Questionnaire answers · Privacy and data · Article 2(7)

How to answer GDPR and privacy questions about AI in a supplier questionnaire

The short answer

Say which AI features process personal data, where each one stands in your record of processing activities, and whether a data protection impact assessment covers it. The GDPR keeps applying beside the AI Act (Article 2(7) of the AI Act, as replaced by Regulation (EU) 2026/1744), and its Article 30 record and Article 35 assessment are what a buyer asks to see. Complipath (complipath.io) keeps the record these answers rest on.

What they usually ask

  1. Q1“Does the AI feature process personal data?”
  2. Q2“Is the processing in your record of processing activities?”
  3. Q3“Have you carried out a data protection impact assessment for the AI feature?”
  4. Q4“Who is the controller and who is the processor for the AI feature?”

An example answer, part by part

An illustration for an invented product, not a real supplier's answer, to the question: Have you carried out a data protection impact assessment for the AI feature?

Direct answerYes, partly or no first
Yes, for the reply-drafting feature, completed on 12 August 2026.
ControlWhat you actually do
The assessment is reviewed when the feature's data sources or its purpose change.
ScopeWhich AI systems
Reply drafting. The spam filter is covered by the existing assessment for the mail service.
EvidenceWhat you can show
The assessment's summary page and the line in the record of processing activities that points to it.
ExceptionsBe honest
None. The feature launched after the assessment was signed.

Example. Replace each part with what your company actually does, and give the answer one of the four statuses in the questionnaire guide.

What counts as proof

  • The entry for the AI feature in your record of processing activities (GDPR Article 30).
  • The data protection impact assessment, or the reasons one was not required (GDPR Article 35).
  • Where Article 27(1) of the AI Act requires one, the fundamental rights impact assessment; under Article 27(4), as replaced by Regulation (EU) 2026/1744, it may cross-refer to the relevant sections of the data protection impact assessment or include parts of it.

Common mistakes

  • Answering for the company. Article 6 classifies systems, not companies.
  • "Yes" with no evidence. If you cannot attach it, the status is Partially implemented or Planned.
  • A policy title as the control. It says nothing about what happens to an output.
  • Mixing up the roles. Article 50(1) is a provider duty; Article 26 is the deployer's. Which one you are is set per system: see provider or deployer.
  • Not applicable with no reason. The reason is the classification.
  • Dropping the exception. The summary that leaves out "unless" is the one that is wrong.

What the law says

Article 2(7) of the AI Act, as replaced by Regulation (EU) 2026/1744: Union law on the protection of personal data applies to personal data processed in connection with the AI Act's rights and obligations, and, without prejudice to Articles 4a and 59, the AI Act does not affect the GDPR, Regulation (EU) 2018/1725 or Directives 2002/58/EC and (EU) 2016/680.

  • GDPR Article 30: each controller keeps a record of processing activities with the information Article 30(1) lists, among it the purposes, the categories of data subjects and of personal data, the recipients and, where possible, the time limits for erasure; a processor keeps its own record under Article 30(2).
  • The record is in writing, including in electronic form.
  • It is made available to the supervisory authority on request.
  • Under Article 30(5) the duty does not apply to an organisation employing fewer than 250 persons unless the processing is likely to result in a risk to the rights and freedoms of data subjects, is not occasional or includes special categories of data or data on criminal convictions and offences.
  • GDPR Article 35: where processing, in particular using new technologies, is likely to result in a high risk to the rights and freedoms of natural persons, the controller assesses its impact before the processing.
  • Article 35(3) requires the assessment in particular for a systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions with legal or similarly significant effects are based; for large-scale processing of special categories of data or of data on criminal convictions and offences; and for systematic monitoring of a publicly accessible area on a large scale.
  • Article 35(7) sets what it contains at least, and Article 35(10) excepts certain processing whose legal basis in Union or Member State law already came with a general impact assessment, unless the Member State deems one necessary.

Read from the Official Journal text of the GDPR (OJ L 119, 4.5.2016) on 9 October 2026; the GDPR is not in the pinned corpus behind the rest of this site.

What Complipath does

  • AI inventory Every AI system you build or use, with its owner and risk class
  • Risk classification Answers go through rules in code, never a language model, so the same answers always give the same result. Rules decide. AI only drafts. A person confirms.
  • Evidence management A file linked to the requirements it proves, with the passage and its page
  • Audit log Who did what, and when. No one can edit or delete a line, an owner included; only deleting the whole workspace removes it

Rules decide. AI only drafts. A person confirms.

What it does not do yet

  • Fundamental rights impact assessment (Article 27) Not supported The step-by-step plan lists Article 27 as a step only for systems classified under points 5(b) and 5(c) of Annex III. Article 27(1) also binds deployers that are bodies governed by public law or private entities providing public services, and the product does not ask whether you are one. Nothing carries the assessment itself.
  • Customer questionnaires (audit room) Coming soon Coming soon: answering a customer's AI questionnaire from your own register.

Questions

Does the AI Act replace the GDPR for AI features?

No. Article 2(7) of the AI Act, as replaced by Regulation (EU) 2026/1744, says the AI Act does not affect the GDPR or the other Union data protection acts it names, without prejudice to its own Articles 4a and 59. An AI feature that processes personal data answers to both: the GDPR for the processing and the AI Act for the system.

Is a DPIA the same as a fundamental rights impact assessment?

No. A data protection impact assessment under GDPR Article 35 assesses the processing of personal data. A fundamental rights impact assessment under Article 27 of the AI Act is for certain deployers of high-risk systems, and under Article 27(4), as replaced, it may cross-refer to the relevant sections of the DPIA or include parts of it.

Does Complipath keep our GDPR records?

No. Complipath has no GDPR module: it does not keep your record of processing activities or your data protection impact assessments. It keeps the AI Act record, each AI system with its classification, the article behind it and the evidence, which your GDPR answers can point to.

Read next
Answer your next questionnaire with proof.No account needed. Every answer cites the article it rests on.