The classic trap
This final recital records that the AI Act was co-designed with the EDPS and the EDPB, the two European guardians of data protection. The concrete trap: believing that the AI Act replaces or overrides the GDPR. Wrong. Both texts apply cumulatively, and the CNPD remains fully competent for the personal data dimension of any AI system deployed in Luxembourg, in parallel with the future AI market surveillance authority and the EU AI Office in Brussels.
What this EDPB-EDPS joint opinion of 18 June 2021 means in practice
The joint opinion directly shaped several safeguards in the final text, which must be anticipated in any AI governance:
- Reinforced ban on social scoring and remote biometric identification (Article 5), driven by EDPB-EDPS pressure.
- Explicit articulation between AIA and GDPR: a GDPR DPIA does not exempt you from a Fundamental Rights Impact Assessment (FRIA) under Article 27 AIA for high-risk systems.
- Mandatory GDPR legal basis for training: the AI Act creates no new legal basis to process personal training data.
- Potential double notification on incidents: CNPD within 72h (Article 33 GDPR) AND AI market surveillance authority (Article 73 AIA) when the incident affects a high-risk system.
- Designation of a single internal contact point able to engage with both regulators without contradiction.
The 'AIA + GDPR cumulation' test: the key to your defense before CNPD and the future AI authority
A CNPD audit on a chatbot, an HR scoring tool or a fraud detection system will cover both Article 22 GDPR (automated decision) and Articles 14 and 26 AIA (human oversight, transparency). If your two registers (GDPR processing register and AIA system register) do not talk to each other, you will defend the same point twice with inconsistent answers.
How Luxgap automates this risk
Our Luxgap Dual-Compliance Bridge automatically reconciles your GDPR Article 30 register and your AI system register under Article 49 AIA into a single view, simultaneously opposable to the CNPD and the future Luxembourg AI authority. The tool ingests your Odoo processings, your M365 Copilot workflows, your models deployed on Azure ML, AWS Bedrock or Vertex AI, and automatically maps the overlaps between GDPR and AIA obligations, with no manual entry.
- Automatically detects every AI system active in your IT stack through Azure OpenAI, AWS Bedrock, Hugging Face, GitHub Copilot for Business and Odoo Studio ML flags APIs.
- Classifies each system along the AIA pyramid (prohibited, high-risk, limited risk, minimal risk) and cross-references with its GDPR qualification (Article 22 automated decision, profiling, sensitive processing).
- Auto-generates the Article 27 AIA FRIA by reusing elements from your existing GDPR DPIA, avoiding duplicate work while respecting the specific requirements of each text.
- Issues real-time alerts when an incident meets the dual notification criteria (CNPD 72h + AI authority), with pre-drafted templates for each regulator.
- Produces a single timestamped audit dossier, structured in two parts (CNPD / AI authority), demonstrating the consistency of your governance and the absence of contradiction between the two registers.
Available alongside a Luxgap DPO or CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real AI systems, with a free white audit within 48h to measure your dual GDPR + AIA exposure before any engagement.