# Infringement Reporting — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/infringement-reporting-protection-framework
> Sources are cited per item. Verify against the official texts before relying on them.

This specific topic is needed to comprehensively cover Article 84 of the AI Act, which establishes a dedicated framework for reporting infringements and protecting those who report them, including confidentiality protections and safeguards against retaliation.

## Overview

## Legal Framework

Article 87 of the AI Act establishes the infringement reporting framework by directly incorporating Directive (EU) 2019/1937 — the EU Whistleblower Directive — into the AI Act's enforcement architecture. This means that the procedural and protective standards governing whistleblower reports under that Directive apply in full to violations of the AI Act. The Directive requires Member States to establish internal and external reporting channels, mandate acknowledgment of reports within prescribed timeframes, and provide feedback to reporters. Critically, it imposes confidentiality obligations on the identity of reporters and any third parties named in a report, and it establishes a robust anti-retaliation regime covering dismissal, demotion, intimidation, and other forms of professional reprisal.

The framework intersects with broader transparency obligations under adjacent digital regulation. Article 24 of the Digital Services Act imposes transparency reporting duties on providers of online platforms, and Article 42 DSA extends transparency obligations more broadly across the DSA's scope. These provisions create a layered ecosystem where infringement reporting obligations under the AI Act operate alongside — but remain distinct from — transparency and disclosure duties under the DSA.

The GDPR provides a complementary data protection dimension. Article 15 GDPR governs data subject access rights, which may intersect with infringement reports when individuals seek information about whether their personal data has been processed in connection with a complaint. Article 23 GDPR permits Member States to restrict certain data subject rights for reasons of substantial public interest, which can encompass the protection of whistleblower identities. Article 24 GDPR encourages certification mechanisms as compliance tools, relevant where organizations seek to demonstrate the adequacy of their internal reporting channels.

## Key Developments

The CJEU's reasoning in *Meta Platforms and Others v Bundeskartellamt* reinforces that adequate security of systems processing personal data — including databases used for managing public documents and infringement reports — requires protection measures extending to the electronic components and infrastructure supporting those systems. This establishes that organizations cannot treat reporting channel security as merely a procedural matter; the underlying technical infrastructure must meet substantive security thresholds.

Enforcement by national DPAs illustrates the financial stakes of non-compliance with adjacent reporting and transparency obligations. The Croatian DPA (AZOP) imposed a €4.5 million fine on a telecommunications operator for multiple GDPR violations, signaling that failures in reporting infrastructure and data handling attract significant penalties. The Italian Garante's fine against FT Solutions S.r.l. for direct marketing violations further demonstrates that authorities actively pursue entities that mishandle personal data within reporting or complaint ecosystems.

The EDPB's Guidelines 01/2021 and the revised Guidelines 9/2022 on personal data breach notification provide practical benchmarks that inform how infringement reports involving personal data should be managed, particularly regarding timeliness and documentation.

## Practical Guidance

- **Establish dedicated internal reporting channels** compliant with Directive (EU) 2019/1937 standards, ensuring reports can be submitted in writing or orally, with confirmation of receipt issued within seven days and feedback provided within three months.

- **Implement strict confidentiality protocols** protecting the identity of reporters and all third parties mentioned in reports, applying Article 23 GDPR restrictions where national law permits, to shield whistleblower identities from access requests.

- **Conduct a security assessment of reporting infrastructure** — including databases, communication channels, and storage systems — to meet the substantive security standards articulated in *Meta Platforms v Bundeskartellamt*, covering both software and hardware components.

- **Document anti-retaliation safeguards** in employment policies and contracts, explicitly covering all forms of professional reprisal prohibited under the Whistleblower Directive, and train managers on these protections.

- **Align AI Act infringement reporting with existing GDPR breach notification and DSA transparency reporting procedures** to avoid fragmented compliance and ensure consistent treatment of overlapping obligations across regulatory regimes.

## Legislation (full text of key provisions)

### Recital 76 — AI system cybersecurity protection measures

*Source: AI Act, aiact-rec-76-en, 2024-06-12 — https://overview.legal/posts/93834*

Cybersecurity plays a crucial role in ensuring that AI systems are resilient against attempts to alter their use, behaviour, performance or compromise their security properties by malicious third parties exploiting the system’s vulnerabilities. Cyberattacks against AI systems can leverage AI specific assets, such as training data sets (e.g. data poisoning) or trained models (e.g. adversarial attacks or membership inference), or exploit vulnerabilities in the AI system’s digital assets or the underlying ICT infrastructure. To ensure a level of cybersecurity appropriate to the risks, suitable measures, such as security controls, should therefore be taken by the providers of high-risk AI systems, also taking into account as appropriate the underlying ICT infrastructure.

### Recital 54 — high-risk biometric AI classification

*Source: AI Act, aiact-rec-54-en, 2024-06-12 — https://overview.legal/posts/93790*

As biometric data constitutes a special category of personal data, it is appropriate to classify as high-risk several critical-use cases of biometric systems, insofar as their use is permitted under relevant Union and national law. Technical inaccuracies of AI systems intended for the remote biometric identification of natural persons can lead to biased results and entail discriminatory effects. The risk of such biased results and discriminatory effects is particularly relevant with regard to age, ethnicity, race, sex or disabilities. Remote biometric identification systems should therefore be classified as high-risk in view of the risks that they pose. Such a classification excludes AI systems intended to be used for biometric verification, including authentication, the sole purpose of which is to confirm that a specific natural person is who that person claims to be and to confirm the identity of a natural person for the sole purpose of having access to a service, unlocking a device or having secure access to premises. In addition, AI systems intended to be used for biometric categorisation according to sensitive attributes or characteristics protected under Article 9(1) of Regulation (EU) 2016/679 on the basis of biometric data, in so far as these are not prohibited under this Regulation, and emotion recognition systems that are not prohibited under this Regulation, should be classified as high-risk. Biometric systems which are intended to be used solely for the purpose of enabling cybersecurity and personal data protection measures should not be considered to be high-risk AI systems.

## Recent developments

### De AI-wet is niet voldoende: we moeten de gevaarlijke hiaten dichten die misbruik mogelijk maken en de rechten van mensen schenden.

*Source: European Digital Rights, 2025-11-13 — https://overview.legal/posts/51727*

Hoewel de AI-wetgeving van de EU tot doel heeft om AI-systemen met een hoog risico te reguleren, wordt deze ondermijnd door belangrijke uitzonderingen die hun ongecontroleerde toepassing mogelijk maken in de context van nationale veiligheid en handhaving van de wet. Deze uitzonderingen riskeren onder meer het mogelijk maken van grootschalige surveillance van protesten en discriminerende migratiepraktijken. Om dit te voorkomen, heeft de EDRi-partner Danes je nov dan aanbevelingen gepubliceerd voor Slovenië om strengere nationale beschermingsmaatregelen en transparante toezichtsmechanismen in te voeren. De post "De AI-wetgeving is niet..."

## Literature

### Transparency Discourse on Digital Platforms: A Comparative Textual Analysis of Platform Reports and Regulatory Texts in the EU and Türkiye

*Source: Lectio Socialis, 2026-07-16 — https://overview.legal/posts/132111 — original: https://doi.org/10.47478/lectio.1921434*

This study examines transparency reporting in digital platform governance through a comparative analysis of platform reports, the European Union’s Digital Services Act (DSA), and Türkiye’s Law No. 7253. Drawing on surveillance capitalism, disciplinary power, and critical platform studies, the research employs systematic qualitative content analysis using MAXQDA software. The analysis covers 65 transparency reports and two regulatory texts published by Meta, X (formerly Twitter), YouTube, and Tik

### Eu regulatory ecosystem for ethical AI

*Source: AI and Ethics, 2025-06-02 — https://overview.legal/posts/53866 — original: https://doi.org/10.1007/s43681-025-00749-x*

Abstract AI applications raise complex ethical, legal, and security challenges that demand comprehensive and coordinated governance at multiple levels. In this paper, we examine how key European Union (EU) regulatory frameworks, such as the AI Act, GDPR, and NIS2, interact to set standards for AI security, functionality, and ethical performance. By comparing the objectives and requirements outlined in these regulatory instruments, we identify points of convergence that encourage a holistic appro

### A Comparative Analysis of the EU AI Act and the Colorado AI Act: Regulatory Approaches to Artificial Intelligence Governance

*Source: International Journal of Computer Applications, 2024-09-26 — https://overview.legal/posts/132613 — original: https://doi.org/10.5120/ijca2024923954*

International Journal of Computer Applications (0975 – 8887) Volume 186 – No. 38 , September 2024 23 A Comparative Analysis of the EU AI Act and the Colorado AI Act: Regulatory Approaches to Artificial Intelligence Governance Mayur Jariwala School of Computer and Information Sciences, University of the Cumberlands, Williamsburg, KY, USA ABSTRACT This comparative study examines the EU AI Act and the Colorado AI Act, focusing on their regulatory approaches to artificial intelligence. The EU AI Act provides a comprehensive framework with a risk - based classification, emphasizing transparency, accountability, and the protection of fundamental rights across diverse sectors. It aims to set a global benchmark for AI governance, influencing international standards. The Colorado AI Act targets high - risk AI systems, prioritizing consumer protection, fairness, and the prevention of algorithmic discrimination. It mandates detailed documentation, ri sk management, and transparency measures to ensure ethical AI deployment. This analysis explores the impacts of each act on innovation, industry practices, and consumer protection, as well as their potential global influence. The findings highlig

### Regulatory Responses to Data Breaches: Evaluating the Effectiveness of GDPR and CCPA in Consumer Protection

*Source: International Journal of Social Sciences and Public Administration, 2025-01-23 — https://overview.legal/posts/132539 — original: https://doi.org/10.62051/ijsspa.v6n1.22*

In the digital age, data breaches have become a significant threat to consumer privacy, prompting the implementation of stringent data protection regulations worldwide. This paper evaluates the effectiveness of two prominent regulatory frameworks, the General Data Protection Regulation (GDPR) in the European Union and the California Consumer Privacy Act (CCPA) in the United States, in safeguarding consumer data and responding to data breaches. Through a comparative analysis of their key provisio

## Related topics

- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals
- **Infringement Reporting Procedures and Mechanisms** — https://overview.legal/topics/infringement-reporting-procedures-ai
  This new topic is needed because the content specifically addresses the procedures, mechanisms, and requirements for reporting infringements of AI Act requireme
- **Artificial Intelligence** — https://overview.legal/topics/ai
  AI systems and their implications for data protection
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities
- **AI Value Chain Actors and Roles** — https://overview.legal/topics/ai-value-chain-actors
  The content focuses on responsibilities distributed across different actors in the AI value chain. A dedicated topic for understanding the various actors, their
- **High-Risk AI Classification** — https://overview.legal/topics/high-risk-ai-classification
  The content specifically addresses classification rules for high-risk AI systems under the AI Act, which is a distinct regulatory concept requiring its own dedi

---
Generated by overview.legal · https://overview.legal/topics/infringement-reporting-protection-framework · 2026-08-22
