• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechAI

Europe’s privacy watchdogs tell AI companies what they must do to avoid big GDPR fines

By
David Meyer
David Meyer
Down Arrow Button Icon
By
David Meyer
David Meyer
Down Arrow Button Icon
December 18, 2024, 10:26 AM ET
OpenAI CEO Sam Altman Visits "Making Money With Charles Payne" at Fox Business Network Studios on December 04, 2024 in New York City.
OpenAI CEO Sam Altman in December 2024 in New York City. Mike Coppola—Getty Images

Europe’s privacy regulators have issued new guidelines for judging whether AI companies are breaking the EU’s General Data Protection Regulation, which threatens fines of up to 4% of global revenues.

Recommended Video

The guidelines may provide enough clarity for companies such as Meta—under fire from privacy campaigners and regulators over its training of AI models on people’s personal data—to roll out new AI services in Europe.

But they also make clear that these companies have high hurdles to jump if they want to stay on the right side of European privacy law. It may be the case that AI companies will struggle to comply if they trained their models on personal data that had been illegally collected, and if they don’t take steps to ensure that information cannot be accessed by others when people use the models.

The European Data Protection Board (EDPB), the umbrella organization for the EU’s privacy watchdogs, issued the formal opinion on AI on Wednesday, in response to a request from Ireland’s data protection commissioner.

The Irish watchdog requested the opinion in September, shortly after it had convinced Elon Musk’s X to stop training its Grok AI on some public posts from European users. X hadn’t asked for the users’ consent and had no legal basis under the GDPR for using their data in this way. Commissioner Dale Sunderland said at the time that the EU’s data protection authorities should agree on key questions about AI and the GDPR, to “enable proactive, effective, and consistent Europe-wide regulation of this area.”

The GDPR requires anyone processing someone’s personal data (meaning any data that can be linked to them as an identifiable person) have a legal basis for doing so. The law provides a list of possible legal bases, such as user consent or carrying out contracts, and the big AI companies have generally opted to claim that they have a “legitimate interest” in processing people’s personal data for training their models.

This is the vaguest legal basis allowable, and reflects the fact that none of the other options applies. But it also highlights the need for further clarity about exactly what is permissible.

The ‘legitimate interests’ test

On the one hand, the EDPB’s Wednesday opinion confirms that this is a potentially valid legal basis for training AI models.

“We welcome the EDPB’s recognition that legitimate interests is an appropriate legal basis for training generative AI models,” said a Meta spokesperson. “But it’s frustrating that it has taken many months of unnecessary delay for regulators to approve the same legal mechanisms that the industry proposed at the start of this year … We urge European regulators to quickly apply these principles in a pragmatic and transparent way so the EU can deliver the growth that leading European political figures are calling for.”

The Computer and Communications Industry Association (CCIA)—a group whose membership includes big AI players like Meta, X, and Google—said the confirmation of legitimate interest as a lawful basis marked “an important step towards more legal certainty.”

However, the opinion stresses that successfully claiming “legitimate interest” will mean passing a three-step test. An AI company would have to have a “clear and precisely articulated” reason for processing someone’s data—it can’t rely on hypothetical future reasons—and the processing would have to be “really necessary” for achieving that aim. The legitimate interest can also be overridden by fundamental rights such as privacy and freedom of expression, depending on the case.

Privacy advocates have argued that AI models such as OpenAI’s GPT series are too general to pass this test, as they were developed without a specific use case in mind, and people can come up with entirely new applications long after the model was trained and released.

In their opinion, the regulators gave two examples of what could pass the test: training a “conversational agent to assist users,” and deploying an AI-based cybersecurity tool in a network. They stressed that legitimate interest had to be judged on a case-by-case basis.

“A large part of the opinion is telling AI companies what they should have been doing anyway, but it also sends a message that being innovative is not an excuse for not complying with the law,” said Tom West, a legal officer at the rights group Privacy International.

The EDPB noted that it wasn’t able to cover every possible AI scenario in its opinion, not least because the models are evolving so quickly. But that vagueness has left some dissatisfied. Claudia Canelles Quaroni, the CCIA’s European senior policy manager, suggested that AI companies still wouldn’t have the confidence they need to fully roll out their services in Europe.

“Greater legal clarity and a practical framework are needed to reconcile EU privacy principles with technological progress,” she said in an emailed statement. “This is essential for Europe to remain competitive and unlock AI-driven innovation. Otherwise European consumers and businesses risk missing out on more cutting-edge technologies powered by AI and data.”

Where the data comes from

Most of today’s cutting-edge foundation models were likely trained on data that was scraped from public sources on the web—the companies are very opaque on this point—so this was a major focus in the EDPB opinion.

The watchdogs suggested that it might be possible for someone to legally scrape people’s data from the web if they were very careful about minimizing the data they collected, and if they made people aware that they were taking their data. But without those mitigations—which are unlikely to have been in place—the collection may very well have broken people’s privacy rights, and possibly even their freedom of expression if a “sense of surveillance” makes them likely to self-censor.

Crucially, using data with dodgy provenance could undermine an AI company’s claim to be exercising its legitimate interests when training its models on that data, potentially leaving it open to a big GDPR fine. And if another company then goes and deploys those models, then it could also be in trouble—the onus is on that company to check whether the model it’s deploying was trained on lawfully processed data.

That picture could change if the model is made “anonymous,” meaning there’s no significant likelihood that someone could extract people’s personal data from it. But the opinion makes clear that companies are not to be taken at their word on this. To determine whether a model is “anonymous,” regulators can go so far as to conduct “analysis of reports of code reviews, as well as a theoretical analysis documenting the appropriateness of the measures chosen to reduce the likelihood of reidentification of the concerned model.”

In any case, the big AI companies don’t tend to go so far as to claim that they have made their models anonymous, though they do sometimes claim to protect people’s privacy.

OpenAI, for example, insists that it doesn’t “actively seek out personal information” to train its models, and doesn’t use personal information in training data to build profiles of people. It also filters out data from training datasets that comes from “websites that aggregate large volumes of personal information,” and says it trains its models to “reject requests for private or sensitive information about people.” The company lets Europeans opt out of having their personal data used in model training as well.

Privacy International’s West pointed out that it is virtually impossible to remove someone’s personal information from a model that has been trained on it. He also noted that the EDPB opinion says watchdogs can go so far as to order a model’s deletion if it can’t be brought in line with the GDPR. “We support keeping that option on the table,” he said.

OpenAI had not responded to a request for comment on the EDPB opinion at the time of writing; nor had Microsoft or Google.

Join us at the Fortune Workplace Innovation Summit May 19–20, 2026, in Atlanta. The next era of workplace innovation is here—and the old playbook is being rewritten. At this exclusive, high-energy event, the world’s most innovative leaders will convene to explore how AI, humanity, and strategy converge to redefine, again, the future of work. Register now.
About the Author
By David Meyer
LinkedIn icon
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

receipts
EconomyFederal Reserve
‘Inflationary surge’: Fed economists warn AI hype is overheating the economy whether or not the technology ever delivers
By Jake AngeloApril 1, 2026
26 minutes ago
AI
AIProductivity
AI is saving workers up to an hour a day — but Goldman Sachs says 80% of companies aren’t using it yet
By Nick LichtenbergApril 1, 2026
40 minutes ago
Nvidia CEO Jensen Huang
SuccessJobs
Nvidia CEO Jensen Huang’s advice to workers scared of AI: You’re just confusing your job with the tools you use to do it
By Emma BurleighApril 1, 2026
50 minutes ago
Five hard lessons from Allbirds’ 99% stock plunge and $39 million fire sale
Retailchief executive officer (CEO)
Five hard lessons from Allbirds’ 99% stock plunge and $39 million fire sale
By Phil WahbaApril 1, 2026
51 minutes ago
Exclusive: Paradigm, a major investor in Kalshi, is building its own prediction markets trading terminal, say sources
CryptoVenture Capital
Exclusive: Paradigm, a major investor in Kalshi, is building its own prediction markets trading terminal, say sources
By Ben WeissApril 1, 2026
1 hour ago
gary
Commentaryregulation
The biggest mistake CEOs make with AI has nothing to do with the technology
By Gary ShapiroApril 1, 2026
2 hours ago

Most Popular

Jerome Powell says the $39 trillion national debt is ‘not unsustainable,’ but warns the trajectory ‘will not end well’
Economy
Jerome Powell says the $39 trillion national debt is ‘not unsustainable,’ but warns the trajectory ‘will not end well’
By Fortune EditorsMarch 30, 2026
2 days ago
Markets cheer as Trump threatens to abandon Iran war, but Jamie Dimon sides with allies: ‘Win this thing and clean up the straits’
Energy
Markets cheer as Trump threatens to abandon Iran war, but Jamie Dimon sides with allies: ‘Win this thing and clean up the straits’
By Fortune EditorsMarch 31, 2026
1 day ago
A man used AI to call 3,000 Irish bartenders to track the cost of Guinness. Now pubs are lowering their prices to compete
AI
A man used AI to call 3,000 Irish bartenders to track the cost of Guinness. Now pubs are lowering their prices to compete
By Fortune EditorsMarch 30, 2026
2 days ago
Kevin O'Leary says if you earn $68,000 a year and follow this rule, you'll retire a millionaire
Personal Finance
Kevin O'Leary says if you earn $68,000 a year and follow this rule, you'll retire a millionaire
By Fortune EditorsMarch 31, 2026
1 day ago
Two-thirds of parents say their adult Gen Z kids still rely on them financially  for support—even though it's putting them under strain
Success
Two-thirds of parents say their adult Gen Z kids still rely on them financially  for support—even though it's putting them under strain
By Fortune EditorsMarch 31, 2026
1 day ago
The federal government shed 385,000 employees last year. Now the Trump administration is on a blitz to hire Gen Z workers
Politics
The federal government shed 385,000 employees last year. Now the Trump administration is on a blitz to hire Gen Z workers
By Fortune EditorsMarch 31, 2026
1 day ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.