the Federal Council spoke out in favour of ratifying the Council of Europe’s AI Convention, which mainly concerns state actors, and instructed the FDJP to prepare a consultation draft by the end of 2026. General cross-sector rules are to be limited to central areas relevant to fundamental rights, such as data protection (Federal Council press release). Switzerland signed the Convention in March 2025. The Federal Office of Justice page (in German), read on 26 September 2026, still gives the end of 2026 as the deadline for the consultation draft. Independently of that process, the FDPIC confirms that the FADP in force applies directly to AI-supported data processing.

Reuse evidence without merging the tests

An inventory can record both processing purposes and AI use cases. A vendor review can cover processor terms, training reuse, security, source coverage and human oversight. For example, one supplier record can hold the processor terms required by GDPR Article 28 and the conditions for assigning processing under FADP Article 9 (including that no duty of confidentiality prohibits the assignment), the basis for any disclosure abroad (FADP Article 16), and the supplier’s AI Act role, while each conclusion keeps its own legal reference. A DPIA under GDPR Article 35 addresses likely high risks to people from processing. An AI Act fundamental-rights impact assessment under Article 27 applies only to specified deployers and uses. Where both are required, coordinate them while preserving their distinct questions.

Keep human review meaningful

Document who may rely on outputs, what they must check and how they can stop use. A nominal approval click is not proof of meaningful human involvement. GDPR Article 22 concerns decisions based solely on automated processing with legal or similarly significant effects, subject to its exceptions and safeguards. It is not a ban on every AI-supported recommendation.

The Court of Justice reads that scope with the actual decision in mind. In Case C-634/21 (7 December 2023) it held that a credit agency’s automated probability score is itself an automated individual decision where a third party to which it is sent draws strongly on it to establish, implement or terminate a contract with the person. An automated output can therefore count as the decision even when a person formally decides. In Case C-203/22 (27 February 2025) it held that, where automated decision-making within the meaning of Article 22(1) takes place, the right of access under Article 15(1)(h) lets the data subject require the controller to explain the procedure and principles actually applied to obtain a specific result, such as a credit profile.

Assign current duties and preparation tasks

Data protection obligations do not wait for the AI Act’s high-risk dates. Review data minimisation, notices, access restrictions, retention, security and relevant international-transfer requirements now. Separately plan the high-risk duties that apply to the actual role and use. Keep Article 50 transparency and existing-system transitions visible in the record.

Review and incident management

Name the owner of the inventory, contract review and escalation process. Reassess when the model, purpose, data or supplier changes. Use the data-processing guide for the distinct breach-notification thresholds and clocks. Training exercises and internal response targets support compliance but do not replace statutory tests.

Pending, not law (checked 26 September 2026): the Commission’s Digital Omnibus proposal, COM(2025) 837 of 19 November 2025, would require notification to the supervisory authority only for breaches likely to result in a high risk, where feasible within 96 hours and through a single entry point, and would have the European Data Protection Board propose EU-wide lists of processing that does or does not need a DPIA. It remains a proposal; the current GDPR rules apply until an amending act is adopted and in force.

A combined evidence record

0/6

Key Takeaway

A shared evidence file can support both regimes. Each legal conclusion still needs its own scope, role and provision.

Primary sources

Clarify how AI decisions are made

Connect business, HR, IT and risk through clear ownership and review routines.

You might also like

Need clearer footing for an AI decision?

Start with a focused conversation about a live AI use case, workflow bottleneck, training need, or governance gap.