Skip to main content
News Directory 3
  • Business
  • Entertainment
  • Health
  • News
  • Sports
  • Tech
  • World
Menu
  • Business
  • Entertainment
  • Health
  • News
  • Sports
  • Tech
  • World

CEPD Notice 28/2024: AI Data Processing

March 22, 2025 Catherine Williams Health
News Context
At a glance
  • An examination of the European Data⁤ Protection Board's guidelines on AI ⁢model anonymity and data protection.
  • European data protection authorities‍ are grappling with the complexities of artificial intelligence, notably concerning the use of personal data in AI model training.
  • It's important to note⁤ that an AI model, while a crucial algorithm within an AI system, does not constitute an entire AI system ⁣on it's own.
Original source: tnpconsultants.com

Navigating Data Privacy: anonymity in AI⁤ Model Growth and Deployment

Table of Contents

  • Navigating Data Privacy: anonymity in AI⁤ Model Growth and Deployment
    • Circumstances for Anonymity
    • Evaluating Anonymity Claims
      • AI Model Design:
      • AI Model Analysis:
      • AI Model Testing and Attack Resistance:
      • Documentation and Risk Assessment:
    • Legitimate Interest as a Legal Basis
    • Mitigating Risks in AI Model Development
    • Mitigation in the Deployment⁤ Phase
    • Impact of Illegal Data Processing
  • Navigating Data privacy: Anonymity in AI Model Growth and Deployment
    • Frequently Asked Questions about AI Model⁢ Anonymity and data Protection
      • 1.What is the core concern regarding data privacy and AI models?
      • 2. When is an AI model considered “anonymous” ‍under GDPR, and why is this important?
      • 3. What are the key criteria for determining if an AI model is truly anonymous?
      • 4. What are some examples⁤ of AI models ⁤that are not considered anonymous?
      • 5. What steps should be taken to evaluate claims of AI model anonymity?
        • AI Model Design:
        • AI Model Analysis:
        • AI Model Testing and Attack‍ Resistance:
        • Documentation and risk‍ Assessment:
    • data Protection in AI model ⁢Lifecycle
      • 6. What legal basis can AI developers use for model training?
      • 7. What are some risk mitigation strategies during the AI model development phase?
      • 8. What are specific mitigation considerations for the AI model deployment phase?
      • 9. what are the⁣ implications of illegal data processing during AI model development?

An examination of the European Data⁤ Protection Board’s guidelines on AI ⁢model anonymity and data protection.

March 22, 2025

European data protection authorities‍ are grappling with the complexities of artificial intelligence, notably concerning the use of personal data in AI model training. At the request of the Irish data protection authority, guidelines have been issued covering ‍the “development phase” and the “deployment phase” of AI models trained using personal data.

It’s important to note⁤ that an AI model, while a crucial algorithm within an AI system, does not constitute an entire AI system ⁣on it’s own.

Circumstances for Anonymity

A ⁣simple claim of anonymity is insufficient to exempt an AI ‍model from⁢ the General Data Protection Regulation (GDPR).Demonstrating that an AI model,developed using⁢ personal data,is indeed anonymous falls under the principle of accountability.

Weather an AI model achieves anonymity requires a case-by-case assessment based on specific criteria. Examples ⁤include:

  • AI models designed ‍to infer data about individuals different from those whose data was used for training.
  • Generative AI models refined from vocal recordings ⁤to mimic a person’s voice.
  • AI ⁣models not intentionally designed to produce information related to natural persons. The European Data Protection ⁣Board (EDPB) considers that learning data can be “captured” within the model’s parameters and potentially extracted.

If⁤ information relating to identified or identifiable ⁤individuals has been used to train the model and ⁣can be ⁢obtained from the AI model⁤ through ⁣means reasonably likely to be used, the ⁤model cannot be considered anonymous. For an AI model to be considered anonymous,the probability of direct extraction must be insignificant,considering potential reuse or involuntary disclosure. The evaluation considers:

  1. Characteristics of learning data, the AI model, and the learning procedure.
  2. The context in which the AI model is disseminated.
  3. Additional information that could enable identification.
  4. The cost and time ⁤required to obtain this additional information.
  5. available technology and technological advancements.

Evaluating Anonymity Claims

Elements to consider when evaluating a controller’s ⁤anonymity claim include:

AI Model Design:

  • Selection of training data sources.
  • Data readiness and minimization.
  • Use of robust‍ development methods, such as ⁣regularization to improve generalization and reduce overfitting, and privacy-preserving techniques ⁤like differential Privacy.
  • Measures to reduce the probability of obtaining personal data from requests.

AI Model Analysis:

  • Documentary‍ audits assessing measures to limit identification probability, such as code review reports and theoretical analyses.

AI Model Testing and Attack Resistance:

  • Consider the scope, frequency, quantity, and⁣ quality of tests conducted, including:
    ‍ ⁢

    • attribute and belonging inference.
    • Exfiltration.
    • Data regurgitation.
    • Model inversion.
    • Reconstruction attacks.

Documentation and Risk Assessment:

  • information‍ relating to AI privacy impact assessments (AIPDs).
  • Advice from the Data protection Officer (DPO).
  • Information on technical and organizational ⁤measures taken to reduce identification probability, including risk assessments.
  • Documentation⁣ demonstrating the ⁣AI model’s theoretical resistance to re-identification techniques.

Legitimate Interest as a Legal Basis

The EDPB has stated that legitimate interest can be used as a legal basis by AI developers for model training, as long as a three-step test is passed. It is necessary to achieve⁤ a⁢ balance of⁣ interests, and publishing⁤ this balance improves ⁢openness and equity.

Mitigating Risks in AI Model Development

During the AI ‍model ⁤development⁣ phase, measures to mitigate risks include:

  • Pseudonymization: Preventing data combination ⁤based on individual identifiers.
  • Data⁣ masking: ⁢ Replacing real data with false data during training.
  • Measures facilitating individual rights:
    • Respecting a reasonable time between data collection and‍ use.
    • Offering ⁢an unconditional “opt-out” ⁣option.
    • Allowing individuals to exercise their right to erasure, even when ⁣specific GDPR conditions do not apply.
    • Allowing individuals to submit complaints concerning data regurgitation.
  • Transparency measures:
    • Publishing accessible communications beyond the requirements of GDPR articles 13 or 14.
    • Using media campaigns, email information campaigns, graphic visualizations, FAQs, transparency labels, model cards, and annual transparency reports.
  • Specific risk mitigation for web scraping:
    • Eliminating data from ⁣publications that may include personal data presenting⁣ risks.
    • Excluding certain data categories or sources.
    • Excluding collection from websites opposed to content reuse for AI training.
    • Imposing time-based collection limits.
    • Creating an exclusion list managed by the controller.

Mitigation in the Deployment⁤ Phase

Specific considerations for mitigation measures in the deployment phase include:

  • Technical measures to prevent storage, regurgitation, or generation of personal data, especially in generative AI models, and to mitigate the risk of illegal reuse.
  • Measures facilitating the exercise of individual rights, such as⁤ erasing personal data from‍ model output data.
  • Ensuring the‍ DPO is ⁤involved.

Impact of Illegal Data Processing

The possible impact of illegal data processing during AI model development can be considered in three scenarios:

  • Scenario 1: Personal data is kept in the⁣ model and processed later by the same controller. Evaluation should be on a case-by-case basis, considering the impact on the lawfulness of subsequent treatment.
  • scenario 2: Personal data is kept in the model and processed by ⁢another controller. The deploying controller must demonstrate the lawfulness of the treatment.
  • Scenario 3: The controller ensures the model is anonymized before further processing. The lawfulness of treatment in the deployment phase should not be affected by the initial illegality.

Navigating Data privacy: Anonymity in AI Model Growth and Deployment

An examination of the European Data Protection Board’s guidelines on AI model anonymity and data protection.

March 22, 2025

European data‍ protection authorities are grappling with the complexities of artificial intelligence, notably concerning the use of personal data in AI model training.At the request of the Irish⁣ data protection authority, guidelines‍ have been issued covering the “growth phase” and the⁣ “deployment phase” of AI models trained using personal data.

It’s important to note that an AI model, while a⁤ crucial algorithm within an AI ⁢system, does not constitute an entire AI system on its own.

Frequently Asked Questions about AI Model⁢ Anonymity and data Protection

1.What is the core concern regarding data privacy and AI models?

The primary concern revolves around the use of personal data in training AI models. The European Data Protection Board (EDPB) has established ⁣guidelines to address⁤ the lifecycle of AI models, specifically focusing on the development and deployment phases.

2. When is an AI model considered “anonymous” ‍under GDPR, and why is this important?

An AI⁢ model is not automatically considered anonymous simply because an ⁢AI model is involved. Demonstrating that an AI ⁢model, developed using personal data, is indeed anonymous ⁢falls under the principle of accountability.Models are considered anonymous if they are unlikely to identify the individuals whose data was used in its‍ creation. For ‍an AI model to be considered anonymous, the probability of direct extraction of personal data must be insignificant, considering potential reuse or involuntary disclosure.

3. What are the key criteria for determining if an AI model is truly anonymous?

Determining whether an AI model achieves⁣ anonymity requires a case-by-case assessment based on specific criteria. These include:

  • Characteristics of learning data, the AI model and the learning procedure.
  • The context in wich the AI model is disseminated.
  • Additional information that could enable identification.
  • The cost and time required to obtain this additional information.
  • Available technology and technological‍ advancements.

4. What are some examples⁤ of AI models ⁤that are not considered anonymous?

The EDPB considers that⁢ AI models trained with personal data cannot, in all cases, be considered anonymous. examples ⁢include, but are not limited to:

  • AI models designed to infer data about individuals different from those whose data was used for training.
  • Generative AI models refined from vocal recordings to mimic a person’s voice.
  • AI models not intentionally designed to produce information related to natural persons. The EDPB considers that ⁢learning data can be “captured” within the model’s parameters and potentially extracted.

5. What steps should be taken to evaluate claims of AI model anonymity?

Evaluating a controller’s anonymity claim involves several elements:

AI Model Design:

  • Selection of training data sources.
  • Data readiness and minimization.
  • Use of robust development methods, such as regularization to improve generalization and reduce overfitting, and privacy-preserving techniques like differential Privacy.
  • Measures to reduce the probability of⁣ obtaining personal data from requests.

AI Model Analysis:

  • Documentary audits assessing measures to limit identification probability, such as code review reports and theoretical analyses.

AI Model Testing and Attack‍ Resistance:

  • Consider the scope, frequency, quantity, and quality of ‍tests conducted, including:
    • attribute and belonging inference.
    • Exfiltration.
    • Data ⁣regurgitation.
    • Model‍ inversion.
    • Reconstruction attacks.

Documentation and risk‍ Assessment:

  • Information ⁣relating to AI privacy impact assessments (AIPDs).
  • Advice from the Data protection Officer (DPO).
  • Information on technical and organizational measures taken to reduce identification probability, including risk assessments.
  • Documentation demonstrating the AI model’s theoretical resistance to re-identification techniques.

data Protection in AI model ⁢Lifecycle

6. What legal basis can AI developers use for model training?

The EDPB has stated that legitimate interest can be used as a legal basis by AI developers for model training, provided that a three-step test is passed.

7. What are some risk mitigation strategies during the AI model development phase?

Measures to mitigate risks include:

  • Pseudonymization: Preventing data combination based on individual identifiers.
  • data masking: Replacing real data with false data during training.
  • Measures facilitating individual rights:
    • Respecting a reasonable time between data collection and use.
    • Offering an unconditional “opt-out” option.
    • Allowing individuals to exercise their right to erasure, even when specific GDPR conditions do not apply.
    • Allowing individuals to submit⁤ complaints concerning data⁤ regurgitation.
  • Transparency measures:
    • Publishing accessible communications beyond the requirements of GDPR articles 13 or 14.
    • Using media campaigns, email information campaigns, graphic visualizations, FAQs, transparency labels, model cards, and annual transparency reports.
  • Specific ⁤risk mitigation for web scraping:
    • Eliminating data from publications that ⁢may include personal data presenting risks.
    • Excluding certain data categories or sources.
    • Excluding collection from websites opposed to ⁤content reuse ⁢for AI training.
    • Imposing ⁢time-based collection limits.
    • Creating an exclusion list managed by the controller.

8. What are specific mitigation considerations for the AI model deployment phase?

Considerations include:

  • Technical measures⁣ to prevent storage, regurgitation, or generation of personal data, especially in generative AI ⁣models, and to mitigate the risk of ⁢illegal ⁤reuse.
  • Measures facilitating the exercise of individual rights, such⁣ as ⁤erasing personal data ⁣from model output data.
  • Ensuring the DPO is involved.

9. what are the⁣ implications of illegal data processing during AI model development?

The impact can vary across three scenarios:

  • Scenario 1: Personal data is kept in the⁣ model and processed later by the same controller.⁤ The evaluation should be⁣ on a case-by-case basis, considering the impact on the lawfulness of subsequent treatment.
  • Scenario 2: Personal data is kept in the model and processed by another controller. The deploying controller must demonstrate the lawfulness ‍of the treatment.
  • scenario 3: The controller ensures the model is‍ anonymized before further processing. The lawfulness of treatment ⁣in the deployment phase should not be affected by the initial illegality.

Share this:

  • Share on Facebook (Opens in new window) Facebook
  • Share on X (Opens in new window) X

Related reading

  • 1 in 8 Cancer Cases Linked to Infections, New Study Finds
  • Florida Sues Pfizer for Deceptive COVID-19 Vaccine Marketing

Related

Search:

News Directory 3

News Directory 3 catalogs US newspapers, news services, newsstands and digital news outlets across all 50 states. Browse local publishers by city, state, or topic, and follow current headlines linked back to their original sources.

Quick Links

  • Disclaimer
  • Terms and Conditions
  • About Us
  • Advertising Policy
  • Contact Us
  • Cookie Policy
  • Editorial Guidelines
  • Privacy Policy

Browse by State

  • Alabama
  • Alaska
  • Arizona
  • Arkansas
  • California
  • Colorado

© 2026 News Directory 3. All rights reserved.
For contact, advertising, copyright, issues email: office@newsdirectory3.com