Alessandro Del Ninno
Conferences
Artificial Intelligence and Personal Data Protection: relationships between sources and legal systems, and practical Issues for operators.
Workshop organized by Paradigma S.p.A. - Rome, 31 March 2026.
31/03/2026
Artificial Intelligence and Personal Data Protection: relationships between sources and legal systems, and practical Issues for operators.

Avv. Alessandro Del Ninno took part as a speaker in the Paradigma conference entitled “Data Protection Profiles of Artificial Intelligence”, held on 31 March 2026 and devoted to the analysis of the personal data processing issues raised by the application of the AI Act, the guidance issued by European authorities, and the compliance adjustments required in practice. Within the programme, his presentation was entitled “Artificial Intelligence and Personal Data Protection: Relationships Between Sources and Legal Systems, and Practical Issues for Operators”, serving as an introductory and systematic contribution to the entire event. 

 

During his presentation, Avv. Del Ninno outlined the regulatory framework within which the relationship between artificial intelligence and personal data protection must now be understood, first focusing on the notion of “data” in the European regulatory landscape and on the distinctions between personal data, non-personal data, electronic documents and digital documents. On this basis, he explained that the AI Act does not replace the GDPR, but rather operates alongside it in a complementary relationship, leaving the General Data Protection Regulation as the primary legal framework governing the lawfulness of processing, data subjects’ rights, and the safeguards applicable whenever an AI system involves the processing of personal data. 

 

Particular attention was devoted to the relationship between the risk-based approach under the GDPR and the one adopted by the AI Act. His speech highlighted that, whereas under the GDPR the concepts of risk and high risk largely require case-by-case assessments by the controller, under the European AI Regulation the qualification of a system as “high-risk” is based on more clearly defined legislative criteria and on categories expressly identified by law. Against this background, he examined the points of contact and possible overlaps between the two regimes, especially where high-risk AI systems involve personal data processing that may also amount to a high risk under Article 35 GDPR.

 

Avv. Del Ninno then explored the main express references made by the AI Act to the GDPR, focusing in particular on the obligations of deployers, the relationship between the fundamental rights impact assessment and the DPIA, the issues relating to logs automatically generated by AI systems, as well as the conformity declarations and the information to be entered in the EU database for high-risk systems. His analysis showed that the interaction between the two regulations is not merely theoretical, but gives rise to specific documentary, organisational and governance obligations that companies and public bodies must address from the design and deployment stages onward.

 

A further part of the presentation addressed the data governance system laid down by Article 10 of the AI Act for high-risk AI systems. In this respect, Avv. Del Ninno examined the quality requirements applicable to datasets used for training, validation and testing, the need for representativeness, accuracy and completeness, and the safeguards required to prevent bias, discrimination and distorted outcomes. He also discussed the particularly sensitive issue of the possible processing of special categories of personal data for the purposes of detecting and correcting bias, highlighting the conditions of strict necessity, pseudonymisation and security that must accompany such processing.

 

In the final part of his presentation, Avv. Del Ninno addressed the most recent developments under the Digital Omnibus package, illustrating the proposed amendments to the GDPR that are relevant in the context of artificial intelligence. In particular, he examined the possible expansion of the derogations for the processing of special categories of data, the proposed amendments concerning fully automated decision-making, the reinforcement of minimisation and pseudonymisation principles, and the possible introduction of specific provisions governing the processing of personal data in the development and operation of AI systems and models. His presentation therefore provided participants with an integrated reading of current European regulatory developments, highlighting their practical implications for controllers, processors, deployers, technology providers and DPOs.

 

Through this contribution, Avv. Alessandro Del Ninno offered a systematic and operational interpretation of the relationship between the AI Act, the GDPR and other European instruments on data, platforms and digital governance, showing how compliance in the AI field now requires an integrated model capable of combining technological innovation, the protection of fundamental rights and the robustness of organisational safeguards.