# Notified Body Information Obligations — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/notified-body-information-obligations
> Sources are cited per item. Verify against the official texts before relying on them.

This specific topic is needed to comprehensively cover the distinct information obligations that notified bodies must fulfill under the AI Act, including their duties to disclose assessment findings, report non-compliance, notify authorities of incidents, and provide transparent information to stakeholders.

## Overview

## Legal Framework

Notified bodies operating under the AI Act are subject to layered information obligations that extend beyond mere conformity assessment. Article 13 of the AI Act establishes the core transparency and information-sharing duties owed to deployers, requiring that high-risk AI systems be accompanied by instructions for use, documentation, and information that enables meaningful oversight. Notified bodies must communicate assessment findings to providers, flag non-conformities, and where an AI system fails to meet requirements, refuse or withdraw the EU technical documentation assessment.

Beyond provider-facing duties, notified bodies must inform the notifying authority and the AI Office of significant changes affecting their competence, suspensions or withdrawals of certificates, and any circumstances that may cast doubt on a provider's compliance. These obligations mirror the structured transparency reporting seen in the Digital Services Act under Articles 15 and 42, where providers of intermediary services must publish periodic reports on content moderation and algorithmic decisions — establishing a regulatory pattern of mandatory, documented disclosure to supervisory authorities.

The GDPR framework reinforces these duties where notified bodies process personal data during assessments. Article 13 GDPR requires transparent information to data subjects, and Article 15 GDPR grants access rights that intersect with notified body activities — particularly when assessment findings touch on individuals' data. Member States may impose professional secrecy obligations under Article 15(2) that qualify how broadly assessment findings can be disseminated, creating a tension between transparency and confidentiality that notified bodies must navigate.

## Key Developments

Dutch administrative case law illustrates the practical thresholds for adequate information provision. In one ruling, the court upheld a controller's right to request specification when a data subject sought access to a large volume of records — establishing that information obligations are not unlimited where the scope is genuinely broad. In another matter, the court found information provision deficient because the controller failed to disclose specific intelligence indicators, did not provide copies of referenced decisions, and omitted personal data handling information — demonstrating that partial or incomplete disclosure constitutes a violation.

The Malta Data Protection Commissioner's enforcement actions reinforce these standards. A €20,000 fine was imposed where a controller's data protection policy failed to meet transparency requirements alongside a failure to inform a data subject. A separate €4,000 fine addressed both unsolicited messaging and a non-compliant privacy policy. These decisions establish that transparency obligations are enforced independently — a deficient policy alone triggers liability even absent other violations.

The February 2026 AI Omnibus proposals seeking to weaken AI Act transparency provisions signal ongoing political pressure that notified bodies should monitor, as any dilution of reporting standards would directly affect their compliance burden.

## Practical Guidance

- **Document every assessment finding with a clear communication chain**: Notified bodies must maintain auditable records of what was communicated to providers, authorities, and the AI Office, tracing each disclosure to the specific legal basis under Article 13 AI Act and related provisions.

- **Establish escalation protocols for non-conformity**: When assessment reveals non-compliance, notified bodies must have predefined procedures for refusing or withdrawing certification and simultaneously notifying the notifying authority — delays or omissions create enforcement exposure.

- **Reconcile transparency with professional secrecy**: Where Member State law imposes confidentiality obligations under Article 15(2) GDPR-equivalent provisions, notified bodies must classify information into tiers — fully disclosable, restricted, and legally protected — and apply access controls accordingly.

- **Ensure information provided to deployers is operationally sufficient**: Following the Dutch court standard, information must be complete enough to enable meaningful human oversight; partial disclosure that omits material findings fails the legal threshold.

- **Monitor legislative amendments actively**: The AI Omnibus proposals demonstrate that information obligations remain politically contested; notified bodies should build compliance systems that are modular enough to accommodate tightened or relaxed reporting requirements without structural redesign.

## Legislation (full text of key provisions)

### Recital 153 — national competent authorities designation

*Source: AI Act, aiact-rec-153-en, 2024-06-12 — https://overview.legal/posts/93988*

Member States hold a key role in the application and enforcement of this Regulation. In that respect, each Member State should designate at least one notifying authority and at least one market surveillance authority as national competent authorities for the purpose of supervising the application and implementation of this Regulation. Member States may decide to appoint any kind of public entity to perform the tasks of the national competent authorities within the meaning of this Regulation, in accordance with their specific national organisational characteristics and needs. In order to increase organisation efficiency on the side of Member States and to set a single point of contact vis-à-vis the public and other counterparts at Member State and Union levels, each Member State should designate a market surveillance authority to act as a single point of contact.

## Guidance

### Guidelines 8/2020 on the targeting of social media users

*Source: EDPB, edpb-guidelines-on-the-targeting-of-social-media-users, 2021-04-13 — https://overview.legal/posts/38073 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-82020-on-the-targeting-of-social-media-users_en*

The EDPB adopted Guidelines 8/2020 on the targeting of social media users to clarify the roles, responsibilities, and legal obligations of the various actors involved in social media targeting, including social media providers, targeters, and users. The guidelines analyze different targeting mechanisms—based on provided, observed, and inferred data—and address controller determinations, legal bases, transparency requirements, DPIAs, and the processing of special categories of data. No fines are imposed, as this is interpretive guidance intended to assist stakeholders in achieving GDPR compliance.

### Guidelines 02/2021 on virtual voice assistants

*Source: EDPB, edpb-guidelines-on-virtual-voice-assistants, 2021-07-07 — https://overview.legal/posts/38077 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-022021-on-virtual-voice-assistants_en*

A virtual voice assistant (VVA) is a service that understands voice commands and executes them or mediates with other IT systems if needed. VVAs are currently available on most smartphones and tablets, traditional computers, and, in the latest years, even standalone devices like smart speakers. VVAs act as interface between users and their computing devices and online services such as search engines  or  online  shops.  Due  to  their  role,  VVAs  have  access  to  a  huge  amount  of  personal...

## Recent developments

### AI Omnibus: Reject the proposals to undermine transparency in the AI Act

*Source: European Digital Rights, 2026-02-11 — https://overview.legal/posts/52497 — original: https://edri.org/our-work/ai-omnibus-reject-the-proposals-to-undermine-transparency-in-the-ai-act/*

The European Commission’s dangerous and misguided Digital Omnibus proposal includes a dangerous rollback of transparency requirements in the AI Act. 60 civil society organisations, independent public authorities and individuals, including EDRi, urge EU lawmakers to reject a change that would risk weakening enforcement, legal certainty, and the protection of fundamental rights, while offering negligible benefits for companies. The post AI Omnibus: Reject the proposals to undermine transparency in

## Literature

### General-Purpose AI under the EU AI Act: A Conceptual Allocation of Duties across the Value Chain

*Source: SCRIPTed A Journal of Law Technology & Society, 2026-06-30 — https://overview.legal/posts/132370 — original: https://doi.org/10.2218/scrip.12300*

This article examines how the final version of the EU Artificial Intelligence Act (“AI Act”, adopted 2024) allocates obligations across the AI value chain, with a focus on general-purpose AI (“GPAI”) or foundation models. It proposes a taxonomy of key actors – foundation model providers, fine-tuners, integrators, and deployers – and analyses the interfaces between them, including documentation tools (model cards, system cards) and logging requirements. Building on principles of control, foreseea

### Italy’s Artificial Intelligence Act and Global AI Governance: The EU Model’s Practice and Prospects

*Source: Law and Economy, 2026-02-25 — https://overview.legal/posts/132619 — original: https://doi.org/10.63593/le.2788-7049.2026.03.004*

The Italian Artificial Intelligence Act, enacted on September 17, 2025, represents the first comprehensive national implementation of the European Union’s AI Act. This study examines the Italian legislation through the theoretical lens of multi-level governance, analyzing its dual function as both a “bridging legislation” that translates EU framework into domestic practice and a site of significant regulatory innovation. Through detailed textual analysis and case studies, particularly in healthc

### A Comparative Analysis of the EU AI Act and the Colorado AI Act: Regulatory Approaches to Artificial Intelligence Governance

*Source: International Journal of Computer Applications, 2024-09-26 — https://overview.legal/posts/132613 — original: https://doi.org/10.5120/ijca2024923954*

International Journal of Computer Applications (0975 – 8887) Volume 186 – No. 38 , September 2024 23 A Comparative Analysis of the EU AI Act and the Colorado AI Act: Regulatory Approaches to Artificial Intelligence Governance Mayur Jariwala School of Computer and Information Sciences, University of the Cumberlands, Williamsburg, KY, USA ABSTRACT This comparative study examines the EU AI Act and the Colorado AI Act, focusing on their regulatory approaches to artificial intelligence. The EU AI Act provides a comprehensive framework with a risk - based classification, emphasizing transparency, accountability, and the protection of fundamental rights across diverse sectors. It aims to set a global benchmark for AI governance, influencing international standards. The Colorado AI Act targets high - risk AI systems, prioritizing consumer protection, fairness, and the prevention of algorithmic discrimination. It mandates detailed documentation, ri sk management, and transparency measures to ensure ethical AI deployment. This analysis explores the impacts of each act on innovation, industry practices, and consumer protection, as well as their potential global influence. The findings highlig

## Related topics

- **Conformity Body Notification** — https://overview.legal/topics/conformity-assessment-body-notification
  This new topic is needed because the content specifically addresses the application and notification procedures for conformity assessment bodies under the AI Ac
- **Notified Bodies for AI Systems** — https://overview.legal/topics/notified-bodies-ai
  This topic is needed to comprehensively cover the role, responsibilities, and obligations of notified bodies in the AI Act conformity assessment framework, incl
- **Conformity Assessment for AI Systems** — https://overview.legal/topics/conformity-assessment-ai
  Provider obligations typically include conformity assessment procedures and documentation requirements, which is a specific compliance mechanism under the AI Ac
- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals
- **Authority Cooperation** — https://overview.legal/topics/cooperation-with-authorities-ai
  This new topic is needed because the AI Act establishes specific cooperation and coordination mechanisms between AI providers/deployers and competent authoritie
- **AI Value Chain Actors and Roles** — https://overview.legal/topics/ai-value-chain-actors
  The content focuses on responsibilities distributed across different actors in the AI value chain. A dedicated topic for understanding the various actors, their

---
Generated by overview.legal · https://overview.legal/topics/notified-body-information-obligations · 2026-08-22
