The AI Act and the GDPR in Everyday Work Life (in German)

Understand where the AI Act and the GDPR intersect in practice, and what that means for how you use AI systems in your day-to-day work.

Bayerischer KI Innovationsbeschleuniger Module 2

Description

The GDPR is not superseded by the AI Act; both sets of regulations apply simultaneously. This affects almost everyone in their daily work life today: AI is no longer just a tool that you consciously open, but is embedded indirectly in email programs, CRM systems, HR software, and many office applications—often unnoticed. It is precisely this combination of complex regulatory frameworks and new AI tools that makes it difficult to navigate, especially without data protection expertise: What data am I allowed to enter, and who is liable in the event of an automated erroneous decision or a fabricated statement about a real person?

This training does not cover traditional data protection law but specifically demonstrates where the AI Act and the GDPR intersect in everyday professional life—from the data layers of an AI system (training, input, and output data) to scenarios such as shadow AI and automated individual decision-making under Article 22 of the GDPR. You will learn to independently assess such everyday situations and recognize when to involve your data protection department. The focus is on the use of AI systems when handling personal data from the operator’s perspective, not on the development or provision of AI systems.

Learn objectives

  • By examining the three data layers of an AI system (training, input, and output data), you can identify the points at which the GDPR applies in parallel with the AI Act.
  • You will recognize typical risk scenarios from your day-to-day work and, as a result, be able to manage your daily work with AI systems with greater confidence and competence.
  • You will be able to assess whether your organization has an adequate AI governance process in place regarding the GDPR and the AI Act for your specific role, and understand how to engage with or involve your data protection department to ensure your organization’s compliance.

Target audience

This training is designed for anyone who uses AI systems in their daily work and comes into contact with personal data, regardless of prior knowledge or field of expertise—from administrative staff to marketing and sales professionals to executives—and explicitly includes those without a background in compliance or law. Not intended for data protection officers; this is not traditional data protection training.

Prerequisites

A basic understanding of the EU AI Act (risk classes, roles along the value chain) is a plus, but not a requirement. Prior knowledge of the GDPR is not necessary, but personal experience in everyday use of AI systems related to the GDPR is helpful.

Trainer

Demian Niemeyer, Senior AI Regulatory Expert, appliedAI Institute for Europe.

Many thanks to the community partners of the Bavarian AI Innovation Accelerator for their support in communicating and promoting the project offerings: BIHK – Bavarian Association of Chambers of Industry and Commerce, vbw – Bavarian Industry Association, Bayern Innovativ GmbH, UnternehmerTUM GmbH, Munich Innovation Ecosystem GmbH, fortiss GmbH, German Mittelstand e.V., and BAIOSPHERE.

This training is offered as part of the Bavarian AI Innovation Accelerator. The project is funded by the Bavarian State Ministry for Digital Affairs. Details: https://innovationsbeschleuniger.bayern/