1Legal basis, sensitive data
Reusing data to train a model is a new processing operation: it needs a legal basis GDPR · art. 6 and a compatible purpose with the original collection.
Special categories GDPR · art. 9 — ethnicity, health, opinions, religion, orientation, biometrics… — are prohibited from processing, except for an exception. Yet to verify that a model doesn't discriminate based on ethnicity or sex, you need to know the ethnicity or sex.
The GDPR itself provides exceptions to this prohibition art. 9(2) — including the explicit consent of the individual — distinct from the specific door opened by the AI Act (§5) below.
2Purposes, minimization, duration, anonymization
The six legal bases
All processing rests on one of the six bases of art. 6: consent, performance of a contract, legal obligation, vital interest, public interest mission, legitimate interest (subject to a balancing test). "Profitability" is not one of them. In HR, consent is fragile: the subordination relationship casts doubt on whether it is "freely given."
Purpose and reuse
Reusing data for a new use requires a compatible purpose with the original collection (compatibility test) or a new basis. Recycling a marketing CRM into an HR model is a change of purpose to be examined — not a mere technicality.
Minimization and duration
- Minimization: include only what is necessary and relevant to the purpose (a national ID number has no place in a CV-screening dataset). Don't "keep everything just in case."
- Retention limits: data is kept only as long as necessary, then deleted. Sensitive data processed under §5 must be deleted once the bias-measurement objective has been achieved.
Pseudonymization ≠ anonymization
Pseudonymizing (replacing identifiers with codes) leaves the data personal — re-identification remains possible — hence still within the GDPR's scope. Only irreversible anonymization (re-identification impossible) takes the data outside the GDPR… but it is hard to truly guarantee.
3Roles and individuals' rights
Who answers for what
- Controller — determines the purposes and means.
- Processor art. 28 — acts on behalf of the controller, under documented instructions; it ensures security and does not engage a sub-processor without authorization. It does not decide the purposes.
- Joint controllers art. 26 — jointly determine purposes and means; they allocate their respective responsibilities.
Individuals' rights
Access, rectification, erasure (subject to conditions — not absolute: exceptions exist), objection… However, there is no "absolute veto right" over all AI training.
4DPIA and transfers outside the EU
The data protection impact assessment (DPIA)
When a processing operation presents a high risk — new technologies, large-scale profiling, sensitive data — a DPIA art. 35 is mandatory, upfront. A high-risk AI system triggers it almost always.
Moving data outside the EU
A transfer outside the EU requires a transfer mechanism chapter V: adequacy decision, standard contractual clauses, etc. It is neither free nor banned by default. A provider offering to send data to a cloud outside the EU "to speed things up" raises this exact question — and departs from the in-place logic: it must be tightly controlled or refused.