Build a board-ready risk heatmap in minutes — free, no account required

Open tool

Article 26(9)

UpcomingConditional timing

Use Provider Information to Support an Applicable Data Protection Impact Assessment

Applies to Deployer; High-Risk AI, where DPIA is applicable.

Actors
Deployer
AI class
High-Risk AI
Themes
Data, Privacy & InformationGovernance & Accountability

Tracker Guidance

Where your organization is required to carry out a data protection impact assessment under Article 35 GDPR or Article 27 of Directive (EU) 2016/680, use the relevant information supplied by the high-risk AI provider under Article 13 when conducting that assessment.

Official text

Article 26(9)Official source
9. Where applicable, deployers of high-risk AI systems shall use the information provided under Article 13 of this Regulation to comply with their obligation to carry out a data protection impact assessment under Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680.

Timing depends on the system

  • 2 Dec 2027Article 6(2) / Annex III high-risk AI
  • 2 Aug 2028Article 6(1) / Annex I Section A high-risk AI
  • 2 Dec 2027Pre-existing Annex III high-risk AI type/model first placed on the market or put into service before 2027-12-02
  • 2 Aug 2028Pre-existing Article 6(1) / Annex I high-risk AI type/model first placed on the market or put into service before 2028-08-02
  • 2 Aug 2030Pre-existing high-risk AI intended to be used by public authorities

Recognized by G2 as a Leader

Trusted by customers and rated highly across all categories

Article 26(9): Use Provider Information to Support an Applicable Data Protection Impact Assessment | EU AI Act Library