Spain brings to Brussels its red lines for training AI with personal data

Digital Transformation demands that synthetic and anonymized data take priority and defends that citizens should be able to oppose the use of their personal information to train models.

4 minutes

fotonoticia 20260504191503 1920

fotonoticia 20260504191503 1920

Add DEMÓCRATA to Google

Ask FREN

Published

4 minutes

Most read

Spain wants to tighten the guarantees to prevent technology companies from using Europeans' personal data without limits to train artificial intelligence models. The Government conditions its support for the new simplification of the digital regulation being negotiated by the EU on the text establishing clear limits to protect citizens' privacy.

Sources from the Ministry for Digital Transformation explain to DEMÓCRATA that Spain is defending this position in the European negotiations on the Digital Omnibus, the reform with which Brussels intends to simplify part of the community legislation on data, cybersecurity, and artificial intelligence. The Commission proposed the package to reduce burdens and provide greater legal clarity for the development of AI, including the processing of personal data.

The Spanish position is based on a premise: facilitating the development of artificial intelligence should not become a "free-for-all" to use personal information. The Government argues that innovation and competitiveness can advance without lowering the guarantees currently offered by European data protection regulations.

Synthetic data before personal information

One of the main changes that Spain demands directly affects the data used to train the models. The Executive wants companies to prioritize the use of synthetic and anonymized data before using real personal information.

When the use of real data is necessary, companies would have to justify why they need to resort to it. For the Government, claiming the existence of a "legitimate interest" should not be enough on its own to open the door to the indiscriminate processing of personal information.

Sources cite as an example an artificial intelligence system intended to detect cancer. Its development might require real data to achieve an adequate level of reliability, but that necessity would not eliminate the obligation to introduce guarantees regarding the information used, including its anonymization.

The debate is not minor. The European proposal aims to provide greater clarity on the use of personal data to develop AI, while European data protection authorities have warned that regulatory simplification should not translate into a reduction of fundamental rights.

A European criterion to determine when data is anonymous

Spain also intends to prevent each company from deciding on its own when it considers that certain data has ceased to be personal and, therefore, falls outside certain protections.

To this end, Digital Transformation proposes that the European Data Protection Board (EDPB) be responsible for establishing through a binding opinion for all member states common technical criteria for anonymization and generation of synthetic data.

The intention is to have a common reference throughout the EU and reduce the margin for companies to individually interpret when a set of information can be considered sufficiently anonymized.

Precisely, one of the sensitive points of the European reform is the definition of personal data and the conditions under which certain sets of information can be shared and used when the recipient lacks the ability to re-identify the individual.

A right to say "no" to AI training

The second major front that Spain raises directly affects citizens. The Government demands to recover an unconditional right of opposition so that anyone can refuse to have their data used to train artificial intelligence.

The Spanish proposal seeks for this right to be effective and not merely formal. When removing certain data from the training of a model proves technically unfeasible, companies should adopt alternative measures that provide equivalent protection and limit the processing of that information to what is strictly necessary, according to sources from the Ministry.

The objective is to maintain decision-making power over personal information even in a context where AI models require increasingly larger amounts of data for their development.

Spain rejects that competing in AI requires relaxing the GDPR

The Spanish position directly addresses one of the debates accompanying the revision of European digital rules: how far can regulation be simplified to favor competitiveness without reducing the protection of citizens.

Digital Transformation rejects that Europe has to choose between developing a competitive artificial intelligence industry and maintaining the guarantees of the General Data Protection Regulation (GDPR). The Government's approach is to establish "clear, proportionate, and verifiable" rules that provide legal certainty to companies without leaving the decision about what personal information they can use in their hands.

European data protection authorities have expressed a similar concern during the processing of the Digital Omnibus. The EDPB and the European Data Protection Supervisor support regulatory simplification but have warned that some changes could affect existing guarantees.

Spain thus brings to the European negotiation three main conditions: priority for synthetic and anonymized data, common European criteria on anonymization, and an effective right for citizens to oppose the training of models with their data. According to sources from Digital Transformation conveyed to DEMÓCRATA, the incorporation of these conditions will determine Spanish support for the new simplification of European digital rules.