Ready for the new Google Consent Mode v2? Learn more »
News

Can AI be GDPR compliant? What to look out for


A robotic hand reaching for a human hand

In early February, Italian data protection authority Garante asked AI chatbot Replica to stop processing citizens’ personal data. The purpose of the AI ​​software was to be a virtual “AI friend” for social interactions that did not require age verification. The DPA found that the AI ​​bot had processed children’s personal data without their consent.

As AI technologies advance, especially after the launch of ChatGPT and Google Bard, more similar cases might appear.

And before you unknowingly find yourself in such a situation, it would make a lot of sense to learn about the AI-related provisions of the GDPR :

Personal data:

AI systems are designed to collect large amounts of data, including personal data, which is then analyzed and processed. According to the GDPR, certain requirements must be met for this. The focus is on transparency, legality and security in the processing of personal data. AI systems must therefore be developed with these data protection requirements in mind. Users must be informed about what data is collected and how it is used. And they must be able to rely on AI systems to ensure the confidentiality, integrity and availability of their personal data.

profiling

According to the GDPR, individuals have the right not to have their data used for “profiling”. Profiling is an automated process designed to predict an individual’s behaviour, preferences or interests based on data collected from them. Therefore, AI systems should be designed in such a way that the user is clearly informed about how the profiling is used.

consent

Similar to the processing of personal data, the consent aspect of the GDPR requires that the user give their express, conscious and voluntary consent to the processing of their personal data. Therefore, AI systems must be designed in such a way that they collect such consent and provide users with comprehensive information about the data collected, the disclosure of the data to third parties and the possibility to withdraw consent at any time.

Conclusion:

AI developers must ensure that their systems are developed with privacy in mind and that users are fully informed about the processing of their personal data. GDPR compliance is critical to instilling trust in AI systems and ensuring they are used in a way that respects citizens’ rights to privacy and data protection.


more comments

General

Newsletter 09/2024

New features: Data Subject Rights (DSR) tool The GDPR provides that those affected (such as website visitors, customers or other persons whose data is processed) enjoy certain rights. This includes, in particular, the right to query their rights and obtain information about the data processed. The rights include, among others: Our new DSR tool now […]
consentmanager logo with the text ‘consentmanager is a Google CMP Gold Partner’ on the left side. Gold medal with a ribbon next to a shield with the text ‘Certified CMP Partner’ in Google brand colours.
News

consentmanager achieves Gold Status as Google CMP Partner

consentmanager is pleased to announce that it has been named a Gold Tier CMP Partner within Google’s Consent Management Platform (CMP) Partner Program. This recognition is awarded to us with consideration of the following criteria: The latest development in the Google Partner Program makes CMP implementation easier for our customers. Now you can integrate your consent banner directly […]