Digital Law

GDPR, AI Act, Data Act: bringing your operations into line with a fast-changing framework.

grayscale photo of motherboard

Data and digital tools have become central assets, but also a source of numerous and shifting legal obligations. Between the GDPR, now well established, and the new European regulations on artificial intelligence and on data, businesses have to organise their compliance without slowing down their activity. LexInnov Law Firm supports them in this, with a pragmatic approach.

The General Data Protection Regulation (European Regulation 2016/679) governs all processing of personal data. It rests on clear principles: lawfulness, a specified purpose, data minimisation, accuracy, storage limitation and security.

In practice, a compliant business must identify a legal basis for each processing operation, keep a record of processing activities, inform data subjects transparently, ensure they can exercise their rights (access, rectification, erasure, objection, portability), and secure the data. Some sensitive processing requires a data protection impact assessment (DPIA), and any data breach must in principle be notified to the CNIL as soon as possible — generally within 72 hours — and sometimes communicated to the individuals concerned. Failing to meet these obligations exposes a business to significant administrative penalties and to reputational harm.

The European regulation on artificial intelligence (the “AI Act”, Regulation 2024/1689) entered into force in 2024, with a phased application over time. It takes a risk-based approach: some uses deemed unacceptable are prohibited, systems classed as “high-risk” are subject to strict obligations (documentation, risk management, human oversight), while others are subject to simple transparency requirements.

For a business that designs, integrates or merely uses an AI system, it becomes necessary to map these uses, identify the level of risk, and put in place the corresponding documentation and safeguards. The interplay with the GDPR is constant, whenever personal data feeds into — or comes out of — these systems.

The European regulation on data (the “Data Act”, Regulation 2023/2854) governs access to and sharing of data, in particular the data generated by connected devices. It creates new rights for users and new obligations for manufacturers and service providers, with a direct impact on data-supply and data-sharing contracts, which need to be revised accordingly.

Digital compliance does not stop at the record of processing and privacy notices. Using cookies and trackers on a website requires, for non-essential purposes, consent obtained in the proper way. Direct marketing, particularly by electronic means, is likewise subject to precise rules. And whenever data is hosted or processed outside the European Union, you have to make sure the transfer rests on a valid legal framework. These points, frequently the subject of checks, deserve particular attention when setting up or overhauling an online service.

The firm helps businesses audit their processing operations and digital tools, draft the necessary documents (privacy notices, privacy policies, contractual clauses, data-processing agreements), and build lasting compliance in the face of a moving regulatory framework. The aim is to reconcile legal certainty with the growth of the business.

Grenoble – 17 September 2026