The AI forces a review of data protection rules in the EU: the legal keys of the proposal from Ireland

The commitment text that Ireland will take to the Council maintains the obligations of the General Data Protection Regulation and raises when personal data may be used to develop and train artificial intelligence systems.

8 minutes

ILUSTRACIONES (1200 x 675 px) (1200 x 675 px) (1)

ILUSTRACIONES (1200 x 675 px) (1200 x 675 px) (1)

Add DEMÓCRATA to Google

Ask FREN

Published

8 minutes

Most read

"Buses are always complex. There are many things to take into account," summarizes a high diplomatic source in the corridors of the Schuman roundabout. On the table of the Twenty-Seven continues one of the main reflections of the reform of part of the community digital regulation. This Friday, a new reform file of the General Data Protection Regulation (GDPR) will be submitted for examination by the capitals with the aim of providing greater legal certainty to the use of personal data in the processes of development and training of artificial intelligence systems.

The negotiating team of the Irish Presidency of the Council of the European Union arrives at the meeting defending that the proposal to be debated seeks, precisely, to provide legal clarity to the processing of personal data in the context of AI development, without altering the general protection framework established by the GDPR.

According to what DEMÓCRATA has learned, the idea that Ireland will convey to the room is that the obligations of the General Data Protection Regulation remain, including one of its central and most discussed elements: Article 6, which establishes the legal bases that allow for the lawful processing of personal data.

The member states received the latest draft of the proposal this Monday and "it is still being studied," explain sources from the Spanish Executive. Dublin argues that currently the GDPR does not contain a specific provision regarding the development of artificial intelligence systems nor on how to legally address certain data processing operations linked to these technologies.

Ireland seeks to clear legal uncertainty

The Irish Presidency does not intend to propose, according to its interpretation of the proposal, a departure from the obligations and safeguards provided for users. The declared objective is to introduce a specific legal reference that allows determining under what conditions personal information can be used during the development cycle of AI systems.

The text would allow the processing of personal data for the development and training of these systems "when there is a legitimate interest," although this possibility would be subject to the rest of the requirements established by the GDPR. The central issue, therefore, is to determine what exactly that "legitimate interest" means and how far it can be used as a legal basis to feed artificial intelligence systems.

European Council
European Council -

Ireland explains that the proposal currently under discussion does not modify the obligation of the data controller to select an appropriate legal basis for each processing operation in accordance with the GDPR. That basis could be, for example, the consent of the data subject, but also others provided for in the Regulation, including legitimate interest.

The team responsible for drafting the proposal argues that appropriate measures, safeguards, and protections of the rights and freedoms of data subjects would still be applicable. The change seeks, therefore, to clarify how to fit certain operations related to AI within the existing legal framework.

Spain maintains a more flexible position

Spain maintains in these debates a position that the consulted voices define as "more flexible than other member states", although there has not yet been an attempt to elevate the document to the level of permanent ambassadors.

So far, discussions have remained at a lower scale, within the corresponding working group of the Council. In response to questions from DEMÓCRATA, the Government has avoided commenting on the content of the latest compromise text for the moment. The process is also progressing in parallel to the negotiations of the European Parliament, which is also working on building its own position on the reform.

The adjustment of the legal framework applicable to the processing of personal data in artificial intelligence services responds to a request from the member states derived from the known as "digital omnibus", the reform of part of the European digital legislation that came into force in July.

That modification opened the door to a more specific review of certain issues related to the use of data for the development of AI systems. The request from the capitals has now been translated into a compromise text drafted by the Irish Presidency.

EuropaPress| Minister for Digital Transformation, Oscar López
EuropaPress| Minister for Digital Transformation, Oscar López -

This type of document constitutes a usual tool of the rotating presidencies to try to unlock legislative files. The text of commitment synthesizes the different national positions and tries to bring them closer to a formula likely to gather the consensus of the Twenty-Seven, although it does not yet constitute the definitive result of the negotiation.

The legitimate interest, at the center of the debate

The draft now under discussion makes it clear that the use of personal data in artificial intelligence tools must be backed by a valid legal basis in accordance with the GDPR and accompanied by specific safeguards. The main novelty introduced by Ireland is precisely in the specification of legitimate interest as one of the avenues that could be used for the development and training of AI systems.

The Presidency proposes that recourse to the legitimate interest of the data controller or a third party may be made as long as the fundamental rights and freedoms of the data subject do not prevail. The text pays special attention to cases where the data belongs to minors, for whom reinforced guarantees are contemplated.

Consent constitutes another of the relevant legal bases. The Irish Presidency proposes to maintain its full validity when expressly required by other European Union regulations or by applicable national legislation, as well as when the data controller itself decides to request it. The third avenue contemplated is public interest, which could be applicable to processing carried out by authorities and public bodies in the exercise of their competencies.

The proposed architecture does not eliminate, therefore, the different legal bases provided for by the GDPR. What it aims to do is define more precisely how they can operate in a technological environment in which the massive processing of information constitutes an essential part of the development of AI models.

Minimization, transparency, and right to object

For processing based on legitimate interest to be considered lawful during the lifecycle of an AI system, member states are also discussing a series of additional conditions.

One of them involves evaluating whether the development of the model brings benefits for users or for society. Among the examples being considered are the development of mechanisms aimed at detecting and eliminating discriminatory biases or improving the accuracy and safety of the results generated by the systems.

The capitals are also studying to strengthen the application of the data minimization principle, so that this is taken into account from the phase of selecting sources and during the different stages of training and testing the model.

The logic is that developers cannot indiscriminately process all available information merely because it may potentially be useful for training a system. The processing must be related to the intended purpose and respect the general guarantees of the GDPR.

In addition, there is the obligation to provide clear information to the interested parties about the use of their personal data for the development of AI systems. Ireland has also proposed that users have an unconditional option to oppose their personal data being processed for purposes related to artificial intelligence.

The text also states that developers must respect the indications and technical limitations incorporated in websites or services to restrict the use of certain data by third parties. This involves introducing a specific consideration of the restrictions that content holders may establish in the very process of collection.

The limit of sensitive data

One of the most delicate points of the file affects the processing of special categories of personal data, whose use is subject to reinforced guarantees by the European data protection framework. The latest proposal states that the presence of this type of information in datasets used for training or validation can only be justified exceptionally when it is incidental, unintentional, and residual.

This is information that is especially sensitive related, among other issues, to health, religion, political opinions, or biometric data. Dublin suggests that those responsible for processing may apply techniques aimed at preventing the collection of this type of information. In the event that, despite those measures, sensitive data is detected within the sets used for the development of the system, the responsible party must eliminate it without delay.

The draft, however, contemplates a situation especially relevant for developers: that the deletion of that information is technically impossible or requires a disproportionate effort.

In that case, the destruction of the complete model would not necessarily be imposed. Instead, the responsible party should effectively block and protect the affected data to prevent it from being processed again, used to infer results, or revealed to third parties.

This issue is especially relevant because it introduces a distinction between the specific personal data and the AI model itself. The goal is to prevent the incidental appearance of sensitive information from automatically requiring the dismissal of the entire developed system, as long as effective mechanisms exist to prevent that data from continuing to produce effects.

A text still open before reaching Coreper

Ireland will arrive at the working group meeting on Friday with this proposal in hand, after having previously consulted the mood of the different capitals.

Member States still have room to oppose certain elements of the text or propose new amendments. The next step will depend precisely on to what extent the Presidency considers that there is a sufficient basis to elevate the discussion. Only if a high level of consensus is perceived could the file advance to the table of the permanent representatives of the Twenty-Seven, known as Coreper, to subsequently continue its processing at the ministerial level.

Diplomatic sources consulted by DEMÓCRATA point out, however, that the document could reach the ambassadors even with "one or two articles pending consensus," so that the permanent representatives themselves attempt to resolve those issues.

The file is therefore still in an open phase. The discussion on Friday will not necessarily determine the final text, but it will allow to check to what extent the capitals are willing to accept a formula that seeks to introduce greater legal certainty for the development of AI without altering the general architecture of the GDPR.

"It is also not yet known if the text will be mature for Coreper," says another source present in the negotiations at the Council. That will precisely be one of the main unknowns that the working group's meeting will need to clarify.

Hola, soy Fren. ¿Cómo te ayudo?