AIPolicyTracker
Legal requirement Privacy and personal-data protection European Union Partially applicable

Deployers must use the provider's transparency information in their data protection impact assessment

Context fileUnder EU AI Act, Article 26(9)

Source-linked Open official source

What does it require?

Where a deployer of a high-risk AI system is required to carry out a data protection impact assessment under Article 35 of the GDPR or Article 27 of the Law Enforcement Directive, it must draw on the information the provider supplied under Article 13, such as the intended purpose, performance, limitations and human-oversight measures, when producing that assessment.

Practical action

Attach the provider's instructions for use to the DPIA template and cross-reference the Article 27 fundamental rights impact assessment where one is required.

Who does it apply to?

Deployers of high-risk AI systems that process personal data in a way that triggers a DPIA.

Applies from:

Which controls meet this duty?

Satisfies: the control, operated properly, does the work the duty asks for. Supports: it contributes but the duty needs more. Each control page lists every other duty it serves, so work done once can be counted once.

  • satisfiesProcessData protection officer · once per ai system
    Privacy and data-protection controls for AI

    Serves 13 recorded duties · evidence: Data protection impact assessment for an AI system, AI data-flow and legal-basis record, Privacy notice section on AI use

    DPIA built on the provider's documentation.

  • supportsProcessAI system owner · once per ai system
    AI impact and fundamental-rights impact assessment

    Serves 11 recorded duties · evidence: AI impact assessment, Impact assessment approval, Impact assessment procedure and template

    Shared inputs with the fundamental rights impact assessment.

What evidence would a reviewer expect?

Evidence examples
EvidenceTypeNotes
Data protection impact assessment citing the provider's Article 13 informationreport

Framework mappings

Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.

See every European Union duty mapped this way →

Framework mappings
FrameworkReferenceNoteConfidence
ISO/IEC 42001:2023Clause 6.1.4; Annex A.5.2AI system impact assessment process.medium
NIST AI RMF 1.0MAP 3.1, MEASURE 2.10Privacy risk assessed with system information.medium

Cite this record

AIPolicyTracker (2026). “Deployers must use the provider's transparency information in their data protection impact assessment (EU AI Act)”. https://aipolicytracker.org/obligations/eu-ai-act-art-26-9-dpia-using-provider-information (accessed 24 September 2026). Data licensed CC BY 4.0.

Cite the official text alongside it: Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, Official Journal of the European Union, https://eur-lex.europa.eu/eli/reg/2024/1689/oj.

Similar obligations in other instruments

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.