Generative AI: EDPS publishes guidance for use

Guidance for generative AI in the EU.
Categories:

The European Data Protection Supervisor (EDPS) recently published initial guidance on the use of generative artificial intelligence (Generative AI, GAI). It is primarily aimed at EU institutions. However, the data protection obligations it contains for generative AI can also be useful for companies.

Data protection tips for generative AI

The guide aims to provide practical advice on how to Processing of personal data in connection with the use of GAI systems. This is intended to ensure the data protection-friendly use of such systems without violating the fundamental rights of the data subjects.

The good news right at the beginning of the guide is that all EU institutions can develop and use their own generative AI solutions. Alternatively, they can also use solutions available on the market for their own use. Only the legal framework conditions must be complied with.

The guidelines emphasize the need for careful risk assessment and continuous monitoring when using AI systems. This concerns, among other things, minimizing data collection and ensuring data accuracy. In addition, safeguarding the rights of data subjects, such as the right to information, Correction or Deletion of your data.

The role of the data protection officer (DPO) is particularly emphasized. He or she must ensure that the GAI systems comply with data protection requirements.

In addition, the facilities must Technical and organizational measures to take the Data security and to prevent abuse by Third to prevent.

Admissibility of the Processing personal data in AI systems

The guidance explicitly points out that providers of generative AI models can claim a legitimate interest under the General Data Protection Regulation as a legal basis for data processing. This applies in particular to the collection of data used for the development of the system, including the training and validation processes.

The ECJ has laid down three conditions for the Processing of personal data is lawful:

  1. the pursuit of a legitimate interest by the person responsible for the Processing responsible (or by a third party);
  2. the necessity of Processing personal data for the purposes of the legitimate interest pursued;
  3. The interests or fundamental freedoms and rights of the data subject shall not take precedence over the legitimate interest of the data controller. Processing responsible (or a third party).

However, the EDPS acknowledges this: 'In the case of data processing by generative AI systems, many circumstances can influence the balancing process. This may affect both the data subjects and the data controllers responsible for the Processing lead to legal uncertainty for those responsible.

Reading tip: AI Act came into force on August 1 - here's what happens next!

Transparency and fairness in the use of GAI systems

The guidance emphasizes the importance of Transparency when informing the persons concerned about the Processing of their data by generative AI systems. Institutions must provide clear and comprehensive information about the data sets used, how the algorithms work and the potential impact on data subjects.

In addition, precautions must be taken to ensure that GAI systems operate fairly and without discriminatory bias. This requires regular review and adjustment of the systems to identify and correct distortions.

Conclusion: The use of Generative AI offers numerous opportunities for the EU institutions, but requires careful attention to data protection requirements. The guidelines published by the EDPS Guidelines are a first step towards ensuring that these technologies are used in compliance with data protection regulations. The EDPS intends to implement these Guidelines over time in order to meet the constantly changing challenges.

Source: First EDPS Orientations for ensuring data protection compliance when using Generative AI systems

Tags:
Share this post :