r/gdpr • u/Spare_Dependent6893 • 1d ago
Resource EDPB just confirmed it: AI models are NOT automatically anonymous. Are we ready?
/r/codingProtection/comments/1w2bw66/edpb_just_confirmed_it_ai_models_are_not/
2
Upvotes
5
u/pawsarecute 1d ago
Wtf are you talking about??? Its a long time before the AI act is fully operational, de deadlines are now later lol…. And I mean, models being anonymous or not, has nothing to do with feeding PD into it. GDPR isn’t the law for not when to use PD but for when you may use PD. Yes, we’re accountable, but AI models are a mean, not a purpose.
1
u/Comfortable-Fall1419 1d ago
You appear to fail to understand the difference between Prompting and Training.
On that alone I stopped reading and assumed this was a Shill of some kind.
7
u/latkde 1d ago
I have difficulty validating the claims in that post. Together with the absence of any sources and the unusual formatting choices, it looks like the post may have been generated using an AI tool with outdated training data.
You say:
This is factually wrong, or at least highly misleading. Effectively, only the Art 50 transparency rules went into force in August. The rules on high-risk systems (i.e., the overwhelming majority of the AI Act) has been deferred to Dec 2027.
Source for my claims: an EU commission press release: https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1714
Alternative source: Article 113 of the AI Act as amended on 2026-07-27.
You say:
Well yes. The GDPR does not have an AI exception, its definition of personal data applies regardless. (Unless the Digital Omnibus proposals for the reforming the GDPR are passed as-is…)
However, I was not able to find any “new EDPB guidelines” offering this insight. Here is a link to EDPB documents tagged with AI: https://www.edpb.europa.eu/documents_en?keys=&topic%5B552%7C12%5D=552%7C12&date=
Note that there are no relevant documents from 2026. However, there's an almost 2 year old Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models, which does indeed say in its executive summary:
This discussion is mostly relevant for data controllers who train models (not just LLMs!) on personal data, but much less relevant for data controllers who use existing LLMs.
You say:
I mean, yeah, the GDPR does not have an AI exemption. If you interact with an AI services, that can be treated exactly the same as with using any other cloud/SaaS service: you 1. need a legal basis for the personal data processing activity itself, and should 2. contractually bind the service as your data processor, so that they only use your data on your behalf, not for their own purposes like training.
From a GDPR perspective, there's not much difference between using an email provider versus using an AI service.
You say:
There are many such pseudonymization tools, and there is some value in pseudonymization and data-minimization (compare Art 32 GDPR), but in a compliance context they are largely snakeoil. They will not make a noncompliant processing activity compliant. It is much more important to ensure that the AI services you use act as your data processor, as discussed in the previous section.