AI and Privacy: What's Allowed and What's Not?

EuropeThu Dec 19 2024
The European Data Protection Board (EDPB) recently stepped in to help clarify how AI models can use personal data without breaking the law. They looked at big questions like whether AI models can be anonymous and if companies need people's consent to use their data. They also discussed what to do with AI models trained on data that wasn't collected legally. The EDPB wants to ensure that AI development follows the rules set by the General Data Protection Regulation (GDPR). AI models can't just be labeled as anonymous and left alone. The Board said that each case needs to be checked individually to see if the model really can't identify people. They suggested ways to make sure data is anonymous, like choosing good sources and using data minimization. Using people's data without their permission might be okay if there's a good reason, like improving a security system. But this needs to be balanced with people's rights. The EDPB said there are steps that can be taken if the balance isn't right, like making data anonymous or letting people opt out. What about AI models built with illegal data? The EDPB said it depends on the situation. If the model doesn't use personal data anymore, it might be okay. But people need to be careful not to break the rules on purpose. An expert warned that the EDPB's opinion might make some people think it's okay to scrape data from the web without following the rules. But the EDPB's guidelines are just one piece of the puzzle, and each country's data protection authority will make their own decisions.
https://localnews.ai/article/ai-and-privacy-whats-allowed-and-whats-not-3bf18994

questions

    Could AI models be used to manipulate public opinion and evade GDPR regulations?
    What are the key considerations for determining if a legitimate interest is an appropriate legal basis for AI development and deployment?
    What are the potential implications for AI ethics and accountability given the EDPB's stance on model anonymity and legitimate interest?

actions