Académie / Signing expert — the core track

Tier 2 · Personal data · Cours

GDPR, sensitive data, and the §5 door

Article 10 lives inside the GDPR. A signable file rests on a chain of legal bases — and on the one door that allows touching sensitive data to measure bias.

4 sections

1Legal basis, sensitive data

Reusing data to train a model is a new processing operation: it needs a legal basis GDPR · art. 6 and a compatible purpose with the original collection.

Special categories GDPR · art. 9 — ethnicity, health, opinions, religion, orientation, biometrics… — are prohibited from processing, except for an exception. Yet to verify that a model doesn't discriminate based on ethnicity or sex, you need to know the ethnicity or sex.

The GDPR itself provides exceptions to this prohibition art. 9(2) — including the explicit consent of the individual — distinct from the specific door opened by the AI Act (§5) below.

The narrow door — art. 10 §5. The AI Act allows processing of sensitive data to the extent strictly necessary for the detection and correction of bias in high-risk systems, subject to safeguards: security, restricted access, pseudonymization, no transmission, deletion once the objective is achieved. It is this §5 that makes a bias file lawful.

2Purposes, minimization, duration, anonymization

The six legal bases

All processing rests on one of the six bases of art. 6: consent, performance of a contract, legal obligation, vital interest, public interest mission, legitimate interest (subject to a balancing test). "Profitability" is not one of them. In HR, consent is fragile: the subordination relationship casts doubt on whether it is "freely given."

Purpose and reuse

Reusing data for a new use requires a compatible purpose with the original collection (compatibility test) or a new basis. Recycling a marketing CRM into an HR model is a change of purpose to be examined — not a mere technicality.

Lawfulness upstream. Collection without a legal basis contaminates everything that follows: the model's performance does not regularize the unlawfulness. A regulator can require deletion of the data — or even of the model built from it.

Minimization and duration

  • Minimization: include only what is necessary and relevant to the purpose (a national ID number has no place in a CV-screening dataset). Don't "keep everything just in case."
  • Retention limits: data is kept only as long as necessary, then deleted. Sensitive data processed under §5 must be deleted once the bias-measurement objective has been achieved.

Pseudonymization ≠ anonymization

Pseudonymizing (replacing identifiers with codes) leaves the data personal — re-identification remains possible — hence still within the GDPR's scope. Only irreversible anonymization (re-identification impossible) takes the data outside the GDPR… but it is hard to truly guarantee.

3Roles and individuals' rights

Who answers for what

  • Controller — determines the purposes and means.
  • Processor art. 28 — acts on behalf of the controller, under documented instructions; it ensures security and does not engage a sub-processor without authorization. It does not decide the purposes.
  • Joint controllers art. 26jointly determine purposes and means; they allocate their respective responsibilities.

Individuals' rights

Access, rectification, erasure (subject to conditions — not absolute: exceptions exist), objection… However, there is no "absolute veto right" over all AI training.

In-place processing, from a GDPR standpoint. When the data stays with the client (only metadata leaves), the operator acts as a processor, nothing raw is transmitted to a third party, exposure is reduced: minimization and security both come out stronger.

4DPIA and transfers outside the EU

The data protection impact assessment (DPIA)

When a processing operation presents a high risk — new technologies, large-scale profiling, sensitive data — a DPIA art. 35 is mandatory, upfront. A high-risk AI system triggers it almost always.

Moving data outside the EU

A transfer outside the EU requires a transfer mechanism chapter V: adequacy decision, standard contractual clauses, etc. It is neither free nor banned by default. A provider offering to send data to a cloud outside the EU "to speed things up" raises this exact question — and departs from the in-place logic: it must be tightly controlled or refused.