TLDRocket
Sign in

EU Could Legimitate Use of Personal Data for AI Training

Trending Topics Jakob Steinschaden

EU talks could let AI firms use personal data on a legal basis, and Germany wants that rule to be much stronger. Privacy groups say it could flip GDPR protection into a broad AI training permit.

Based on reporting by Trending Topics, Jakob Steinschaden — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

The EU’s Digital Omnibus has moved into the Council’s hard part, and leaked internal papers show where the fight is headed: personal data, AI training, and the line between simplification and a rewrite of GDPR. The Vienna privacy group noyb published two Council documents, one from the Irish Presidency and one with German drafting suggestions, both marked “LIMITE” and not meant for public release.

At the centre is a new clause on using personal data “in the context of the development and operation” of AI systems and models. The Irish compromise keeps that tied to a controller’s “legitimate interest” under GDPR Article 6(1)(f), with a balancing test still in place. It also adds a narrower-sounding idea to the definition of personal data: whether information counts as personal would depend on who holds it and what means that entity has to identify someone.

Germany’s draft pushes much further. It would make the processing of personal data for the training and technical operation of an AI system or AI model a presumed legitimate interest, and would also presume that data collected for other purposes is compatible with AI training. The wording strips out a reference to consent where national law requires it, and weakens a set of safeguards that the Presidency had drafted, including an unconditional right to object.

The most aggressive part lands on data subject rights. Germany’s text says the duties and rights in Articles 14 and 16 to 18 would not apply if compliance is impossible or would take a disproportionate effort. That covers notice for data not collected directly, rectification, erasure and restriction. In exchange, controllers would have to say before training that personal data will be used, explain how objections or corrections can be filed effectively, and then use technical measures to stop disclosure or identification after training.

There are limits in the German proposal, too. It would not apply to systems aimed at identifying, monitoring or evaluating people, or at generating the voice, image or other personal traits of a specific person. Public authorities are excluded, and the rest of the GDPR would still stand. But noyb says the direction is obvious anyway: a rule built around AI rather than a specific purpose could hand large companies a very broad pass to use data they never collected from their own users.

My take — AI-written commentary, not fact-checked reporting

Brussels keeps selling these resets as “simplification,” which is a nice word when the real product is leverage. If a rule starts with a presumption in favour of AI training, privacy law is no longer setting the terms — it’s being asked to mop up afterward. That’s a familiar EU trick: call it clarity, then hope nobody notices the rebalancing.

Read more about this at: Trending Topics

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.