Deployers must use the provider's transparency information in their data protection impact assessment
Context fileUnder EU AI Act, Article 26(9)
What does it require?
Where a deployer of a high-risk AI system is required to carry out a data protection impact assessment under Article 35 of the GDPR or Article 27 of the Law Enforcement Directive, it must draw on the information the provider supplied under Article 13, such as the intended purpose, performance, limitations and human-oversight measures, when producing that assessment.
Practical action
Attach the provider's instructions for use to the DPIA template and cross-reference the Article 27 fundamental rights impact assessment where one is required.
Who does it apply to?
Deployers of high-risk AI systems that process personal data in a way that triggers a DPIA.
Applies from:
Which controls meet this duty?
Satisfies: the control, operated properly, does the work the duty asks for. Supports: it contributes but the duty needs more. Each control page lists every other duty it serves, so work done once can be counted once.
-
satisfiesProcessData protection officer · once per ai systemPrivacy and data-protection controls for AI
Serves 13 recorded duties · evidence: Data protection impact assessment for an AI system, AI data-flow and legal-basis record, Privacy notice section on AI use
DPIA built on the provider's documentation.
-
supportsProcessAI system owner · once per ai systemAI impact and fundamental-rights impact assessment
Serves 11 recorded duties · evidence: AI impact assessment, Impact assessment approval, Impact assessment procedure and template
Shared inputs with the fundamental rights impact assessment.
What evidence would a reviewer expect?
| Evidence | Type | Notes |
|---|---|---|
| Data protection impact assessment citing the provider's Article 13 information | report |
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
See every European Union duty mapped this way →
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| ISO/IEC 42001:2023 | Clause 6.1.4; Annex A.5.2 | AI system impact assessment process. | medium |
| NIST AI RMF 1.0 | MAP 3.1, MEASURE 2.10 | Privacy risk assessed with system information. | medium |
Cite this record
AIPolicyTracker (2026). “Deployers must use the provider's transparency information in their data protection impact assessment (EU AI Act)”. https://aipolicytracker.org/obligations/eu-ai-act-art-26-9-dpia-using-provider-information (accessed 24 September 2026). Data licensed CC BY 4.0.
Cite the official text alongside it: Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, Official Journal of the European Union, https://eur-lex.europa.eu/eli/reg/2024/1689/oj.
Similar obligations in other instruments
- Collect and use personal information only with consent and for the stated purpose — Nepal Privacy Act 2075, Nepal
- Process personal data only with valid consent or a legitimate use, after notice — India DPDP Act, India
- Identify consent or an applicable PDPA exception before using personal data in AI — PDPC AI advisory guidelines, Singapore
- Employers and employment agencies must disclose the data collected and their retention policy for the tool — NYC Local Law 144 (automated employment decision tools), New York (United States)
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.