GDPR vs PL 2338: what they share and how they differ
GDPR and PL 2338 share 10 of 24 control themes and 11 checks. 45% of PL 2338 requirements can be proven with checks GDPR already uses, 80% the other way round.
In force
GDPR
How to make AI compliant with the GDPR
10 requirementsNext Jan 2027
Under discussion
PL 2338
Preparing for the Brazil AI Bill (PL 2338/2023)
20 requirementsNext Oct 2026
10/24shared control themes
11shared checks
45%of PL 2338 requirements covered by GDPR evidence
80%of GDPR requirements covered by PL 2338 evidence
At a glance
| GDPR | PL 2338 | |
|---|---|---|
| Jurisdiction | European Union | Brazil |
| Kind | Regulation | Bill |
| Status | In force | Under discussion |
| Binding | Yes | No |
| Object analysed | Data processing | AI system |
| Scope | Controllers and processors. | Developers, distributors and appliers of AI systems. |
| Territorial reach | EU establishment, or targeting / monitoring people in the EU. | Systems provided or used in Brazil. |
| Penalties | Up to €20M or 4% of worldwide turnover. | Senate text: up to BRL 50M or 2% of turnover per infringement; suspension. |
| Qualification axes | Automated decision (Art. 22), DPIA required (Art. 35) | PL 2338 risk level, Role (Art. 4) |
| Roles | Controller, Processor | Developer, Distributor, Applier |
| Requirements | 10 | 20 |
| Next milestone | Jan 2027, Possible adoption of the Omnibus amendments | Oct 2026, Vote pushed past the October 2026 elections |
Theme by theme
requirements per theme
GDPRPL 2338
Governance
Assessment
Build
People & use
Lifecycle & third parties
What they share: one piece of evidence, two frameworks
11
| Code | Check | Requirements GDPR | Requirements PL 2338 |
|---|---|---|---|
| VER-029-D-01 | Affected persons informed of the use of the AI system | ||
| VER-008-02 | System designed to allow human oversight (stop button, override) | ||
| VER-033-D-01 | Decision explanation procedure documented | ||
| CHK-BR-CONTEST | Procedure to contest a decision and obtain human review published | ||
| VER-004-01 | Documented data governance (collection process, bias, quality) | ||
| VER-019-D-02 | DPIA carried out in accordance with GDPR Art. 35 | ||
| VER-009-01 | Cybersecurity of the hosting environment | ||
| VER-009-03 | Cybersecurity of the AI system verified | ||
| VER-022-D-01 | Serious incident reporting procedure | ||
| VER-026-F-01 | Contractual responsibilities documented between provider and third parties | ||
| VER-033-D-03 | Explanations provided on request within a reasonable timeframe |
Differences: requirements specific to each framework
Requirements with no check serving the other framework: the extra work.
GDPR
2
GDPR-01
GDPR-05
Record of processing activities Art. 30
PL 2338
11
BR-01
Preliminary assessment Arts. 12, 29
BR-02
Excessive-risk practices Art. 13
BR-04
Synthetic content identifier Art. 19
BR-09
Applier documentation Art. 18 I.a, I.c, I.f
BR-10
Developer documentation and explainability Art. 18 II.a, II.d
BR-11
Operation logging Art. 18 II.b
BR-13
Monitoring of results Art. 18 I.b
BR-17
General-purpose and generative AI Arts. 29, 30
BR-18
Training content and opt-out Arts. 62, 64
BR-19
Public-sector duties Arts. 22, 23
BR-20
Remuneration of rights holders Art. 65
Timelines
PastSet in the textPotentialTo verify
Apr 27, 2016GDPR · Adoption
May 25, 2018GDPR · Application date
May 3, 2023PL 2338 · Filed in the Senate
Dec 10, 2024PL 2338 · Senate approval
Dec 17, 2024GDPR · EDPB Opinion 28/2024 on AI models
May 2025PL 2338 · Special committee in the Chamber of Deputies
Nov 19, 2025GDPR · Digital Omnibus: legitimate interest for AI training, personal data definition
Oct 2026PL 2338 · Vote pushed past the October 2026 elections
Jan 2027GDPR · Possible adoption of the Omnibus amendments
Jun 2027PL 2338 · Possible adoption and start of the vacatio legis
Run these requirements across all your AI systems
TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.