In This Issue


The Intersection of the EU AI Act and the GDPR—Compliance Through Existing Data Governance

Because providers of AI systems train models using vast amounts of data—including personal data in many instances—providers must consider how data protection laws may apply to their processing activities. Likewise, deployers of AI systems must do the same when they fine-tune models with personal data for various highly regulated use cases. Personal data is already subject to comprehensive data privacy and data protection laws and entities that process personal data often do so through comprehensive corporate data governance and compliance programs. Regulators seeking to establish controls over developing and deploying AI technology enter a space that is already crowded.

The drafters of the European Union Artificial Intelligence Act (EU AI Act)[1] approached this challenge by incorporating the General Data Protection Regulation (GDPR) and its principles, concepts, and processes regarding personal data into the EU AI Act, deferring to the GDPR whenever there is a conflict between the two laws. In other words, when considering how the EU AI Act applies to AI technologies that process personal data, practitioners must first consider how the GDPR applies to the processing activity and ensure that the GDPR controls in the event of a conflict. 

Three Takeaways for AI Act Compliance

For this reason, entities seeking to comply with the EU AI Act should incorporate AI-related compliance policies and procedures into their existing data governance and compliance programs, which already include processes for complying with the GDPR and other laws regulating personal data processing. Entities that fail to do so run the risk of reaching inconsistent conclusions regarding, for instance, the risks of automated processing and the types of mitigation that should be adopted to address those risks. Addressing AI governance through existing data privacy compliance programs is also efficient: Those responsible for compliance with laws governing personal data processing should consider the full range of laws that apply, whether such laws are characterized as data privacy laws or AI laws.

To illustrate this point, we explore below the relationship between the EU AI Act and the GDPR and explain why there is no realistic way to analyze the EU AI Act's regulation of AI services that process personal data without first analyzing and understanding the GDPR. 

The EU AI Act Defers to the GDPR for AI systems That Process Personal Data

The EU AI Act regulates a technology that processes personal data, while the GDPR regulates the processing of personal data.

To prevent inconsistencies in this shared space, the EU AI Act incorporates and references core GDPR concepts. For example:

  • The EU AI Act requires processing of personal data by AI to be performed according to principles in the GDPR: "The right to privacy and to protection of personal data must be guaranteed throughout the entire lifecycle of the AI system. In this regard, the principles of data minimisation and data protection by design and by default, as set out in [the GDPR among other data protection laws], are applicable when personal data are processed." [2]
  • The EU AI Act also requires evaluation of biometric data in accordance with the GDPR: "The notion of 'biometric data' used in this Regulation should be interpreted in light of the notion of biometric data as defined in Article 4, point (14)" of the GDPR.[3]
  • AI systems used for biometric categorization according to sensitive attributes or characteristics protected under Article 9(1) of the GDPR are "high-risk" and subject to additional regulation.[4]
  • All AI systems listed in Annex III that involve "profiling" as defined by the GDPR are high risk because they are ineligible for the exception for AI systems that do not pose a significant risk of harm.[5]

There are many other examples, as the EU AI Act references the GDPR 30 times. 

The EU AI Act Incorporates Critical Definitions from the GDPR

In addition, other key terms used throughout the EU AI Act are defined in the GDPR:

  • "Personal Data." The EU AI Act and its recitals refer to personal data 80 times. Rather than defining the term in the EU AI Act, the drafters incorporated the GDPR's definition and further added that "non-personal data" is anything that is not personal data under the GDPR.[6]
  • "Special Categories of Personal Data." The EU AI Act adopts the definition of "special categories of personal data" in Article 9(1) of the GDPR, and AI systems processing such data are subject to additional regulations.[7]
  • "Profiling." As noted above, the EU AI Act incorporates the GDPR definition of profiling,[8] which is a critical term because any system that performs profiling for specific sensitive use cases may not rely on risk-reduction exemptions and is automatically classified as a high-risk AI system.

The EU AI Act's Prohibited and High-Risk Activities Primarily Involve the Processing of Personal Data Subject to the GDPR

Almost all of the prohibited AI practices in EU AI Act Article 5 involve processing personal data that is subject to the GDPR, including:

  • Social scoring, risk assessments of persons, scraping of facial images, emotion inference in the workplace and at educational institutions, and certain biometric categorization and identification systems.

The same is true for almost all the AI Systems categorized as high risk in Annex III:

  • Biometrics that are not identified as prohibited, educational and vocational training, access and learning outcomes, employment, worker's management and access to self- employment and recruitment for jobs, access to essential public and private services, certain law enforcement uses, migration/asylum/border control, and administration of justice.

EU AI Act Fundamental Rights Impact Assessments (FRIA) and GDPR Data Protection Impact Assessments (DPIA) Are linked

The drafters of the EU AI Act understood that a FRIA required for certain AI systems would overlap in many cases with the GDPR's required DPIA for personal data processing. For this reason, the EU AI Act directs entities to combine the processes: "[i]f any of the obligations laid down in this Article is already met through the data protection impact assessment conducted pursuant to Article 35 of [the GDPR], the fundamental rights impact assessment … shall complement that data protection impact assessment."[9]

Additionally, deployers of high-risk AI Systems must use the information they receive under the transparency provisions of EU AI Act Article 13 "to comply with their obligation to carry out a data protection impact assessment under Article 35" of the GDPR.[10]

Analyzing the EU AI Act and the GDPR Separately Risks Noncompliance With Both Laws

Entities that bifurcate EU AI Act and GDPR compliance may reach inconsistent conclusions with respect to the same processing activities. For example, the GDPR regulates certain decisions based on the processing of personal data by AI systems—i.e., automated processing, including profiling. The GDPR at a minimum requires disclosure of "meaningful information about the logic involved" in such automated processing and the significance and consequences for the data subject.[11]

But the GDPR may prohibit processing entirely if there is no lawful basis, such as when the processing is an undisclosed secondary use omitted from the privacy policy, there is inadequate data subject consent, or the entity cannot show it has a legitimate interest in that processing. And in some cases, the data subject may object to the processing under the GDPR. In these situations, the processing may not proceed.[12]

In contrast, the profiling could be permitted under the EU AI Act, albeit subject to controls applicable to high-risk AI systems, such as the requirement to establish and maintain a risk management system and observe certain data governance standards on training, validation, and testing.[13]

An entity that analyzes the same processing activity under the EU AI Act—without regard to the GDPR—could process the data subject's personal data in violation of the GDPR or fail to give the data subject the rights to which they are entitled, creating the risk of enforcement by data protection authorities.

Action Items

These are just a few examples of the ways in which the EU AI Act and GDPR are intertwined. Practitioners should incorporate their EU AI Act compliance program into their existing GDPR-compliant data governance and strategy processes. Entities that do not consider how both laws work together create the unnecessary risk of regulatory scrutiny and enforcement.

Contact: David Rice



[1] Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024, laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828.

[2] EU AI Act Recital (69).

[3] EU AI Act Recital (14).

[4] EU AI Act Recital (54).

[5] EU AI Act Article 6(3) and Annex III. "Notwithstanding the first subparagraph, an AI system referred to in Annex III shall always be considered to be high risk where the AI system performs profiling of natural persons." Profiling is defined in GDPR Article 4(4).

[6] "'[P]ersonal data' means personal data as defined in Article 4, point (1), of Regulation (EU) 2016/679." EU AI Act Article 3 (50). "'[N]on-personal data' means data other than personal data as defined in Article 4, point (1), of Regulation (EU) 2016/679." EU AI Act Article 3 (51).

[7] EU AI Act Article 3(37).

[8] "'[P]rofiling' means profiling as defined in Article 4, point (4), of Regulation (EU) 2016/679." EU AI Act Article 3 (52). GDPR Article 4(4) defines profiling to mean "any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements."

[9] EU AI Act Article 27(4).

[10] EU AI Act Article 26(9).

[11] GDPR Article 13(2)(f); Article 14 (2)(g); Article 15(1)(h); Article 22.

[12] GDPR Article 22 ("The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her," with limited exceptions including explicit consent.)

[13] See EU AI Act Articles 8 to 15.

Back to top


CalPrivacy Continues Enforcement Against Data Brokers

CalPrivacy ramped up enforcement against data brokers last month, settling complaints against LocateSmarter, Cybba, and SalesIntel Research, Inc. (SalesIntel).

The settlement agreement with LocateSmarter was CalPrivacy's first combined enforcement action against a data broker under both the Delete Act and the CCPA. In that matter, CalPrivacy found that LocateSmarter was a "data broker" under the Delete Act and a "business" under the CCPA. It alleged that LocateSmarter had failed to register as a data broker and violated the CCPA data minimization requirements by requesting unnecessary additional information (last four digits of Social Security numbers) from consumers who requested to opt out of the sale or sharing of their personal information. CalPrivacy noted that only a handful of consumers had made requess to opt out and surmised that this was likely due to the business making it harder to exercise this right.

Cybba and SalesIntel are required to pay fines of $52,400 and $36,400, respectively, for failing to register, while LocateSmarter is required to pay fines totaling $116,490 ($30,600 for failing to register, $6,000 for the unpaid registration feel, and $79,890 for violating the CCPA) and must also modify its methods for submitting and responding to opt-out requests as follows:

  • Provide opt-out methods that are easy to use, require minimal steps, and do not require more information than necessary to complete the request;
  • Not require verifiable consumer requests to opt-out of sale of their personal information;
  • Not require consumers to provide any portion of their Social Security numbers to make a request; and
  • Honor a request to opt-out of sale within the time period required by the CCPA to the extent that it is able to do so when a consumer makes such a request.

CalPrivacy reminded businesses that the CCPA prohibits businesses from collecting more personal information than is "reasonably necessary and proportionate" to achieve the purpose of collection and they are prohibited from requiring consumers to verify their identities to opt out of the sale of their personal information. At most, a business may ask a consumer to provide information necessary for the business to effectuate the consumer's request to opt out, but to the extent that a business can comply with a request without additional information, it must do so. In particular, CalPrivacy noted that by requiring consumers to submit the last four digits of their Social Security numbers, LocateSmarter violated the data minimization requirements and could have intimidated consumers from exercising their privacy rights, in violation of the requirement to make it easy for consumers to exercise their rights.

Contact: Nancy Libin

Back to top


White House Opens the Door to Government-Supervised Private-Sector Offensive Cyber Operations

President Trump signed a National Security Presidential Memorandum (the NSPM), "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime," directing the creation of a program (the Program) under which vetted U.S. companies (Participating Companies) may engage in offensive cyber operations against "Cyber-Enabled Transnational Criminal Organizations" (CE-TCOs). The August 12, 2026, NSPM expressly builds on a March 2026 executive order, "Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens," directing the federal government to combat cybercrime against Americans. The NSPM also is a significant step by the Trump Administration to "unleash the private sector" to disrupt cyber criminals, as called for in the administration's National Cyber Strategy. We discussed the National Cyber Strategy and the May 2026 executive order, which were published the same day, in a prior blog post. The Program is to be run by the National Coordination Center, a function within the Department of Homeland Security created by a January 2025 executive order, "Protecting the American People Against Invasion."

The NSPM authorizes Participating Companies to engage in two types of operations: "Cyber Surveillance Operations," defined as clandestine collection that involves accessing systems without authorization or in excess of authorization, and "Cyber Effects Operations," meaning the manipulation, disruption, denial, degradation, or destruction of systems, infrastructure, or data. The Program's two Program Executive Directors, one designated by the Attorney General and one designated by the Secretary of Homeland Security, must approve all operations through coordination with each other and must establish "complete oversight and control of Participating Companies' performance." Targets are limited to CE-TCOs, defined as foreign groups conducting cyber-enabled crime against the U.S. government, U.S. persons, or U.S. interests that are not institutionally part of, or wholly directed by, a foreign government.  Approved operations may not include those resulting in "Critical Outcomes," i.e., those likely to cause loss of life or serious injury, or to rise to the level of use of force or armed attack under international law. All operations must be conducted expressly in accordance with the Constitution, international obligations, and federal law, including the Computer Fraud and Abuse Act (CFAA).

By October 11, 2026, the Program Executive Directors must establish operating procedures for key aspects of the Program, including minimum technical and security standards for Participating Companies. This includes requirements for Participating Companies to enter into contracts with the Department of Justice or Department of Homeland Security, to post a bond or escrow of at least $1 million (to be forfeited in the event of noncompliance with Program rules), and to report noncompliance, cyberattacks, and other events to the government. 

Companies should note that the NSPM is not a general license to "hack back" against cyber attackers. The NSPM only authorizes activity by approved Participating Companies and only with written federal approval and direction. All operations must comply with federal law.  Importantly, the extent to which Participating Companies may be shielded from liability for participating in approved operations (for example, if an operation were to cause collateral damage to an innocent party) remains unclear.   

Contact: Michael T. Borgia and Andrew Lewis

Back to top


New Cybersecurity Reporting Requirements Set to Become Effective for Critical Infrastructure, Federal Contractors

Critical Infrastructure

More than four years after the law's enactment, reporting requirements under the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) may finally be about to go into effect. According to an entry in the Office of Management and Budget's (OMB) unified regulatory agenda, the Cybersecurity and Infrastructure Security Agency (CISA) is set to issue its implementing rules this month. The rules would become effective no less than 60 days after publication.

Under CIRCIA, covered entities must report certain substantial cyber incidents to CISA within 72 hours after reasonably believing that such an incident occurred, and must report ransomware payments within 24 hours of making the payment. CIRCIA directed CISA to develop implementing regulations, and CISA published its proposed regulations in April 2024. The regulations then faced a series of delays, including those due to responding to significant industry and lawmaker criticism on multiple grounds, particularly the breadth of entities subject to the regulations. Under CISA's own estimates, the proposed regulations would apply to more than 316,000 entities, over 310,000 of which would be small businesses. CISA recently held a series of town halls to solicit further industry feedback. Critical infrastructure should review the new regulations carefully once they are published, as they may be significantly scaled back in some respects as compared to the 2024 proposed rules.

Federal Contractors

The OMB's unified regulatory agenda also indicates that the federal government may be close to amending the Federal Acquisition Regulation (FAR) to introduce new incident reporting and cybersecurity requirements for federal contractors. In October 2023, the Department of Defense (DoD), General Services Administration (GSA), and National Aeronautics and Space Administration (NASA) proposed two sets of FAR amendments: FAR Case 2021-017, titled "Cyber Threat and Incident Reporting and Information Sharing," proposed to require contractors to report security incidents affecting products or services provided to CISA within eight hours. FAR Case 2021-019, titled "Standardizing Cybersecurity Requirements for Unclassified Federal Information Systems," proposed various minimum security requirements for cloud and non-cloud systems. Cloud systems would be required to comply with applicable security baselines under the Federal Authorization and Risk Management Program (FedRAMP). Non-cloud systems would be required to comply with certain NIST privacy and security standards, and systems determined to be "moderate" or "high" impact would have to undergo third-party security assessments. For "high" impact systems—both cloud and non-cloud—contractors would be required to maintain all government data in the United States. Both proposed FAR rules implement provisions of Executive Order 14028, issued by President Biden in 2021. Entries in the OMB unified regulatory agenda for both 2021-017 and 2021-019 indicate that final rules may be issued this month. These rules are separate from recently proposed requirements, including incident notification requirements, for controlled unclassified information (CUI) proposed as part of the Trump Administration's "Revolutionary FAR Overhaul."

Contact: Michael T. Borgia, Andrew Lewis, and Alix Town

Back to top


California Legislature Unanimously Passes SB 690, Narrowing CIPA Website-Tracking Suits

For website operators, some relief may finally be on the way. On August 28, 2026, the California legislature enacted a bill to substantially limit private suits under the California Invasion of Privacy Act (CIPA). SB 690 passed by unanimous vote in both chambers. The law does not totally eliminate private suits under CIPA, however, and companies should take note of SB 690's significant limitations.

CIPA is a criminal wiretapping statute enacted in 1967. On of CIPA's provisions, § 638.51 of the California Penal Code, prohibits installation of a "pen register" or "trap and trace device" without a court order or consent of the user to capture "dialing, routing, addressing, or signaling information" or certain other information "reasonably likely to identify the source of a wire or electronic communication."

Over the past several years, plaintiffs' attorneys began sending bevies of demand letters to website operators asserting that website cookies, pixels, analytics tags, and chat widgets that transmit IP addresses, device identifiers, and routing data are pen registers, trap and trace devices, or both. Under CIPA, plaintiffs do not need to allege that any communication's contents were intercepted or that a reasonable expectation of privacy was infringed. Under Penal Code § 637.2, a plaintiff injured by a CIPA violation may recover the greater of $5,000 per violation or three times actual damages, without proving actual harm. Different courts have reached conflicting conclusions about whether § 638.51 applies to common online advertising and website analytic tools.

While not a complete fix to complaints about § 638.51, SB 690 provides that only the California Attorney General, not private plaintiffs, may bring an action against a private actor for a § 638.51 violation arising from conduct on a website, online application, or mobile application. The amendment expressly applies retroactively to any pending claim in an action commenced within two years before its operative date. Governor Newsom has until September 30, 2026, to sign or veto the bill. The bill will become law if the governor takes no action by that date. Assuming Governor Newsom does not veto the bill, SB 690 would become effective on January 1, 2027, thereby barring actions commenced on or after January 1, 2025. Plaintiffs' attorneys are expected to challenge the bill's retroactivity provision.

Several limitations of SB 690 are important to note. First, the bill merely prohibits certain private suits alleging violations of § 638.51. It does not amend § 638.51 to exempt website and other online trackers from CIPA. The California Attorney General remains free to bring suits alleging that those technologies are unlawful pen registers or trap and trace devices under § 638.51 (although the Attorney General has never brought such a suit). Second, SB 690 does not limit private suits alleging violations of two other key CIPA provisions, Penal Code § 631 and § 632. Section 631 prohibits "wiretapping," defined as reading or attempting to read the contents of a communication in transit without the consent of all parties. Section 632 prohibits eavesdropping on or recording a confidential communication without the consent of all parties to the confidential communication[1] (Plaintiffs frequently have alleged violations of § 631 and § 632 along with violations § 638.51 and may continue to use § 631 and § 632 as a basis for claims related to website tracking. These claims likely will be more difficult to make, as both sections require an interception (or attempted interception) of the contents of communications.) Section 638.51 previously allowed plaintiffs to avoid having to allege that website tracking technologies intercept communications' contents.

Pending appellate decisions by the California Court of Appeal on whether § 638.51 reaches internet tracking technologies at all, and by the Ninth Circuit on whether plaintiffs have Article III standing for § 638.51 claims, also may significantly reshape and landscape irrespective of SB 690.

Contact: Michael T. BorgiaNancy Libin, Sean M. Sullivan, and James H. Moon



[1] The prerecorded statement at the beginning of many inbound and outbound voice calls with customer service centers that a call may be recorded—for any purpose, although quality assurance or training are common examples—generally dashes any expectation of confidentiality in the communication so participating in the call after such notice usually suffices to permit recording even in an all-party consent state like California.

Back to top