{"id":18367,"date":"2025-06-18T08:00:24","date_gmt":"2025-06-18T08:00:24","guid":{"rendered":"https:\/\/letslaw.es\/?p=18367"},"modified":"2025-06-11T13:44:58","modified_gmt":"2025-06-11T13:44:58","slug":"misconceptions-artificial-inteligence-aepd","status":"publish","type":"post","link":"https:\/\/letslaw.es\/en\/misconceptions-artificial-inteligence-aepd\/","title":{"rendered":"What are the misconceptions about artificial intelligence according to the AEPD?"},"content":{"rendered":"<p>Generative Artificial Intelligence (GAI) represents one of the most disruptive technological developments of our time, with profound implications for how data is processed, reused, and generated. However, as a method for developing applications and services, it relies heavily on <strong>data usage, raising fundamental questions under the General Data Protection Regulation (GDPR)<\/strong>. As Recital 7 of the GDPR itself warns, technological progress requires \u2018a stronger and more coherent <a title=\"data protection lawyers\" href=\"https:\/\/letslaw.es\/en\/privacy-data-protection-lawyers\/\">data protection<\/a> framework in the Union\u2019, in order to foster and maintain public trust.<\/p>\n<p>In this context, it is essential to examine the challenges posed by GAI from the standpoint of personal data protection. The <strong>Information Commissioner\u2019s Office (ICO)<\/strong>, the United Kingdom\u2019s data protection authority, conducted a public consultation on the sector\u2019s use of specific areas of GAI, subsequently publishing a series of clarifications regarding common misconceptions identified during the process. These clarifications aim to guide developers towards compliance with data protection obligations, given the growing importance of these systems in the digital sphere.<\/p>\n<h2>AEPD\u2019s commentary on the ICO\u2019s consultation<\/h2>\n<p>The Spanish Data Protection Agency (AEPD), for its part, has sought to comment on and emphasize these clarifications, analyzing them in light of its prior 2022 joint publication with the European Data Protection Supervisor (EDPS), which had already identified common misunderstandings related to machine learning.<\/p>\n<p>Ultimately, the AEPD underscores that these clarifications are intended to steer developers toward full compliance with data protection rules, particularly in light of the increasing relevance of these technologies in digital environments.<\/p>\n<h2>Misconceptions regarding generative AI<\/h2>\n<p>The following are among the key misconceptions identified:<\/p>\n<p><strong>1. The \u2018incidental\u2019 or \u2018agnostic\u2019 processing of personal data still constitutes personal data processing and is therefore subject to data protection law.<\/strong><\/p>\n<p>GAI developers must conduct a prior and precise assessment to determine whether their models process personal data and, if so, must ensure compliance with applicable legislation.<\/p>\n<p>That is to say, the assertion that personal data is processed accidentally or unintentionally does not exempt a developer from the requirements of the GDPR. Any processing of personal data, even incidental, is subject to data protection rules.<\/p>\n<p><strong>2. Common practice does not equate to meeting individuals\u2019 reasonable expectations.<\/strong><\/p>\n<p>The principle of transparency under the GDPR requires controllers to inform data subjects in a concise, transparent, intelligible, and easily accessible manner, using clear and plain language. This principle applies equally to the training of models and to any secondary use of personal data for purposes not originally disclosed.<\/p>\n<p>Hence, using personal data for AI model training without adequately informing data subjects beforehand breaches the transparency principle. Even when such data is obtained via <a title=\"web scraping\" href=\"https:\/\/letslaw.es\/en\/protection-web-scraping\/\">web scraping<\/a> or web crawling, it is essential to clearly and accessibly inform individuals about the intended use of their personal data.<\/p>\n<p><strong>3. There is no distinction between \u2018personally identifiable information\u2019 (PII) and \u2018personal data\u2019.<\/strong><\/p>\n<p>To ensure lawful processing under the GDPR, any form of \u201cpersonal data\u201d must be considered. This is a broader and legally defined term under the GDPR, encompassing any information relating to an identified or identifiable natural person.<\/p>\n<p><strong>4. Case law concerning search engines does not directly apply to GAI.<\/strong><\/p>\n<p>Some developers have attempted to rely on Court of Justice of the European Union (CJEU) rulings concerning search engines to justify certain GAI-related practices. However, this analogy is legally flawed.<\/p>\n<p>Whereas search engines index and retrieve existing content, generative AI synthesizes and creates new outputs based on large volumes of data, thus introducing additional risks.<\/p>\n<p>Moreover, mechanisms for exercising data subject rights\u2014such as the <a title=\"right to erasure\" href=\"https:\/\/letslaw.es\/en\/right-to-be-forgotten-artificial-intelligence\/\">right to erasure<\/a>\u2014are well established in the search engine context but remain underdeveloped in GAI systems. This necessitates a more rigorous and context-specific legal analysis to uphold data subject rights effectively.<\/p>\n<p><strong>5. AI models can retain and disclose personal data.<\/strong><\/p>\n<p>A common defence is that AI models do not &#8220;store&#8221; personal data but only process it for training purposes.<\/p>\n<p>This position is untenable when models are capable of reproducing\u2014either verbatim or approximately\u2014segments of personal data used during training. This risk, which has been technically documented in various studies, engages the data minimization principle and mandates the implementation of safeguards to prevent the unintended disclosure of sensitive or identifiable information.<\/p>\n<p><strong>6. Data protection is not a tool for assessing legality under other legal regimes.<\/strong><\/p>\n<p>Although GDPR compliance may intersect with other legal frameworks (such as intellectual property, employment law, or AI regulation), data protection authorities are not competent to interpret or enforce those regimes.<\/p>\n<p>The GDPR is exclusively concerned with the processing of personal data and cannot be used to determine the broader legality of a technology\u2019s use. While controllers must undertake a cross-cutting legal assessment, the jurisdiction of data protection authorities is clearly delimited.<\/p>\n<p><strong>7. There is no \u2018exemption\u2019 for GAI under data protection law.<\/strong><\/p>\n<p>Organisations must be fully aware that there are no general exemptions or derogations for generative AI. If personal data is being processed in any context, the entire data protection framework applies.<\/p>\n<p>Moreover, Article 25 GDPR imposes a clear obligation to implement \u2018data protection by design and by default\u2019. In the GAI context, this entails defining limits from the development phase, conducting risk assessments, and establishing mechanisms for oversight, control, and transparency.<\/p>\n<h2>Data protection as a pillar of responsible AI<\/h2>\n<p>The misconceptions identified by the ICO and echoed by the AEPD are not mere technicalities. They reveal a significant misalignment between technological innovation and the existing legal framework.<\/p>\n<p>Generative AI does not operate in a legal vacuum\u2014it is bound by clear rules grounded in fundamental principles such as <strong>transparency, proactive accountability, and the effective safeguarding of data subject rights<\/strong>.<\/p>\n<p>At a time when innovation is rapidly accelerating, it is incumbent upon data controllers and developers to embed data protection as a core component of technological design. Only through such integration can a legally compliant and democratically anchored digital transformation be achieved.<\/p>\n<div class=\"cyp_post_formulario\"><h2>Contact Us<\/h2>\n<div class=\"wpcf7 no-js\" id=\"wpcf7-f3074-o1\" lang=\"es-ES\" dir=\"ltr\" data-wpcf7-id=\"3074\">\n<div class=\"screen-reader-response\"><p role=\"status\" aria-live=\"polite\" aria-atomic=\"true\"><\/p> <ul><\/ul><\/div>\n<form action=\"\/en\/wp-json\/wp\/v2\/posts\/18367#wpcf7-f3074-o1\" method=\"post\" class=\"wpcf7-form init wpcf7-acceptance-as-validation\" aria-label=\"Formulario de contacto\" novalidate=\"novalidate\" data-status=\"init\">\n<fieldset class=\"hidden-fields-container\"><input type=\"hidden\" name=\"_wpcf7\" value=\"3074\" \/><input type=\"hidden\" name=\"_wpcf7_version\" value=\"6.1.5\" \/><input type=\"hidden\" name=\"_wpcf7_locale\" value=\"es_ES\" \/><input type=\"hidden\" name=\"_wpcf7_unit_tag\" value=\"wpcf7-f3074-o1\" \/><input type=\"hidden\" name=\"_wpcf7_container_post\" value=\"0\" \/><input type=\"hidden\" name=\"_wpcf7_posted_data_hash\" value=\"\" \/><input type=\"hidden\" name=\"_wpcf7_recaptcha_response\" value=\"\" \/>\n<\/fieldset>\n<div class=\"campo_nombre\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-name\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Name\" value=\"\" type=\"text\" name=\"your-name\" \/><\/span><\/div>\n<div class=\"campo_telefono\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-phone\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-tel wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-tel datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Phone\" value=\"\" type=\"tel\" name=\"your-phone\" \/><\/span><\/div>\n<div class=\"campo_email\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-email\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-email wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-email datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Email\" value=\"\" type=\"email\" name=\"your-email\" \/><\/span><\/div>\n<div class=\"campo_asunto\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-asunto\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Subject\" value=\"\" type=\"text\" name=\"your-asunto\" \/><\/span><\/div>\n<div class=\"campo_mensaje\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-mensaje\"><textarea cols=\"40\" rows=\"10\" maxlength=\"2000\" class=\"wpcf7-form-control wpcf7-textarea wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Message\" name=\"your-mensaje\"><\/textarea><\/span><\/div>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"\" type=\"hidden\" name=\"cyp_form_url\" \/>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"cyp_zonaweb\" type=\"hidden\" name=\"zonaweb\" \/>\n<span class=\"wpcf7-form-control-wrap recaptcha\" data-name=\"recaptcha\"><span data-sitekey=\"6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" class=\"wpcf7-form-control wpcf7-recaptcha g-recaptcha\"><\/span>\r\n<noscript>\r\n\t<div class=\"grecaptcha-noscript\">\r\n\t\t<iframe loading=\"lazy\" src=\"https:\/\/www.google.com\/recaptcha\/api\/fallback?k=6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" frameborder=\"0\" scrolling=\"no\" width=\"310\" height=\"430\">\r\n\t\t<\/iframe>\r\n\t\t<textarea name=\"g-recaptcha-response\" rows=\"3\" cols=\"40\" placeholder=\"Aqu\u00ed la respuesta de reCAPTCHA\">\r\n\t\t<\/textarea>\r\n\t<\/div>\r\n<\/noscript>\r\n<\/span>\n<div style=\"width:100%\">\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important;margin-bottom:15px !important\">\nBy clicking on \"Send\" you accept our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup_ingles\">+ Info<\/a>\n<\/p>\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important\">\n<span class=\"wpcf7-form-control-wrap\" data-name=\"checkbox-173\"><span class=\"wpcf7-form-control wpcf7-checkbox wpcf7-exclusive-checkbox\"><span class=\"wpcf7-list-item first last\"><label><input type=\"checkbox\" name=\"checkbox-173\" value=\"\" \/><span class=\"wpcf7-list-item-label\"><\/span><\/label><\/span><\/span><\/span> I agree to receive outlined commercial communications from LETSLAW, S.L. in accordance with the provisions of our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup\">+ Info<\/a>\n<\/p>\n<\/div>\n<div class=\"vc_col-sm-12 botton-datos-contacto\"><input class=\"wpcf7-form-control wpcf7-submit has-spinner\" type=\"submit\" value=\"Send\" \/><\/div><input type='hidden' class='wpcf7-pum' value='{\"closepopup\":false,\"closedelay\":0,\"openpopup\":false,\"openpopup_id\":0}' \/><div class=\"wpcf7-response-output\" aria-hidden=\"true\"><\/div>\n<\/form>\n<\/div>\n<div>","protected":false},"excerpt":{"rendered":"<p>Generative Artificial Intelligence (GAI) represents one of the most disruptive technological developments of our time.<\/p>\n","protected":false},"author":67,"featured_media":18393,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[243],"tags":[],"class_list":["post-18367","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-protection"],"_links":{"self":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/18367","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/users\/67"}],"replies":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/comments?post=18367"}],"version-history":[{"count":5,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/18367\/revisions"}],"predecessor-version":[{"id":18395,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/18367\/revisions\/18395"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media\/18393"}],"wp:attachment":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media?parent=18367"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/categories?post=18367"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/tags?post=18367"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}