PrivacySignal
GDPR / Intl

Thought for the week: Web scraping for generative AI is subject to the GDPR

IAPP · · International · GDPR & International

A commentary from the IAPP argues that web scraping used to build generative AI training datasets falls within the scope of GDPR, meaning the collection and processing of personal data found online is not exempt simply because it occurs at scale or at the infrastructure level.

Why this matters: A lot of AI development runs on scraped data. Companies pull text, images, and other content from across the web, and some of that content includes real people. Names, opinions, medical posts, forum entries. GDPR has rules about collecting personal data, and those rules do not disappear because the collection is automated or the end product is a language model. If this reading holds, AI developers cannot treat the open web as a free data mine. They need a lawful basis, just like anyone else collecting personal information.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

GDPR / Intl
noyb (None of Your Business) · · EU

‘Shadow database’ scandal: noyb sends SCHUFA cease-and-desist letter; interest list for class action opened

German privacy group noyb has sent a cease-and-desist letter to credit agency SCHUFA after investigations revealed it retained millions of records that should have been deleted, and used them for customer testing. Noyb has opened an interest list for a class action, with up to 69 million people potentially affected.

Who should care: Lawyers · Privacy officers · AI governance

GDPR / Intl
C Computing UK · · International

ICO: Police facial recognition needs stronger oversight

The UK's Information Commissioner's Office has called for stronger oversight of how police use facial recognition technology, signaling concern that current controls are insufficient to govern the practice.

Who should care: Lawyers · Privacy officers · AI governance · Cybersecurity · General readers · Policy

#gdpr#surveillance#privacy Read original →
GDPR / Intl
C Computer Weekly · · International

ICO police facial recognition audits reveal ‘mixed’ bag

The UK's Information Commissioner's Office conducted audits of police use of facial recognition technology and found inconsistent results across the forces reviewed. The findings suggest compliance and practice vary significantly, with no uniform standard being met.

Who should care: Lawyers · Privacy officers · AI governance · Cybersecurity · General readers · Policy

#gdpr#surveillance#privacy Read original →