Article 5 is the only one in this series where non-compliance would be current, not future. It has been in force since 2 February 2025, admits no exception for size or sector, and has no calendar left to wait for.
That changes how it reads. Everything else covered here is preparation; this is a list of things you don't do, today.
There are eight points, from a) to h). The two the Digital Omnibus added are different and have their own article; this one covers the original eight, with a test that's usually missing: which ones can touch an ordinary private company.
The ones that don't touch anyone who isn't looking for it
Four are ruled out just by reading them.
d) Predicting crimes through personality profiling — with an express exception to support human assessment based on “objective and verifiable facts”. e) Facial recognition databases built by untargeted scraping from the internet or CCTV. h) Real-time remote biometric identification in publicly accessible spaces for law-enforcement purposes. And f), emotion inference in the workplace and in education institutions — with an exception for medical or safety reasons — already covered here for healthcare, education and staffing, because it's the one that crosses operations the most.
And one usually assumed dangerous that isn't
This one is worth pausing on, because intuition gets it wrong.
Point g) is often cited in connection with biometric access control. Read exactly what it prohibits:
“…biometric categorisation systems that categorise individually natural persons based on their biometric data to deduce or infer their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation.”
What's prohibited is inferring sensitive attributes from biometrics. A turnstile that compares a fingerprint or a face against a register to open a door infers nothing on that list: it checks who you are. That's a different operation, and point g) doesn't reach it.
That doesn't leave it unregulated — it processes biometric data, with everything the GDPR requires — but it isn't a prohibited practice, and treating it as one confuses a serious obligation with an absolute infringement.
The three that can touch you, and where the threshold sits
a) Subliminal or purposefully manipulative techniques
The territory is advertising and AI-driven interface design. But the literal wording sets four cumulative conditions: subliminal techniques or “purposefully manipulative or deceptive techniques”, that “materially” distort behaviour, “appreciably” impairing the ability to make an informed decision, and that cause — or are reasonably likely to cause — “significant harm”.
Ordinary advertising persuasion doesn't reach that bar, and saying otherwise would be alarmist. What does come close is deliberately deceptive design, optimised by AI, to get someone to sign up for something they didn't want, when the result causes them serious harm.
The word that decides it is “significant”. Without harm of that magnitude, there's no point a).
b) Exploiting vulnerabilities
The most reachable of the three, and the least examined. It prohibits exploiting vulnerabilities arising from “their age or disability, or a specific social or economic situation” to materially distort behaviour, in a way that causes significant harm.
Ad targeting by economic situation exists and is common. The line is whether that vulnerability is exploited to induce a harmful decision: offering expensive financing precisely to whoever the model flags as financially vulnerable sits much closer to this point than to any high-risk debate.
c) Social scoring
It's associated with the public sector, and the literal wording doesn't restrict it to that sector. It prohibits evaluating or classifying people “over a certain period of time” based on their social behaviour or personality characteristics, when the resulting score causes:
“(i) detrimental or unfavourable treatment… in social contexts that are unrelated to the contexts in which the data was originally generated or collected” — or “(ii) detrimental or unfavourable treatment… that is unjustified or disproportionate to their social behaviour or its gravity.”
Scenario (i) is the one that can appear without any bad intent: a score built from data in one context — payment behaviour, use of a service, internal activity — that ends up determining how that person is treated in another, unrelated context. When two systems cross and the output of one conditions something unconnected, this point is worth a look.
What to do with this, which is little and specific
You don't need a project. You need three questions about the systems you already have.
Does any of them segment or decide using age, disability or economic situation as a signal? If the answer is yes, the next question is what decision it produces and who it harms.
Is any internal score about people used outside the context in which it was generated? That's scenario (i) of point c), and it shows up when tools get integrated, not when they get bought.
Does any system infer attributes — rather than verify identity — from biometric data? That, and only that, is point g).
And a final note that orders the reading: Article 5 isn't documented or managed. There's no mitigating measure, no impact assessment, no room for proportionality. Whatever falls inside it stops being used. It's the only part of the Regulation where the work isn't being able to explain what you do, but not doing it.
Content in line with Article 5 of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 (Official Journal of the EU, 24 July 2026).
This article is for informational purposes only and does not constitute legal advice.