The European Union is studying modifying its data protection rules to facilitate that artificial intelligence companies can use personal information without prior consent from citizens. The measure appears in the latest commitment text from the Irish presidency of the Council on the so-called Digital Omnibus, the package with which Brussels intends to simplify a good part of its digital legislation, according to the document published by noyb, the European organization specialized in privacy and digital rights founded by Max Schrems
The change would directly affect the General Data Protection Regulation (GDPR) and could have consequences for companies that develop large artificial intelligence models, such as OpenAI, Anthropic, Google, or Meta. The document expressly opens the door for the processing of personal data to develop and operate AI systems or models to be carried out on the basis of the "legitimate interest" of the company, as stated in article 6.1.f of the GDPR.
This would allow certain data to be processed without requesting the express consent of each user, although it would not equate to automatic authorization to use any information. The presidency's text maintains the obligation to verify that the company's interests do not override the fundamental rights and freedoms of the affected person and requires that there be an adequate legal basis for the processing.
The proposal is still under negotiation and does not currently modify the obligations of companies or the rights of citizens. Ireland holds the rotating presidency of the EU Council during the second half of 2026 and has among its priorities advancing in the legislative packages for digital simplification.
What Europe wants to change
The central point of the discussion is found in the new article 88 bis of the GDPR that appears in the commitment text distributed by the Irish presidency. The provision establishes that the processing of personal data in the context of the development and operation of an AI system or model can be carried out for a legitimate interest of the controller, in accordance with article 6.1.f of the Regulation.
The difference is important. Currently, legitimate interest can already be used as a legal basis in certain data processing, but it requires passing a test in which the pursued interest, the necessity of the processing, and its impact on the rights of the person are analyzed.
The European Data Protection Board (EDPB) already established in its opinion on AI models that legitimate interest can serve as a legal basis in certain cases, but it must be studied individually. Among the elements that must be assessed are the origin of the data, the relationship between the company and the citizen, the context in which they were obtained, and whether the affected person could reasonably expect them to be used later to develop artificial intelligence.
The change being negotiated seeks to provide greater legal certainty to AI companies by expressly incorporating that possibility into the Regulation.
The Irish text itself, however, retains important limitations. Business interest could not prevail when the fundamental rights and freedoms of the citizen weigh more, it pays specific attention to minors, and maintains the situations in which another European or national norm expressly requires consent.
Germany proposes to go a step further
Within the negotiation, there is also a proposal from Germany that is considerably broader. Berlin proposes that the processing of personal data intended for the training and technical functioning of a system or model of AI be presumed directly as a legitimate interest.
The difference is not minor. The Irish commitment expressly recognizes that a company can attempt to rely on legitimate interest, but it maintains the balancing structure of the GDPR. The German proposal aims to introduce a legal presumption favorable to processing for AI.
Germany also proposes to presume compatible with the original purpose the processing of information that would have been collected initially for other objectives, always subject to certain safeguards. This could facilitate the reuse to train models of large databases accumulated over the years.
If a formulation of this type succeeds, one of the main consequences would be precisely the possibility of reusing historical information without necessarily having to return to each citizen to request new consent. Its final scope will depend, however, on how the regulation is drafted and on the guarantees that survive the negotiation.
What would happen to sensitive data
The reform also addresses one of the biggest problems posed by training large models: the presence within enormous datasets of especially protected information.
The text contemplates an exception for those cases in which special categories of data appear incidentally and residually during the development or technical operation of an AI. Companies would have to adopt prior technical and organizational measures aimed at preventing that information from being collected.
If those data still appear in the datasets used for training, testing, or validating a system, the responsible party would have to delete them without delay. When doing so is technically impossible or requires a manifestly disproportionate effort, they should remain protected to prevent them from being reused, appearing in the model's responses, or being communicated to third parties.
The exception would not cover, however, situations in which the use of that sensitive information is deliberate and necessary for the pursued objective. In those cases, the legal bases specifically provided by the GDPR would still be necessary.
The right to object remains on the table
The presidency's document seeks to accompany the opening of legitimate interest with guarantees for users. Among them are measures for data minimization, transparency, and protection against the disclosure of information retained by the models.
During the negotiation, an unconditional right to object to the processing of personal data for these purposes has also been raised. The issue is particularly relevant because legitimate interest works differently from consent: instead of initially needing a "yes" from the citizen, processing can begin if there is a valid legal basis, and subsequently, among other guarantees, the rights recognized by the GDPR come into play.
It is precisely here where a good part of the real scope of the reform is played out. The simpler it is for companies to adhere to the legitimate interest and the more difficult it is for citizens to know that their data is being used and to exercise their rights, the greater the shift will be from a model based on prior consent to another supported by processing with the possibility of opposition.
It also changes what is considered personal data
The Digital Omnibus opens another debate of great magnitude. The presidency proposes to clarify that information related to a person does not necessarily have to be considered personal data for all companies or entities simply because another organization can identify that person.
The proposal establishes that the consideration would depend, among other factors, on the reasonably available means for the specific entity to identify the individual. The text also expressly addresses pseudonymized data and the circumstances under which they could cease to be considered personal for certain recipients.
The issue is especially relevant for AI because it directly determines what information is subject to the guarantees of the GDPR.
European data protection supervisors have already expressed reservations about the reform. The European Data Protection Board and the European Data Protection Supervisor have warned during the processing of the Digital Omnibus about the risks of modifying the concept of personal data and consider it unnecessary to introduce a specific provision on legitimate interest for AI.
Privacy organizations warn of a loss of rights
The privacy advocacy organization noyb, founded by activist Max Schrems, has warned about the consequences of the new text and argues that the reform could allow large companies to reuse enormous amounts of information accumulated over the years to develop their models.
The organization interprets that the change would particularly benefit large tech companies that already have gigantic amounts of information from social networks, digital services, and other platforms. It also questions whether a regulation designed to simplify European rules ends up modifying central elements of data protection.
It is, in any case, the interpretation of this organization regarding a negotiation that is still open. The document from the presidency itself expressly maintains the balance between the interests of companies and the fundamental rights of citizens, as well as the application of the rest of the requirements of the GDPR.
A reform still far from being definitive
Nothing proposed currently allows OpenAI, Anthropic, Google, Meta, or other companies to start automatically using any data from Europeans. The current GDPR continues to apply in its current terms.
The document dated September 3 is a revised text of commitment from the presidency of the Council, prepared to continue negotiations among the member states. The Council still needs to set its position, and the European Parliament also participates as a co-legislator in the file.
The debate faces two objectives that Brussels is trying to reconcile since the explosion of generative artificial intelligence: to facilitate access to the necessary data for European companies and AI developers to compete while maintaining the level of privacy protection that has characterized the European regulatory model.