In 2024, the landscape of data protection in the European Union (EU) and the United Kingdom (UK) has been heavily influenced by ongoing discussions and regulatory actions surrounding Artificial Intelligence (AI), especially focusing on Generative AI and Large Language Models (LLMs). Regulatory authorities have shifted their emphasis from aggressive enforcement to consultations and guidance, seeking clarity on how current data protection laws apply to emerging AI technologies.
Central to these discussions is the issue of what lawful basis can be utilised under the General Data Protection Regulation (GDPR) when acquiring personal data to train AI models. A significant development occurred with the Court of Justice of the EU (CJEU) ruling in the case of Koninklijke Nederlandse Lawn Tennisbond v Autoriteit Persoonsgegevens (C-621/22). The CJEU determined that commercial interests could be deemed a legitimate interest for data control purposes, overturning the restrictive stance previously held by the Dutch Data Protection Authority. This judgment provides valuable insights into interpreting 'legitimate interest' under Article 6(1)(f) GDPR, underscoring the importance of considering less restrictive means and the data subject’s reasonable expectations.
In response, regulatory bodies such as the Information Commissioner's Office (ICO) in the UK and France's CNIL are exploring the viability of relying on legitimate interests for AI training, contingent upon meeting a three-part test. Conversely, the Dutch Data Protection Authority maintains a stricter stance, viewing web scraping for AI data acquisition as usually infringing GDPR regulations.
Further examples demonstrate the varied application of GDPR principles to AI technologies. The Belgian Data Protection Authority recognised a bank's reliance on legitimate interests for utilising payment transaction data to train an AI model for personalised discounts, distinguishing between consent-based personalisation and legitimate interest-based model training.
Moreover, Ireland’s Data Protection Commission (DPC) has been active, particularly highlighted by its intervention regarding the use of social media data for training AI models. In one notable case, the DPC mandated a halt on the processing of public posts by X (formerly Twitter) for AI training, highlighting that such regulatory interventions can be as impactful as monetary fines.
Despite the ongoing deliberations, the European Data Protection Board (EDPB) has yet to provide concrete guidelines on using legitimate interests for AI training. Its interim report on ChatGPT suggests that comprehensive guidance remains forthcoming.
Another area of concern is determining whether LLMs themselves are considered personal data. The Hamburg Data Protection Authority opined that merely storing an LLM does not equate to personal data processing per the GDPR, leaving ambiguity over how rights like data erasure could apply to tokenised AI models.
In the UK, the ICO’s intervention in the deployment of Snapchat's MyAI tool underscored the importance of thorough Data Protection Impact Assessments (DPIAs) under Article 35 GDPR. The ICO's actions led to improvements in how Snap documented and mitigated risks associated with its AI technologies.
As the year progresses, it remains imperative for companies leveraging AI technologies to follow evolving guidance from data protection authorities. There is a clear indication that regulators are digging deeper into understanding new technologies’ impacts, urging the need for careful consideration of lawful bases and impact assessments in AI deployment. Future clarifications, especially from the EDPB, are highly anticipated to further illuminate the regulatory framework governing AI and related data protection challenges.
Source: Noah Wire Services