# Corrective Actions and Duty of Information Framework — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/corrective-action-duty-of-information-framework
> Sources are cited per item. Verify against the official texts before relying on them.

This topic combines two interconnected AI Act obligations: the requirement for providers to take corrective actions when systems fail to comply, and the corresponding duty to inform authorities and stakeholders about these actions and any identified issues. This integrated framework is essential for understanding post-market compliance mechanisms.

## Overview

## Legal Framework

The corrective actions and duty of information framework operates at the intersection of two distinct but related obligations under the AI Act and GDPR. AI Act Article 20 establishes the core requirement for providers to take corrective actions when AI systems fail to comply with regulatory requirements, coupled with a duty to inform competent authorities and affected parties. AI Act Article 45 imposes parallel information obligations on notified bodies, ensuring transparency in the conformity assessment ecosystem. Under the GDPR, Article 58(2) grants supervisory authorities the power to impose corrective measures, while Article 20 of the GDPR (as interpreted through national implementing legislation) requires member states to equip supervisory authorities with the capacity to refer infringements to judicial authorities. The CJEU confirmed in *Schrems* (C-362/14, ECLI:EU:C:2015:650) that this judicial referral capability is an essential component of effective oversight. The independence requirement under Article 16 GDPR, reinforced by Article 16(2) TFEU and Article 39 TEU, ensures that supervisory authorities can exercise these corrective powers without external interference, safeguarding the reliability of post-market compliance mechanisms.

## Key Developments

The Dutch Council of State (ECLI:NL:RVS:2021:1407) clarified that the imposition of corrective measures by supervisory authorities constitutes a discretionary power rather than a mandatory obligation for every infringement, aligning with CJEU jurisprudence (ECLI:EU:C:2023:949). This means authorities may calibrate enforcement responses proportionally rather than issuing reprimands for every minor violation. In practice, information duty violations have attracted direct enforcement: the Italian Garante fined a barber shop €800 (March 2026) and a sole trader €1,000 (February 2026) for insufficient fulfilment of information obligations, demonstrating that even small-scale operators face financial penalties for transparency failures. The ICS credit card case established that where automated profiling forms part of a decision-making process, the extended information obligations under GDPR apply, but the presence of human review can mitigate the characterization of purely automated decision-making. The UWV administrative fine case illustrates that information duty breaches—specifically failure to report income changes—trigger both corrective measures and punitive sanctions, with courts requiring authorities to account for individual circumstances when calibrating penalties.

## Practical Guidance

- **Establish internal escalation triggers**: Providers must define specific compliance failure scenarios that activate corrective action obligations under AI Act Article 20, including timelines for notifying competent authorities once a non-conformity is identified.

- **Implement layered information protocols**: Distinct notification duties apply to authorities, affected individuals, and notified bodies; each requires tailored content and timing, as enforcement authorities have penalized incomplete or delayed information provision even for minor commercial actors.

- **Document the human oversight element**: Where automated profiling is involved, maintain records demonstrating meaningful human intervention in decision-making processes, as this affects the scope of information obligations and can distinguish partially automated from fully automated decisions.

- **Calibrate corrective measures proportionally**: While authorities possess discretion in imposing corrective measures, providers should not assume minor violations will go unenforced; the Italian Garante fines demonstrate that information failures attract penalties regardless of organizational size.

- **Maintain audit trails for supervisory authority engagement**: When complaints are filed requesting corrective measures, supervisory authorities must process them within their discretionary framework; providers should preserve all correspondence and compliance documentation to support their position during investigations.

## Legislation (full text of key provisions)

### Corrective actions and duty of information

*Source: AI Act, aiact-art-20-en, 2024-06-12 — https://overview.legal/posts/92298*

### Information obligations of notified bodies

*Source: AI Act, aiact-art-45-en, 2024-06-12 — https://overview.legal/posts/92671*

### Recital 88 — AI value chain supplier cooperation

*Source: AI Act, aiact-rec-88-en, 2024-06-12 — https://overview.legal/posts/93858*

Along the AI value chain multiple parties often supply AI systems, tools and services but also components or processes that are incorporated by the provider into the AI system with various objectives, including the model training, model retraining, model testing and evaluation, integration into software, or other aspects of model development. Those parties have an important role to play in the value chain towards the provider of the high-risk AI system into which their AI systems, tools, services, components or processes are integrated, and should provide by written agreement this provider with the necessary information, capabilities, technical access and other assistance based on the generally acknowledged state of the art, in order to enable the provider to fully comply with the obligations set out in this Regulation, without compromising their own intellectual property rights or trade secrets.

## Guidance

### Report of the work undertaken by the ChatGPT Taskforce

*Source: EDPB, report-of-the-work-undertaken-by-the-chatgpt-taskforce-en, 2024-05-24 — https://overview.legal/posts/125752 — original: https://www.edpb.europa.eu/documents/task-force-report/report-of-the-work-undertaken-by-the-chatgpt-taskforce_en*

Report of the work undertaken by the ChatGPT Taskforce 23 May 2024 Final 2 Final 3 D ISCLAIMER The positions presented in this document result from the coordination of the members of the ChatGPT taskforce with a view to handling investigations regarding the service ChatGPT provided by the US based company OpenAI OpCo, LLC . They reflect the common denominator agreed by the S upervisory A uthorities in their interpretation of the applicable provisions of the GDPR in relation to the matters that…

### EDPB-EDPS Joint Opinion 03/2022 on the Proposal for a Regulation on the European Health Data Space

*Source: EDPB, edpb-edps-joint-opinion-032022-on-the-proposal-for-a-regulation-on-en, 2022-07-12 — https://overview.legal/posts/125922 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-032022-on-the-proposal-for-a-regulation-on_en*

Adopted 1 EDPB - EDPS Joint Opinion 03 /2022 on the Proposal for a Regulation on the European Health Data Space Adopted on 12 July 2022 Adopted 2 Adopted 3 Executive Summary With this Joint Opinion, the EDPB and the EDPS aim to draw attention to a number of overarching concerns on the Proposal on the European Health Data Space and urge the co - legislature to take decisive action. The EDPB and the EDPS note that the Proposal ai ms at supporting individuals to take control of their own health…

## Enforcement decisions

### Italian DPA finds GDPR applies to US-based Character.AI service

*Source: Garante per la protezione dei dati personali (Italy), 2026-07-03 — https://overview.legal/posts/108999 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_487/2026*

Facts — Character Technologies, Inc (the controller) is a company established in the US that operates the site Character.AI. Character.AI is a generative AI service that allows users to create and interact through chat with virtual characters that already exist or are created at the moment. The controller made this available to data subjects in Italian, and had a specific version for children. The DPA initiated an ex-officio investigation in 2024. The DPA requested information related to the LLM models used by the controller, the provision of the service, and data transfers. The controller provided a DPIA, and stated that it introduced an age verification system that required data subjects to register their date of birth. In 2025, the controller announced it would prevent underage data subjects from accessing open chat rooms, and would begin processing personal data of data subjects in the EEA to post-train its generative AI systems. Holding — The DPA first clarified that the GDPR is applicable even if the controller was established outside of the EU, in accordance with Article 3(2) GDPR. The DPA took into account the fact that the service was available in Italy and in Italian, as well as the privacy policy also applying to EEA residents. Given that the controller did not have an establishment in the EU, the one-stop-shop mechanism did not apply and the DPA was competent. The DPA found a violation of Articles 12(1), 13(1) and (2), and 14(1) and (2) GDPR. The DPA considered that the controller had failed to meet its information obligations. In terms of the controller’s privacy policy, the DPA considered that the controller had not provided data subjects’ with clear information regarding its processing activities, data transfers, or data subjects’ right to object and opt out. In addition, the controller failed to designate a representative in the EU, and included misleading and inaccurate statements on the processing of personal data for purposes of post-training LLMs for the service. However, the DPA also took into consideration that the controller had updated its privacy policy to make its language clearer. In terms of its pre-training activities, the DPA stated that the controller had failed to provide adequate information and therefore violated Articles 14(1) and (2) GDPR. The DPA dismissed the controller’s argument that it did not have the obligation to provide this information due to the data being collected by third parties from open sources. The DPA stated that the controller had the obligation to verify whether personal data was present. In addition, the exemption under Article 14(5)(b) GDPR does not exempt the controller from having the obligation to implement appropriate measures to protect data subjects’ rights. However, the DPA did not find a violation of Articles 21(1) and (4). The DPA referred to the EDPB opinion on processing personal data in relation to AI systems. The EDPB recommended controllers to adopt measures for data subjects to exercise their rights, including providing the option to provide data subjects with the option to object unconditionally before the processing takes place. The DPA considered that this opinion went beyond the literal wording of Articles 14 and 21 GDPR. This interpretation could not, in the DPA’s view, be interpreted retroactively to the controller’s processing activities. The DPA found a violation of Articles 24(1) and 25(2) GDPR. The DPA considered that the controller had failed to implement adequate technical and organisational measures to verify data subjects’ age. During its investigations, the DPA found that the controller’s age verification systems were not effective, as they allowed data subjects’ to access the service even after self declaring to be younger than the minimum age limit set by the controller. The DPA also found that the accounts were set to public by default. Therefore, the controller had failed to implement appropriate measures to protect underage data subjects, even if the GDPR does not set a harmonised and binding standard in relation to age verification. The DPA also found a violation of Articles 5(2) and 35 GDPR. Under Article 5(2) GDPR, the controller has the obligation to proactively demonstrate compliance with the GDPR. The DPA stated that a key tool to do this is through data protection impact assessments (DPIAs). Controllers are obliged to carry out a DPIA under Article 35 GDPR if the processing is likely to result in a high to the rights and freedoms of data subjects. The controller failed to do a DPIA on time in relation to providing the service to underage data subjects, as well as in relation to its processing activities for the purpose of pre-training its LLM. The DPA stated that the controller should have done this before launching the service in 2022, as the processing activities had a presumed high risk to freedoms and rights of data subjects (e.g. the use of large scale processing or processing data of vulnerable data subjects). However, the DPA acknowledged that the controller progressively improved its compliance by doing a (late) DPIA and updating it. Finally, the DPA found a violation of Article 27(1) GDPR, as the controller belatedly designated a representative in the EU. The DPA stated that the exemption under Article 27(2) GDPR did not apply. The DPA fined the controller €158,000. The DPA also ordered the controller to bring its privacy policy and storage of personal data for purposes of pre-training its LLM into compliance with the GDPR. The DPA also ordered the controller to implement effective age verification mechanisms.

### Italian DPA: AgID's automatic transfer of PEC addresses to INAD index unlawful

*Source: Garante per la protezione dei dati personali (Italy), 2026-05-28 — https://overview.legal/posts/122875 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_419/2026*

Facts — The data controller for the case is a government body called the Agency for Digital Italy (AgID). AgID is tasked with driving the adoption of digital technologies in both government and the private sector. Additionally, AgID is Italy’s soon-to-be notification authority for the AI Act. The case revolves around two public online indexes of certified email addresses: the INI-PEC and the INAD. INI-PEC is the older of the two indexes and includes, among others, the email addressess of professionals (the data subjects). INAD was created by AgID in 2023 as provided by Italian law and functions as an index of “digital domiciles” (where data subjects are supposed to get certain important communications) for both professionals and other owners of a digital email address. Shortly after setting up the INAD index, AgID automatically included the addresses of professionals from the old INI-PEC index. As a result, the addresses automatically became the digital domicile for communications not related to the professional lives of the data subjects. Data subjects were given the option to opt-out of the inclusion in the INAD index. Some data subjects complained that this processing severely infringed on their privacy. As the DPA’s decision explains, it is not uncommon for professionals to give co-workers access to their professional email addresses, on the assumption that they will only be used for strictly professional communications. When the addressess became digital domiciles, third parties (such as public bodies) started using them for communications unrelated to the data subjects' personal lives - which occasionally led to unintended data disclosures. The data subjects also claimed that the controller had not informed them about the processing, which prevented them from opting out in a timely fashion. Holding — The investigation — On the duty of information — First of all, the DPA clarified that by including email addresses in the INAD index, the controller further processed personal data for a new purpose, incompatible with the original purpose of the processing (i.e.: the inclusion of email addresses in the older index). With regards to the duty of information, the controller pointed out that it contacted professional orders to inform them about the creation of the INAD index. In the context of these communications, the controller asked professional orders to inform the data subjects about this processing of personal data and about their right to opt out. The controller stated that it did not directly contact the data subjects via their email addresses, as it feared that its emails would have been mistaken as phishing or scams . The controller later launched a more effective information campaign with the help of other government bodies; however, this campaign only took place in 2025 - two years after addresses where included in the INAD index. On the controller’s identity — The DPA’s investigation also focused on a second issue, relative to the authentication procedure for digital domiciles: for a long time, a company (InfoCamere S.c.p.a.) was erroneously listed as a service provider for the INAD index. During the investigation, the controller confirmed that InfoCamere had no role in the processing of personal data. The controller also stated that it had contacted the actual service provider in order to correct the error and that the provider had done so with great delay. The DPA's conclusion — The DPA held that until 2025, the controller had failed to inform the data subjects about the inclusion of their email address in the INAD index, in violation of Articles 5(1)(a), 5(1)(b), 5(2), 12, 14 and 25 GDPR. On these grounds, the DPA fined the controller €55,000. With regards to the erroneous indication of the service provider in the authentication screen, the DPA found that the mistake was isolated and that overall, the information provided during the procedure was still sufficient to clarify that AgID was the controller. On these grounds, the DPA found that the mistake did not, in and of itself, constitute a violation of the GDPR.

## Literature

### Regulatory Responses to Data Breaches: Evaluating the Effectiveness of GDPR and CCPA in Consumer Protection

*Source: International Journal of Social Sciences and Public Administration, 2025-01-23 — https://overview.legal/posts/132539 — original: https://doi.org/10.62051/ijsspa.v6n1.22*

In the digital age, data breaches have become a significant threat to consumer privacy, prompting the implementation of stringent data protection regulations worldwide. This paper evaluates the effectiveness of two prominent regulatory frameworks, the General Data Protection Regulation (GDPR) in the European Union and the California Consumer Privacy Act (CCPA) in the United States, in safeguarding consumer data and responding to data breaches. Through a comparative analysis of their key provisio

## Related topics

- **Post-Market Monitoring for AI Systems** — https://overview.legal/topics/post-market-monitoring-ai
  Risk management systems require ongoing post-market monitoring to identify and respond to risks that emerge during real-world deployment. This is a distinct and
- **Monitoring Actions under AI Act** — https://overview.legal/topics/monitoring-actions-ai-act
  The content specifically addresses 'Monitoring actions' as a distinct topic under the AI Act, which encompasses systematic oversight procedures, compliance veri
- **AI Corrective Actions** — https://overview.legal/topics/corrective-actions-ai
  This new topic is needed because corrective actions are a specific and distinct obligation under the AI Act that encompasses systematic procedures for addressin
- **AI Corrective Powers** — https://overview.legal/topics/authority-intervention-corrective-powers-ai
  This new topic is needed to specifically address the corrective and intervention powers that authorities possess to protect fundamental rights, including emerge
- **Risk Management System** — https://overview.legal/topics/risk-management-system
  This new topic is needed because risk management systems are a distinct and mandatory requirement under the AI Act, encompassing systematic processes for identi
- **Authority Powers for Fundamental Rights Protection** — https://overview.legal/topics/authority-powers-fundamental-rights-protection
  This new topic is needed because the content specifically addresses the powers and authorities granted to competent authorities to protect fundamental rights in

---
Generated by overview.legal · https://overview.legal/topics/corrective-action-duty-of-information-framework · 2026-08-22
