The classic trap
Recital 63 sets out a principle many AI integrators forget: AI Act compliance NEVER exempts you from GDPR compliance, nor from national law on polygraphs, emotion recognition or behavioural analysis. Luxembourg's CNPD already sanctions AI deployments where the controller hid behind a 'we are AI Act compliant so we can process' logic. That is wrong: you need cumulatively a GDPR legal basis (Article 6), a condition lifting the prohibition for special categories (Article 9), and AI Act requirements met. The AI Act is not a legal ground for processing.
The dual compliance test: 4 questions to ask before any deployment
- GDPR legal basis: which Article 6 GDPR basis justifies the processing (consent, contract, legal obligation, legitimate interest after LIA)? The AI Act provides no basis on its own.
- Special category data (Article 9 GDPR): does the system process biometric, health, union, sexual orientation or opinion data? If so, which Article 9(2) exception is invoked?
- Emotion recognition: does the system detect emotional state? Beyond the AI Act prohibition in workplaces and education (Article 5), any other use remains subject to GDPR and the Charter. The CJEU applies strict proportionality review.
- National law: are there specific Luxembourg provisions (Labour Code on employee monitoring, sectoral professional secrecy under CSSF, medical secrecy) that prevail?
The hierarchy of norms to document in the DPIA
Concretely, your Fundamental Rights Impact Assessment (FRIA, AI Act Article 27) and your Article 35 GDPR DPIA must be joint and demonstrate each legal layer is respected: Charter of Fundamental Rights, GDPR, national law, then AI Act. If one fails, the deployment is unlawful, even if the other three are compliant.
How Luxgap automates this risk
Our Luxgap AI Legal Stack Validator makes it impossible to deploy an AI system that would be AI Act compliant but unlawful under GDPR or Luxembourg national law. The tool runs an automated multi-layer check: for each declared AI use case, it queries in parallel the GDPR legal bases documented in your Article 30 register, the Article 9 exceptions invoked, Luxembourg Labour Code constraints (employee monitoring, Article L.261-1), CSSF/CAA/ILR sectoral obligations, and applicable AI Act requirements.
- Automatically detects AI systems deployed across your IT estate (Azure OpenAI, AWS Bedrock, Google Vertex, self-hosted Hugging Face, M365 Copilot plugins) by correlating Azure AD, cloud billing and API logs.
- Classifies each use case against the AI Act grid (prohibited, high-risk, limited, minimal) AND the GDPR grid (legal basis, special category, automated decision Article 22).
- Sends real-time Teams alerts when a new prompt sends special category data to an LLM without a documented Article 9 GDPR basis.
- Generates a joint FRIA-DPIA pre-filled and demonstrating cumulative compliance with all four layers: Charter, GDPR, Luxembourg law, AI Act.
- Blocks or flags high emotional risk uses (assisted recruitment, employee evaluation, customer scoring) that require enhanced review.
- Produces a time-stamped PDF report, enforceable before the CNPD and the future Luxembourg AI authority, proving each AI deployment passed the dual compliance test.
Available as part of a Luxgap DPO or CISO mandate or as a dedicated SaaS brick depending on your AI perimeter. Request a tailored quote and our teams will prepare a demonstration on your real AI systems, with a free 48h scan to map your combined AI Act + GDPR exposure before any engagement.