The EDPB's opinion was prompted by the Irish Data Protection Commission, which requested an assessment of key data protection issues in the development and use of AI models. The EDPB, which is tasked with ensuring the consistent interpretation of the General Data Protection Regulation (GDPR) within the EU, addresses three core points in its opinion: the requirements for the anonymity of AI models, the requirements for the lawful processing of personal data by AI models—both during the development and deployment phases—and the consequences of unlawful data processing by such models.
The EDPB defines AI models as essential components of AI systems that are created through certain training mechanisms (so-called „Machine Learning“) are created based on extensive data sets. If these data sets contain personal data, it must be examined whether the AI model used can nevertheless be considered anonymous. This is particularly doubtful for models that are intended to reproduce or make available personal data with which they were fed during their development.
Checking the anonymity of AI models
The EDPB deals in detail with the question under what circumstances an AI system can be qualified as anonymous. Even if an AI model is not aimed at processing or outputting such information, personal data (e.g., from the training dataset) can remain in the processing parameters of the model. According to the EDPB, it is therefore incumbent upon the data protection authorities to examine whether a specific AI model can actually claim anonymity for itself. This must take into account the characteristics of the training data, the context of the model's use, and available technologies to extract data from the AI model.
Anyone who wants to use an AI model without being bound by the requirements of the GDPR—such as the obligations to maintain records of processing activities, to inform data subjects, or to conclude a data processing agreement with the AI model provider—will therefore have to prove the anonymity of the AI model used vis-à-vis the supervisory authority. This requires proving that personal data can neither be extracted from the model nor obtained through queries.
Processing of personal data by AI models
Documentation and transparency
If proof of anonymity fails or if the processing of personal data is intended anyway when using an AI model, the controller must comply with the provisions of the GDPR. On the one hand, this means that the purpose of the processing as well as the nature and scope of the processed data must be documented. On the other hand, the processing must be transparent and comprehensible for the data subjects whose data are being processed.
The EDSA attaches particular importance to this transparency. Because of the complexity of AI model technology, related information about data processing should be provided to data subjects in an accessible, understandable and user-friendly form.
Legal basis and legitimate interest
Legal bases such as consent, performance of a contract, or compliance with a legal obligation will rarely apply when using AI models. Therefore, the EDPB discusses in detail what conditions must be met so that data processing by AI models can be based on legitimate interest as a legal basis. For this purpose, the EDPB provides for a three-step test:
- the pursued interest must be legitimate (such as the development of a chatbot or fraud detection);
- the processing must be necessary for this purpose (it must therefore be examined whether there are processing options that infringe less deeply on the rights of the data subjects);
- the interests of the data subjects (in the protection of their privacy, their freedom of expression, or against discrimination) must not override the interests of the controller in the processing.
A distinction must be made here between individuals whose data is contained in the training dataset and individuals whose data is processed during the deployment phase. The question of whether the data subjects must reasonably expect the type of processing of their data by the AI model plays an equally important role in balancing interests (which must not be confused with the fulfillment of transparency requirements under the GDPR).
Risk minimization
Controllers are therefore particularly called upon to minimize risks for data subjects. Security measures such as pseudonymization, masking of personal data, or their replacement with fake data come into consideration for this purpose. In this context, the EDPB designates such measures as particularly important that enable data subjects to easily exercise their rights – such as an appropriate waiting period between the collection of data and its subsequent use, as well as the possibility of an unconditional opt-out.
For specific risks in AI models – such as web scraping – specific protective measures may also become necessary (in the case of web scraping, for example, the exclusion of certain data sources or the consideration of robots.txt or ai.txt files). In addition, measures should be taken during the deployment phase to prevent the storage or generation of personal data as far as possible.
Legal consequences of GDPR violations
It should be noted at the outset that the unlawful processing of personal data during the development phase of an AI model can have significant implications for the lawfulness of subsequent processing operations. In the event of unlawful data processing by AI models, national supervisory authorities have the authority to investigate, issue orders, and impose sanctions. The supervisory authority may order corrective measures, impose fines (of up to EUR 20 million or 4% of the group’s and worldwide annual turnover), or even order the deletion of the entire dataset or the AI model.
Furthermore, affected individuals can assert their rights to information, erasure, objection, or restriction of the processing of their data not only by lodging a complaint with the data protection authority, but also by enforcing them through the courts. If affected individuals have suffered material or non-material damage as a result of the unlawful processing of their data by an AI model, they can also claim compensation.
Conclusion
Companies must carefully examine whether their AI systems comply with the high requirements of European data protection. The transparency and documentation required in the EDPB's opinion, as well as the three-tier testing procedure for legitimate interests, are groundbreaking. In view of the drastic potential sanctions, a careful implementation of these requirements is essential. For further information and individual consultation, please contact Stefan Knotzer and Roman Taudes at the phone number 01 3912345 or by email office@atb.law available.