GDPR vs PL 2338: what they share and how they differ

GDPR and PL 2338 share 10 of 24 control themes and 11 checks. 45% of PL 2338 requirements can be proven with checks GDPR already uses, 80% the other way round.

EURegulationIn force

GDPR

How to make AI compliant with the GDPR

10 requirementsNext Jan 2027
BRBillUnder discussion

PL 2338

Preparing for the Brazil AI Bill (PL 2338/2023)

20 requirementsNext Oct 2026
10/24shared control themes
11shared checks
45%of PL 2338 requirements covered by GDPR evidence
80%of GDPR requirements covered by PL 2338 evidence

At a glance

GDPR PL 2338
JurisdictionEuropean UnionBrazil
KindRegulationBill
StatusIn forceUnder discussion
BindingYesNo
Object analysedData processingAI system
ScopeControllers and processors.Developers, distributors and appliers of AI systems.
Territorial reachEU establishment, or targeting / monitoring people in the EU.Systems provided or used in Brazil.
PenaltiesUp to €20M or 4% of worldwide turnover.Senate text: up to BRL 50M or 2% of turnover per infringement; suspension.
Qualification axesAutomated decision (Art. 22), DPIA required (Art. 35)PL 2338 risk level, Role (Art. 4)
RolesController, ProcessorDeveloper, Distributor, Applier
Requirements1020
Next milestoneJan 2027, Possible adoption of the Omnibus amendmentsOct 2026, Vote pushed past the October 2026 elections

Theme by theme

requirements per theme

What they share: one piece of evidence, two frameworks

11

CodeCheckRequirements GDPRRequirements PL 2338
VER-029-D-01Affected persons informed of the use of the AI system
VER-008-02System designed to allow human oversight (stop button, override)
VER-033-D-01Decision explanation procedure documented
CHK-BR-CONTESTProcedure to contest a decision and obtain human review published
VER-004-01Documented data governance (collection process, bias, quality)
VER-019-D-02DPIA carried out in accordance with GDPR Art. 35
VER-009-01Cybersecurity of the hosting environment
VER-009-03Cybersecurity of the AI system verified
VER-022-D-01Serious incident reporting procedure
VER-026-F-01Contractual responsibilities documented between provider and third parties
VER-033-D-03Explanations provided on request within a reasonable timeframe

Differences: requirements specific to each framework

Requirements with no check serving the other framework: the extra work.

Timelines

PastSet in the textPotentialTo verify
Apr 27, 2016GDPR · Adoption
May 25, 2018GDPR · Application date
May 3, 2023PL 2338 · Filed in the Senate
Dec 10, 2024PL 2338 · Senate approval
Dec 17, 2024GDPR · EDPB Opinion 28/2024 on AI models
May 2025PL 2338 · Special committee in the Chamber of Deputies
Nov 19, 2025GDPR · Digital Omnibus: legitimate interest for AI training, personal data definition
Oct 2026PL 2338 · Vote pushed past the October 2026 elections
Jan 2027GDPR · Possible adoption of the Omnibus amendments
Jun 2027PL 2338 · Possible adoption and start of the vacatio legis

Run these requirements across all your AI systems

TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.

Request a demo