Your cookie preferences

EDPB guidance · Art. 7 GDPR

We use technical cookies essential for the platform to work (login, security, sessions). We would also like to use analytics cookies to understand how to improve it.

You can accept all, reject all, or choose which categories to switch on.Your consent is valid for 6 months and you can withdraw it at any time from the footer.

You will find everything in our privacy notice.

All news
Regulation May 8, 2026 10 min

AI Act and DPO: how the DPO role changes with deployer obligations entering into force in August 2026

From August 2, 2026, obligations for deployers of high-risk AI systems (art. 26 AI Act) apply: what every operational DPO needs to know

UPDATE (July 2026): this calendar has changed

The Digital Omnibus package, adopted by Parliament on 16 June 2026 and by the Council on 29 June 2026, deferred the high-risk obligations: 2 December 2027 for Annex III (stand-alone systems) and 2 August 2028 for Annex I (AI embedded in regulated products). The Article 50 transparency duties remain confirmed for 2 August 2026. The text below is the version published before the amendment and is kept for documentary continuity.

Deadline August 2, 2026

From August 2, 2026, the obligations of articles 26 and 27 of the AI Act apply for deployers (users) of high-risk AI systems. If your client uses AI systems for recruiting, credit scoring, HR management, biometrics, student evaluation, or critical public services, you have less than 3 months to implement the compliance framework.

The 8 high-risk categories (Annex III)

  • Biometrics (identification, categorization, emotion recognition)
  • Critical infrastructure (traffic management, water/gas/electricity supply)
  • Education and training (admission, evaluation, monitoring)
  • Employment, worker management, access to self-employment
  • Access to essential private/public services
  • Law enforcement (crime risk, polygraphs, evidence reliability)
  • Migration, asylum, border control
  • Administration of justice and democratic processes

DPO's role: 5 concrete actions by July 2026

  • Inventory of AI systems used by your clients
  • Risk classification: assess if each system falls under Annex III
  • Map provider-deployer contracts
  • Update GDPR Art. 30 registers with AI references
  • Prepare FRIA template based on EDPB guidelines 02/2026

Practical tip

If you are DPO of a company with more than 100 employees, it's very likely that at least one AI system in HR (CV screening, performance management) falls under Annex III. Start there.

Official source:AI Act - EU Regulation 2024/1689

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Regulation
26the article nobody signs before broadcasting

Who answers for the live stream of the under-14 match? Sweden answers the question nobody asks

On 25 August the Swedish authority published guidance on streaming youth sport. Many clubs stream children's matches online, and the guidance sets out the factors that decide what is allowed. But the part worth reading is the other one: responsibility when the municipality owns the venue and the club wants to install cameras.

Aug 25, 2026New 5 min
Regulation
24months after which a past incident should not be used

The score they refuse your credit with can be requested, and it has to be explained

On 19 August the CNIL translated for the public its May 2026 recommendation on assessing creditworthiness. Inside are three numbers and one principle that concern anyone doing scoring: twenty-four months for past incidents, six months for the data of a refused application, and a right of access to the score that cannot be dismissed by invoking trade secrecy.

Aug 19, 2026New 6 min
Regulation
2EDPB criteria and the DPIA becomes mandatory

In schools, advertising trackers are prohibited — and consent has nothing to do with it

On 24 August the CNIL published its rules for the digital workspaces used in schools. The decisive point is not the protection of minors but a principle of administrative law: the neutrality of the public education service includes commercial neutrality, so trackers used for advertising or profiling are prohibited in principle. If the tool has them, the controller must switch them off.

Aug 24, 2026New 6 min