The EU data supervisor demanded more guarantees to use sensitive information in AI training.

The European body demanded to recover the criterion of "strict necessity" and limit the exceptional use of sensitive information to cases where there is a serious risk of discrimination or real harm if the biases of the models are not corrected.

4 minutes

20230926 EP 156485A EVD 0330 (1)

20230926 EP 156485A EVD 0330 (1)

Add DEMÓCRATA to Google

Ask FREN

Published

4 minutes

Most read

The Twenty-Seven will sit down again this Friday at the table to study the latest proposal from the Irish Presidency of the Council on the use of personal data for the training of artificial intelligence systems. This is one of the last pending issues for approval of the so-called "Digital Omnibus". In the offices of the European Data Protection Supervisor (EDPS), they are closely monitoring the processing of the file that will reform the current General Data Protection Regulation (GDPR).

In an opinion issued in January together with the European Data Protection Committee, the body already firmly warned against the reduction of guarantees for fundamental rights. The document paid special attention to both privacy and data protection at a time when they may be seen "as a toll to achieve the simplification of the rules." The draft sent by Ireland to the capitals endorses the use of personal data in artificial intelligence tools, including the phases of training, testing, validation, and operation of the models, when it is based on "a valid legal basis of the GDPR and complies with specific safeguards."

However, the consulted diplomatic sources indicate that the processing of sensitive data will only be justified exceptionally if its presence is incidental, unintentional, and residual within the training or validation datasets. The European Data Protection Supervisor "in principle" supported the proposal to extend the exception that allows the processing of special categories of data, such as those related to health or ethnic origin, to detect and correct biases in all AI systems and models.

The body demanded to restore the standard of "strict necessity" that was originally included in the AI Act, rejecting in any case the downgrade of the draft to a mere "necessity and proportionality." In the negotiations of the Omnibus, the Supervisor also recalled that the processing of sensitive data is generally prohibited by the GDPR. Therefore, it called for "very narrowly" defining the cases in which the exception may apply to AI systems that are not high-risk, conditioning them on the existence of a serious risk of discrimination or real harm if those biases are not corrected.

The risk of biases in AI

The agency understands that if AI models are trained with uncorrected biased datasets, the resulting model may generate serious discriminations. That is why it would support in principle allowing the exceptional use of sensitive data to detect and correct these risks.

Similarly, the Supervisor warns that removing key controls in the training phase or reducing transparency obligations, such as model registration, under the argument of reducing costs for companies, may create undesirable incentives for developers to evade critical analysis of the impact of their models.

The agency's position is based on the need to maintain specific guarantees even when the purpose of the processing is to identify and correct biases. The possibility of using sensitive data would therefore not imply a general authorization, but rather an exception linked to specific conditions.

The Irish Presidency defends that the approach does not imply lowering the guarantees that the European data protection framework recognizes for citizens. The proposal aims, instead, to clarify through a specific legal basis under what circumstances personal data can be used during the various phases of development and training of artificial intelligence systems. The compromise text opens the door to this type of processing when it is supported by a legitimate interest, although in no case would it be exempt from the other conditions and obligations established by the GDPR.

The debate thus focuses on delimiting what can be considered a legitimate interest in the context of AI and what scope this legal basis would have for the use of personal data in the training of models. From the Irish perspective, the proposal would not alter one of the central rules of the GDPR: data controllers would still have to identify and justify the legal basis that supports each operation with personal data.

The Prime Minister of Ireland, Micheál Martin, and the President of the European Commission, Ursula von der Leyen, shake hands at the end of a press conference in the Main Quadrangle of University College Cork Liam Mcburney/PA Wire/dpa
The Prime Minister of Ireland, Micheál Martin, and the President of the European Commission, Ursula von der Leyen, shake hands at the end of a press conference in the Main Quadrangle of University College Cork Liam Mcburney/PA Wire/dpa -

Among the options contemplated by the Regulation is the consent of the affected party, but also other legal bases, such as precisely the legitimate interest.

The negotiators also emphasize that the safeguards provided by the GDPR to protect the rights and freedoms of individuals would remain fully in force. The objective of the change would not be, therefore, to create a parallel regime for artificial intelligence, but to specify how existing rules should be applied when data processing occurs within the framework of the development and training of these systems.

The proposal now faces the test of the capitals

Ireland will bring its proposal to the Council working group this Friday after having previously consulted the capitals, which will still be able to propose changes or objections. The progress of the file will depend on the level of consensus reached. If there is a sufficient basis, the text could move to Coreper, even with some articles still open for permanent representatives to try to resolve the pending differences.

The meeting will thus serve to determine whether the proposal is mature enough to continue its processing and advance to the next levels of negotiation. The debate ultimately faces two objectives that Ireland considers compatible: to provide legal certainty to the development of artificial intelligence and to maintain the guarantees of the European data protection framework.

More key points, information and questions with FREN

AI-GENERATED CONTENT

What is the parliamentary status of the Digital Omnibus processing and what are the next steps for its approval in the EU?

The so-called Digital Omnibus is not a single regulation, but a package of several regulatory proposals with which the European Commission aims to simplify and update the EU's “digital acquis” (data protection, AI, cybersecurity, open data, etc.). As of September 2026, the package is in the midst of the co-decision phase: the European Parliament and the Council are working in parallel on the different “dossiers” and in some a preliminary political agreement has already been reached, while others are still under negotiation.

In terms of parliamentary status, it is useful to separate three main pieces:

  • Digital Omnibus on AI (adjustments to the Artificial Intelligence Act): here Parliament and Council have reached a provisional political agreement on simplification measures, new prohibitions (for example, AI-based “nudification” applications) and the postponement of certain obligations of the AI Act. According to the Commission and Parliament, this agreement is part of the seventh simplification package (“digital omnibus”) and must still be formally adopted by both institutions before being published in the Official Journal of the EU.
  • Digital Omnibus on data and cybersecurity: this is the core of what many actors simply call “Digital Omnibus.” The Commission's proposal, presented in November 2025, modifies and streamlines a broad block of rules (GDPR, Single Digital Gateway Regulation, data protection regulation for EU institutions, e-Privacy Directive, NIS2, CER Directive…) and repeals, among others, the Regulation on the free flow of non-personal data and the Data Governance Regulation. According to notes from the Commission and European data protection authorities, this proposal is currently being debated in Parliament and Council, with opinions already issued by the European Data Protection Board and the European Data Protection Supervisor. There is no closed agreement yet: the Council is working on compromise texts (the most recent, under the Irish presidency, introduces for example the controversial GDPR Article 88b) and Parliament is still developing its position.
  • Digital Omnibus linked to the AI Act (“AI simplification”) within the digital simplification package: Parliament has already approved its negotiation mandate for this subpackage in committee, and the Parliament itself indicates that, after ratification in Plenary, trilogues with the Council have started or will start to agree on the final text. Meanwhile, the Commission has announced the intention that the new simplified rules come into force in time to align with the AI Act implementation schedules.

From a procedural point of view, the package is therefore in an intermediate-advanced phase:

  • The European Commission has already exercised its initiative and registered the regulatory proposals in November 2025 (digital simplification package/Digital Omnibus).
  • The European Parliament has already held the first Plenary debate on the package and several committees (Internal Market, Civil Liberties, etc.) have adopted positions to serve as a basis for the trilogues.
  • The Council discusses compromise texts presidency by presidency; the latest relevant move is the draft from the Irish presidency that reopens sensitive issues regarding GDPR and personal data processing for AI, which shows that the Council's position is not yet closed.

The formal next steps for the Digital Omnibus (in its different parts) to be definitively approved in the EU are the usual ones of ordinary legislation:

  • 1. Approval of Parliament's position in Plenary on each proposal, based on prior committee work. Some already have an approved mandate; in others, the committee report must still be submitted to Plenary to set the Parliament's position.
  • 2. Closure of the Council's “general approach”, that is, the common position of the Member States for each regulation in the package, including changes on GDPR, NIS2, open data, etc.
  • 3. Trilogues between Parliament, Council, and Commission for each Digital Omnibus dossier, where a compromise text is negotiated. In the AI component, a provisional political agreement has already been announced; in the data/cybersecurity component, the debate remains open and this is where many reservations from data protection authorities and digital rights organizations concentrate.
  • 4. Formal approval of the agreed text by:
    • the European Parliament Plenary (final vote), and
    • the Council of the EU (adoption by the competent ministers).
  • 5. Publication in the Official Journal of the European Union. From there, each Digital Omnibus regulation will set an entry into force date and, if applicable, implementation phases (for example, new dates for high-risk AI obligations or for centralizing incident notifications).

Until these steps conclude — in particular, the trilogue phase and formal adoption — the Digital Omnibus will remain a package under processing. Some elements (especially those linked to the AI Act) are already closer to the goal, while the major data and cybersecurity reform continues in a politically very sensitive negotiation.

What are the legal powers of the European Data Protection Supervisor and how is this position appointed?

The European Data Protection Supervisor (EDPS) is the independent authority responsible for ensuring that the institutions, bodies, and agencies of the European Union respect the fundamental right to personal data protection. Its statute and functions are mainly set out in Regulation (EU) 2018/1725.

Main legal powers of the EDPS

The EDPS exercises a set of powers very similar to those of a national data protection authority, but limited to the institutional scope of the EU (Commission, Parliament, Council, agencies, and other Union bodies). Among its core powers are:

  • Compliance supervision: it controls that all EU institutions, bodies, offices, and agencies process personal data in accordance with Regulation (EU) 2018/1725, just as national authorities do regarding the GDPR. This includes reviewing internal policies, processing records, and security measures.
  • Investigative powers: it can carry out investigations on its own initiative or following complaints. It is empowered to request information, access data and systems, and examine documentation held by EU institutions.
  • Complaint handling: any natural person can file a complaint with the EDPS if they consider that an EU institution or body has violated their data protection rights. The EDPS analyzes the case, may investigate, and issues a reasoned decision.
  • Corrective and ongoing supervision powers: it can issue warnings, reprimands, and orders to institutions (for example, ordering that a processing be brought into compliance, suspended, or that a data set be deleted). It can also require notification and proper management of data security breaches.
  • Advisory functions: it must be consulted by the Commission, Parliament, Council, or other institutions when they draft legislative proposals or internal acts affecting personal data processing. It issues opinions and recommendations to ensure that new rules respect the data protection framework.
  • Prior control and advice on high-risk processing: for certain particularly sensitive or high-risk processing carried out by EU institutions (for example, large-scale European information systems), the EDPS can perform prior analyses, make observations, and require additional safeguards.
  • European cooperation: the EDPS is part of the European Data Protection Board (EDPB) along with national authorities. It participates in drafting guidelines, opinions, and binding decisions on issues affecting the entire European Economic Area, especially when EU institutions are involved.
  • Promotion of a data protection culture: it promotes training and awareness within EU institutions, develops guidance, and encourages good practices in privacy and information security.

Appointment procedure of the EDPS

The European Data Protection Supervisor is an independent single-person body. Regulation (EU) 2018/1725 establishes an appointment system designed to reinforce its autonomy vis-à-vis the institutions it supervises.

The essential elements of the appointment procedure are:

  • Nominating authority: the EDPS is appointed by common agreement of the European Parliament and the Council. That is, both co-legislators jointly adopt the appointment decision.
  • Proposal and preliminary selection: before that final agreement, the European Commission organizes an open selection procedure based on merit and professional competence. Usually, a call is published, applications are evaluated, and the Commission prepares a shortlist of suitable candidates.
  • Choice among candidates: based on that list, Parliament and Council negotiate and decide whom to appoint as Supervisor (and, if applicable, as Deputy Supervisor). Parliament usually holds public hearings with candidates to assess their suitability.
  • Term duration: the term is five years and may be renewed once. This relatively long duration aims to ensure continuity and independence from the ordinary political cycles of EU institutions.
  • Independence and competence requirements: the chosen person must provide full guarantees of independence and possess recognized experience and knowledge in data protection and EU institutions and procedures. During their term, they cannot seek or accept instructions from any institution or body.
  • Dismissal and removal: the EDPS can only be removed by the Court of Justice of the European Union, and only in serious circumstances (incapacity to perform duties, serious misconduct, etc.). This protection strengthens their autonomy against political pressures.

In summary, the EDPS combines supervisory, investigative, corrective, and advisory powers over all personal data processing carried out by EU institutions and bodies, and its appointment system — by agreement of Parliament and Council, with strong independence guarantees — is designed to act as a truly autonomous regulator within the European legal order.

What legal requirements must be met for Member States to apply exceptions to the processing of sensitive data under the GDPR?

The GDPR starts from a clear rule: the processing of special categories of data (the so-called sensitive data: health, ethnic origin, political opinions, biometric data, etc.) is in principle prohibited (Art. 9.1). It is only allowed if one of the exceptions in Art. 9.2 applies. Several of these exceptions expressly depend on there being a legal basis in Union or Member State law, and this is where national laws come into play.

For a Member State to introduce exceptions or authorizations for the processing of sensitive data, a series of legal requirements must be met, mainly derived from Arts. 9.2, 9.4, and 23 of the GDPR and the case law of the CJEU:

1. Clear legal basis in a norm of sufficient rank

The exception must be supported by a Union or Member State law that:

  • Is accessible and published (law, regulation, or other normative provision with sufficient publicity).
  • Is clear and precise, so that the citizen can foresee in which cases their sensitive data may be processed and under what limits.
  • Has appropriate rank and normative quality given the impact on fundamental rights (in practice, a formal law or equivalent norm is usually required).
2. Legitimate purpose and important public interest

National authorizations are only valid if they respond to a legitimate purpose recognized by the GDPR. Article 9.2 itself provides, among others, the following bases subject to Union or Member State law:

  • Labor and social security law (Art. 9.2.b): e.g., recognition of benefits, occupational risk prevention.
  • Vital interests of the data subject or another person (9.2.c) when the data subject cannot consent.
  • Activities of foundations, associations, churches, or political parties (9.2.d) regarding their members.
  • Important public interest (9.2.g), which must be defined in national law.
  • Public health (9.2.i), such as epidemic control or health planning.
  • Archiving purposes in the public interest, scientific or historical research, or statistical purposes (9.2.j).

The national law must specify that purpose and fit it into one of these cases, without inventing new grounds for exception outside the GDPR.

3. Respect for the essence of the right and proportionality principle

According to Art. 23 GDPR and the EU Charter of Fundamental Rights, any limitation on the right to data protection must:

  • Respect the essence of the right: it cannot empty it of content nor authorize indiscriminate processing of sensitive data.
  • Be necessary and proportionate to achieve the pursued general interest purpose.
  • Be limited to what is strictly necessary, considering if there are less intrusive measures available.
4. Specific safeguards for data subjects

The GDPR requires that the national regulation introducing exceptions incorporates adequate and specific safeguards (Arts. 9.2.b, g, i, j and 9.4). These usually include:

  • Purpose limitation: use only for the specific purposes provided by law.
  • Data minimization: process only the data strictly necessary.
  • Access restriction: only authorized personnel subject to confidentiality obligations.
  • Defined retention periods and, if applicable, anonymization or pseudonymization.
  • Technical measures such as encryption, access control, and operation logging.
  • Impact assessments and, if appropriate, appointment of a data protection officer.
  • Respect, as far as possible, for rights of access, rectification, and objection, except for legitimate restrictions provided by law.
5. No lowering of the GDPR protection level

Article 9.4 allows Member States to maintain or introduce additional conditions or limitations for processing sensitive data, but not to reduce the minimum guarantees of the GDPR. That is:

  • They can strengthen protection (for example, requiring additional requirements for processing health data).
  • They cannot expand exceptions to the point of nullifying the general prohibition rule or the other GDPR principles.

In summary, for a Member State to apply exceptions to the processing of sensitive data, it must rely on a clear legal basis, aimed at a legitimate public interest purpose, respect the essence of the right to data protection, pass a proportionality test, and establish specific and effective safeguards for the affected individuals, never lowering the minimum standard set by the GDPR.

Play

Test your knowledge with FREN!

How much do you know about this topic? Answer the following 3 questions.

What is the main concern of the European Data Protection Supervisor regarding the Irish draft on the use of personal data in AI?

Question 1 of 3

What condition does the European Data Protection Supervisor require for the use of sensitive data in AI training?

Question 2 of 3

What legal basis does the Irish proposal mention to justify the use of personal data in AI?

Question 3 of 3