{"id":118362,"date":"2024-08-11T07:05:00","date_gmt":"2024-08-11T05:05:00","guid":{"rendered":"https:\/\/ceadigilaw.org\/la-dicotomia-regulatoria-rgpd-y-ria\/"},"modified":"2026-07-17T21:34:22","modified_gmt":"2026-07-17T19:34:22","slug":"la-dicotomia-regulatoria-rgpd-y-ria","status":"publish","type":"post","link":"https:\/\/ceadigilaw.org\/en\/blog\/la-dicotomia-regulatoria-rgpd-y-ria\/","title":{"rendered":"The Regulatory Dichotomy: GDPR and the AI Act"},"content":{"rendered":"<p><span style=\"color: #000000\"><strong><a style=\"color: #000000\" href=\"\/staff\/antonio-tejeda-encinas-2\/\" target=\"_blank\" rel=\"noopener\">Antonio Tejeda Encinas<\/a><\/strong>. Lawyer. Chairman of the Euro American Digital Law Committee &#8211;<strong><a style=\"color: #000000\" href=\"\/en\/\" target=\"_blank\" rel=\"noopener\">EA Digital Law<\/a><\/strong><\/span><\/p>\n<p><span style=\"color: #000000\">In the vast and complex framework of European regulations, the General Data Protection Regulation (GDPR) and the Artificial Intelligence Regulation (RIA) are raised as two pillars that reflect the sophistication and global reach of European Union laws. While both seek to protect EU citizens and ensure that business technologies and practices align with European values, their approaches and application criteria are remarkably different.<\/span><\/p>\n<p><span style=\"color: #000000\"><strong>GDPR&#8217;s EXTRATERRITORIAL Scope<\/strong><\/span><\/p>\n<p><span style=\"color: #000000\">The GDPR, which came into force in May 2018, revolutionised the data protection landscape by setting strict rules on how EU residents\u2019 personal data should be handled. Its extraterritorial application is based on two main criteria:<\/span><\/p>\n<p><span style=\"color: #000000\"><strong>Establishment criterion:<\/strong> <\/span><br \/>\n<span style=\"color: #000000\">This criterion determines that GDPR applies if a company has a &#8220;establishment&#8221; in the EU and processes personal data in the context of its activities in the Union. Here, the term &#8220;establishment&#8221; is interpreted broadly, encompassing any physical presence involving effective business activities within the EU.<\/span><\/p>\n<p><span style=\"color: #000000\"><strong>Addressing or Targeting Criteria:<\/strong> <\/span><br \/>\n<span style=\"color: #000000\">GDPR also applies to companies outside the EU that offer goods or services to individuals within the Union or that monitor their behaviour. The latter may include online tracking through cookies or marketing techniques that analyze users&#8217; behavior.<\/span><\/p>\n<p><span style=\"color: #000000\">The essence of GDPR is to protect the fundamental rights of individuals with respect to their data, ensuring that any entity processing data from EU citizens does so within a clear and responsible framework.<\/span><\/p>\n<p><span style=\"color: #000000\"><strong>RIA&#8217;S EXTRATERRITORIAL Scope<\/strong><\/span><\/p>\n<p><span style=\"color: #000000\">On the other hand, the Artificial Intelligence Regulation (RIA), which came into force on 1 August 2024, takes a broader and, in many ways, more aggressive approach. Designed to regulate the use of artificial intelligence technologies that may have an impact on the EU, the RIA is applied without the AI provider or developer having intended to direct their technology to the European market.<\/span><\/p>\n<p><span style=\"color: #000000\">This approach is due to the transformative and potentially disruptive nature of AI. The EU seeks to ensure that any AI system operating within its jurisdiction meets high standards of transparency, ethics and safety, regardless of the original intention of the developer<\/span><\/p>\n<p><span style=\"color: #000000\"><strong>Analysis of the RIA Protectionist Approach<\/strong><\/span><\/p>\n<p><span style=\"color: #000000\">The protectionist stance of the RIA may seem strict, but it reflects a clear intention of the EU to lead the regulation of artificial intelligence globally. By demanding that any AI system that impacts on the EU comply with its regulations, the EU protects not only its citizens, but also its market and ethical values.<\/span><\/p>\n<p><span style=\"color: #000000\"><strong>Incentives for Responsible Innovation:<\/strong> <\/span><br \/>\n<span style=\"color: #000000\">By setting high standards, the EU could promote innovation within an ethical and secure framework, and companies that meet these standards could benefit from a more accessible European market.<\/span><\/p>\n<p><span style=\"color: #000000\"><strong>Challenges for Foreign Companies:<\/strong> <\/span><br \/>\n<span style=\"color: #000000\">AI companies outside the EU could face significant challenges in trying to comply with these regulations, which could limit the availability of certain services or technologies on the European market<\/span><\/p>\n<p><span style=\"color: #000000\"><strong>Global Leadership Position:<\/strong> <\/span><br \/>\n<span style=\"color: #000000\">The EU could consolidate its position as a global leader in AI regulation, setting precedents that other regions could adopt, thus promoting a safer and more ethical AI at a global level.<\/span><\/p>\n<p><span style=\"color: #000000\">In short, for global companies, understanding these differences is crucial. While GDPR focuses on consent and intent in data processing, the RIA expands the spectrum towards preventive regulation of emerging technologies. This dichotomy highlights not only the sophistication of European legislation, but also its leadership in shaping a global environment where technology serves humanity responsibly and ethically.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Antonio Tejeda Encinas. Lawyer. Chairman of the Euro American Digital Law Committee &#8211;EA Digital Law In the vast and complex framework of European regulations, the General Data Protection Regulation (GDPR) and the Artificial Intelligence Regulation (RIA) are raised as two pillars that reflect the sophistication and global reach of European Union laws. While both seek [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":112090,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"wds_primary_category":0,"wds_primary_cea_women":0,"footnotes":""},"categories":[1102,1107],"tags":[],"cea_women":[],"class_list":["post-118362","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-artificial-intelligence","category-data-protection-privacy"],"acf":[],"_links":{"self":[{"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/posts\/118362","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/comments?post=118362"}],"version-history":[{"count":1,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/posts\/118362\/revisions"}],"predecessor-version":[{"id":119442,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/posts\/118362\/revisions\/119442"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/media\/112090"}],"wp:attachment":[{"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/media?parent=118362"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/categories?post=118362"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/tags?post=118362"},{"taxonomy":"cea_women","embeddable":true,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/cea_women?post=118362"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}