Skip to main content

LUP Student Papers

LUND UNIVERSITY LIBRARIES

Coordinating the GDPR and the AI Act – Overlaps, Conflicts and Gaps in High-Risk AI Systems

Nie, Lei LU and Wang, Yue LU (2026) HARN63 20261
Department of Business Law
Abstract
This thesis explores the regulatory friction that surfaces when the General Data Protection Regulation (GDPR) and the Artificial Intelligence Act (AI Act) apply side by side to high‑risk AI systems. It homes in on three connected problems. First, there is a procedural overlap between the Data Protection Impact Assessment (DPIA) and the Fundamental Rights Impact Assessment (FRIA). Second, a normative tension runs between the GDPR’s data minimisation principle and the AI Act’s demand for representative training data. Third, a regulatory gap surrounds AI‑generated inferred data, and this is made worse by fragmented enforcement between Data Protection Authorities (DPAs) and Market Surveillance Authorities (MSAs).
The thesis adopts a legal... (More)
This thesis explores the regulatory friction that surfaces when the General Data Protection Regulation (GDPR) and the Artificial Intelligence Act (AI Act) apply side by side to high‑risk AI systems. It homes in on three connected problems. First, there is a procedural overlap between the Data Protection Impact Assessment (DPIA) and the Fundamental Rights Impact Assessment (FRIA). Second, a normative tension runs between the GDPR’s data minimisation principle and the AI Act’s demand for representative training data. Third, a regulatory gap surrounds AI‑generated inferred data, and this is made worse by fragmented enforcement between Data Protection Authorities (DPAs) and Market Surveillance Authorities (MSAs).
The thesis adopts a legal dogmatic method, drawing on literal, systematic, and teleological interpretation. It analyses how the two frameworks interact, taking into account recent EU regulatory moves such as EDPB Opinion 28/2024 and the 2025 Digital Omnibus Proposal.
The findings show that running the DPIA and the FRIA in parallel leads to a good deal of duplication and makes coordination difficult. The study also flags ongoing legal uncertainty in several areas: the use of sensitive data for bias mitigation, how to strike a balance between representativeness and data minimisation, and the treatment of inferred data. To address these issues, the thesis suggests a more joined‑up approach to compliance that combines DPIA and FRIA processes, along with stronger cooperation between DPAs and MSAs to boost consistency and legal certainty. (Less)
Please use this url to cite or link to this publication:
author
Nie, Lei LU and Wang, Yue LU
supervisor
organization
course
HARN63 20261
year
type
H1 - Master's Degree (One Year)
subject
keywords
Artificial Intelligence Act, General Data Protection Regulation (GDPR), high-risk AI systems, Fundamental Rights Impact Assessment (FRIA), Data Protection Impact Assessment (DPIA), inferred data
language
English
id
9231018
date added to LUP
2026-06-04 12:22:19
date last changed
2026-06-04 12:22:19
@misc{9231018,
  abstract     = {{This thesis explores the regulatory friction that surfaces when the General Data Protection Regulation (GDPR) and the Artificial Intelligence Act (AI Act) apply side by side to high‑risk AI systems. It homes in on three connected problems. First, there is a procedural overlap between the Data Protection Impact Assessment (DPIA) and the Fundamental Rights Impact Assessment (FRIA). Second, a normative tension runs between the GDPR’s data minimisation principle and the AI Act’s demand for representative training data. Third, a regulatory gap surrounds AI‑generated inferred data, and this is made worse by fragmented enforcement between Data Protection Authorities (DPAs) and Market Surveillance Authorities (MSAs).
The thesis adopts a legal dogmatic method, drawing on literal, systematic, and teleological interpretation. It analyses how the two frameworks interact, taking into account recent EU regulatory moves such as EDPB Opinion 28/2024 and the 2025 Digital Omnibus Proposal.
The findings show that running the DPIA and the FRIA in parallel leads to a good deal of duplication and makes coordination difficult. The study also flags ongoing legal uncertainty in several areas: the use of sensitive data for bias mitigation, how to strike a balance between representativeness and data minimisation, and the treatment of inferred data. To address these issues, the thesis suggests a more joined‑up approach to compliance that combines DPIA and FRIA processes, along with stronger cooperation between DPAs and MSAs to boost consistency and legal certainty.}},
  author       = {{Nie, Lei and Wang, Yue}},
  language     = {{eng}},
  note         = {{Student Paper}},
  title        = {{Coordinating the GDPR and the AI Act – Overlaps, Conflicts and Gaps in High-Risk AI Systems}},
  year         = {{2026}},
}