The accelerated development of artificial intelligence (AI) is testing the seams of the European privacy regulatory framework. In recent months, a proposal under discussion in the European Union institutions has set off all the alarms and opened an intense legal debate: the possibility of allowing AI models to be trained using citizens' personal data without the need to obtain their prior and explicit consent.
This initiative responds to pressure from the technology industry and various economic sectors that argue that requiring individual consent for massive volumes of information (big data) paralyzes Europe's competitiveness against powers like the United States or China. To circumvent this obstacle, it is proposed to resort to the legal figure of the’legitimate interest, one of the legal bases provided for in the General Data Protection Regulation (GDPR), but which has so far been applied in a very restrictive way in the digital sphere.
However, basing algorithm training on legitimate interest does not mean that companies have carte blanche. For this to be legal, organisations would have to pass a very rigorous balancing test to demonstrate that their interests do not infringe on the fundamental rights of users. Furthermore, there would be an obligation to provide a simple and accessible mechanism for any citizen to exercise their right to object, thus preventing their data from being incorporated into language or machine learning models.
Faced with this scenario, data protection authorities and digital rights organizations are urging caution. They argue that relaxing consent requirements could dilute the principles of transparency and data minimization, leaving citizens unprotected against possible algorithmic bias, invisible profiling, or re-identification of their personal information.
The basic message right now is one of vigilance and preparedness. While the European Union defines the exact scope of this flexibility, companies developing or implementing AI solutions must continue to conduct rigorous impact assessments and ensure maximum transparency. The key to Europe's digital future should not be choosing between innovation and privacy, but rather demonstrating that it is possible to lead technology while respecting everyone's digital rights. Then, of course, it remains to be seen which path other actors such as the United States choose, and that is already an unpredictable unknown.
Jordi Ventura





