Coordinating the GDPR and the AI Act – Overlaps, Conflicts and Gaps in High-Risk AI Systems
(2026) HARN63 20261Department of Business Law
- Abstract
- This thesis explores the regulatory friction that surfaces when the General Data Protection Regulation (GDPR) and the Artificial Intelligence Act (AI Act) apply side by side to high‑risk AI systems. It homes in on three connected problems. First, there is a procedural overlap between the Data Protection Impact Assessment (DPIA) and the Fundamental Rights Impact Assessment (FRIA). Second, a normative tension runs between the GDPR’s data minimisation principle and the AI Act’s demand for representative training data. Third, a regulatory gap surrounds AI‑generated inferred data, and this is made worse by fragmented enforcement between Data Protection Authorities (DPAs) and Market Surveillance Authorities (MSAs).
The thesis adopts a legal... (More) - This thesis explores the regulatory friction that surfaces when the General Data Protection Regulation (GDPR) and the Artificial Intelligence Act (AI Act) apply side by side to high‑risk AI systems. It homes in on three connected problems. First, there is a procedural overlap between the Data Protection Impact Assessment (DPIA) and the Fundamental Rights Impact Assessment (FRIA). Second, a normative tension runs between the GDPR’s data minimisation principle and the AI Act’s demand for representative training data. Third, a regulatory gap surrounds AI‑generated inferred data, and this is made worse by fragmented enforcement between Data Protection Authorities (DPAs) and Market Surveillance Authorities (MSAs).
The thesis adopts a legal dogmatic method, drawing on literal, systematic, and teleological interpretation. It analyses how the two frameworks interact, taking into account recent EU regulatory moves such as EDPB Opinion 28/2024 and the 2025 Digital Omnibus Proposal.
The findings show that running the DPIA and the FRIA in parallel leads to a good deal of duplication and makes coordination difficult. The study also flags ongoing legal uncertainty in several areas: the use of sensitive data for bias mitigation, how to strike a balance between representativeness and data minimisation, and the treatment of inferred data. To address these issues, the thesis suggests a more joined‑up approach to compliance that combines DPIA and FRIA processes, along with stronger cooperation between DPAs and MSAs to boost consistency and legal certainty. (Less)
Please use this url to cite or link to this publication:
https://lup.lub.lu.se/student-papers/record/9231018
- author
- Nie, Lei LU and Wang, Yue LU
- supervisor
-
- Johan Axhamn LU
- organization
- course
- HARN63 20261
- year
- 2026
- type
- H1 - Master's Degree (One Year)
- subject
- keywords
- Artificial Intelligence Act, General Data Protection Regulation (GDPR), high-risk AI systems, Fundamental Rights Impact Assessment (FRIA), Data Protection Impact Assessment (DPIA), inferred data
- language
- English
- id
- 9231018
- date added to LUP
- 2026-06-04 12:22:19
- date last changed
- 2026-06-04 12:22:19
@misc{9231018,
abstract = {{This thesis explores the regulatory friction that surfaces when the General Data Protection Regulation (GDPR) and the Artificial Intelligence Act (AI Act) apply side by side to high‑risk AI systems. It homes in on three connected problems. First, there is a procedural overlap between the Data Protection Impact Assessment (DPIA) and the Fundamental Rights Impact Assessment (FRIA). Second, a normative tension runs between the GDPR’s data minimisation principle and the AI Act’s demand for representative training data. Third, a regulatory gap surrounds AI‑generated inferred data, and this is made worse by fragmented enforcement between Data Protection Authorities (DPAs) and Market Surveillance Authorities (MSAs).
The thesis adopts a legal dogmatic method, drawing on literal, systematic, and teleological interpretation. It analyses how the two frameworks interact, taking into account recent EU regulatory moves such as EDPB Opinion 28/2024 and the 2025 Digital Omnibus Proposal.
The findings show that running the DPIA and the FRIA in parallel leads to a good deal of duplication and makes coordination difficult. The study also flags ongoing legal uncertainty in several areas: the use of sensitive data for bias mitigation, how to strike a balance between representativeness and data minimisation, and the treatment of inferred data. To address these issues, the thesis suggests a more joined‑up approach to compliance that combines DPIA and FRIA processes, along with stronger cooperation between DPAs and MSAs to boost consistency and legal certainty.}},
author = {{Nie, Lei and Wang, Yue}},
language = {{eng}},
note = {{Student Paper}},
title = {{Coordinating the GDPR and the AI Act – Overlaps, Conflicts and Gaps in High-Risk AI Systems}},
year = {{2026}},
}