Point of law
Using AI in line with data protection law
Training and use are two processing operations, each with a legal basis of its own. Anyone deploying a third party model owes, under the opinion of the European Data Protection Board, an assessment of their own as to whether it was lawfully developed. And the roles of provider and deployer under the AI Act do not map onto controller and processor.
Two sets of roles in one contract
The business unit wants to use a language model to analyse customer enquiries. The supplier presents a processing agreement and describes itself in its documentation as a provider within the meaning of the AI Act. Whether the legal basis is thereby settled, and whether the two labels mean the same thing, is open.
Training and use are two processing operations
What the processing rests on has to be answered twice, and the first answer concerns an operation that never took place in your own organisation. A model comes into being out of data, and its use produces more.
Three operations, three bases
Training the model
At the provider, usually on Art. 6(1)(f) GDPR. The European Data Protection Board requires the three-step test of interest, necessity and balancing for it.
Input and output in operation
In your own organisation, with a basis of its own. It follows from the purpose for which the tool is used, not from the tool.
Further use of the inputs
Where the provider uses inputs to improve the model, that is a third operation for a different purpose, and it needs a basis of its own at whoever carries it out.
3 von 3
In practice that assessment is almost always skipped, because no supplier documentation provides for it. It can nonetheless be carried out, from publicly available information on the origin of the training data, from the provider’s model cards and from proceedings pending against it.
Two Regulations, two role systems, no overlap
Who holds which role has been answered with two pairs of terms since the AI Act became applicable, and the two pairs denote different things. One regime asks about placing on the market, the other about the decision on purposes and means.
The same body, two classifications
| AI Act | Merkmal | GDPR |
|---|---|---|
| Placing on the marketArt. 3(3) AI Act. A provider is whoever develops or has developed and places on the market under its own name. | What it attaches to | Purposes and meansArt. 4(7) GDPR. A controller is whoever decides on them, regardless of distribution and branding. |
| DeployerArt. 3(4) AI Act. Whoever uses the system under its own authority. | The deploying body | ControllerIt decides on the purpose of the deployment and is therefore responsible for the processing. |
| Provider | The model provider | It dependsA processor in so far as it processes on instructions. A controller in its own right in so far as it uses the inputs for its own purposes. |
| By its own actUnder Art. 25(1) AI Act a deployer is deemed a provider where it substantially modifies a high-risk system or changes an intended purpose so that the system becomes high-risk. | Change of role | By determining purposesUnder Art. 28(10) GDPR a processor is deemed a controller where it determines purposes and means. |
For the contract it follows that being labelled a provider says nothing about the data protection role. The two classifications are made separately, and the contract has to reflect both.
Five points the contract has to answer
Retention of the inputs
Whether and for what purpose inputs are retained, with a period rather than a statement of intent. Without a period neither a retention schedule can be kept nor an access request answered.
Use for training
Whether inputs are used for training and whether that can be switched off. Where it happens, that is processing for a different purpose, and the provider decides on purposes and means to that extent.
Sub-processors and locations
Which sub-processors are used and where they process. That determines whether Chapter V of the Regulation applies, and the answer changes more often with these services than the contract does.
Assistance with data subject rights
How the provider assists with an access request while inputs are still held. Art. 28(3)(e) GDPR requires that assistance, and with a language model it is technically demanding.
Information on the origin of the training data
What the provider states about the origin of the training data. On that depends whether the assessment under Opinion 28/2024 can be carried out at all.
How we support you in using AI
Both questions can be answered in one meeting with the business unit and procurement, provided three items are on the table first. The purpose of the deployment in one sentence, because the legal basis follows from it. The provider’s statements on retention and training, taken from its documentation rather than from a sales conversation. And the publicly available information on the origin of the training data. Roles, contract amendments and the assessment under the Opinion all follow from those three.
Frequently asked questions
Is a trained model anonymous?
Not without more. Under Opinion 28/2024 of the European Data Protection Board, models trained with personal data cannot in all cases be regarded as anonymous. They are anonymous only where both the likelihood of direct extraction and the likelihood of obtaining personal data through queries are insignificant.
Is the provider of a language model our processor?
Only in so far as it processes on instructions. Where it uses the inputs for its own purposes, for instance to improve the model, it decides on purposes and means itself to that extent and is a controller in its own right. Under Art. 28(10) GDPR it is even deemed a controller where it does so in breach of the Regulation.
Does the deployment require an impact assessment?
Frequently yes. It is required under Art. 35(1) GDPR where the processing is likely to result in a high risk, and the supervisory authorities' lists under paragraph 4 name AI deployment in several categories. It has to be carried out before the processing and therefore before the roll-out.
Does conformity under the AI Act replace the data protection assessment?
No. The two Regulations apply side by side and pursue different aims. A conformity assessment says something about the system, not about the lawfulness of the processing carried out with it.
More questions from this area
AI Act risk classification
A system is high-risk under Art. 6(1) AI Act where it is a safety component of a product under Annex I, or under paragraph 2 where it falls within one of the eight areas of Annex III, such as creditworthiness assessment under point 5(b).
Transparency duties under Art. 50 AI Act
Art. 50 AI Act allocates four duties to two addressees.
Get in touch!
Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!
Contact usAlternatively you can request a call back.