EU frameworkGDPRNIS 2DORAAI ActWhistleblowing
Recital 10

Recital 10

Artificial Intelligence Act · UE 2024/1689

(10)

The fundamental right to the protection of personal data is safeguarded in particular by Regulations (EU) 2016/679 (11) and (EU) 2018/1725 (12) of the European Parliament and of the Council and Directive (EU) 2016/680 of the European Parliament and of the Council (13). Directive 2002/58/EC of the European Parliament and of the Council (14) additionally protects private life and the confidentiality of communications, including by way of providing conditions for any storing of personal and non-personal data in, and access from, terminal equipment. Those Union legal acts provide the basis for sustainable and responsible data processing, including where data sets include a mix of personal and non-personal data. This Regulation does not seek to affect the application of existing Union law governing the processing of personal data, including the tasks and powers of the independent supervisory authorities competent to monitor compliance with those instruments. It also does not affect the obligations of providers and deployers of AI systems in their role as data controllers or processors stemming from Union or national law on the protection of personal data in so far as the design, the development or the use of AI systems involves the processing of personal data. It is also appropriate to clarify that data subjects continue to enjoy all the rights and guarantees awarded to them by such Union law, including the rights related to solely automated individual decision-making, including profiling. Harmonised rules for the placing on the market, the putting into service and the use of AI systems established under this Regulation should facilitate the effective implementation and enable the exercise of the data subjects’ rights and other remedies guaranteed under Union law on the protection of personal data and of other fundamental rights.

Luxembourg specificity
projet de loi luxembourgeoise de mise en oeuvre du reglement (UE) 2024/1689 (a venir) et position CNPD 2023 sur l'IA generative

In Luxembourg, the AI supervisory authority has not yet been formally designated at the time of writing. The CNPD remains competent for the GDPR aspects applicable to any AI system processing personal data, and published a 2023 position on generative AI reaffirming the full application of the GDPR. The forthcoming Luxembourg law implementing the AI Act will clarify the division of competence between the designated AI authority and the CNPD, following the cooperation model already in place with the ILR for NIS 2.

Luxgap practice: we systematically document the dual legal basis (AI Act + GDPR) in your records and prepare for a joint CNPD-AI authority audit scenario, particularly for financial actors where the CSSF adds a third dimension via its AI circular.