Can I reuse existing personal data to train or run an AI system?
Answered
Only with a lawful basis for that new purpose. Training and deployment are often distinct purposes with different risks, so they may need different lawful bases. Playbook purpose-limitation still applies: repurposing personal data is only legitimate if the new purpose is compatible with the original collection purpose. Public authorities usually cannot rely on legitimate interests for their public tasks.
From the guidance
Primary (how) ICO: How do we ensure lawfulness in AI?
Section: How should we distinguish purposes between AI development and deployment?
Read this in ICO: How do we ensure lawfulness in AI? (opens in new tab)
Secondary (normative) AI Playbook for the UK Government
Section: Lawfulness and purpose limitation
Read this in AI Playbook for the UK Government (opens in new tab)
Secondary (normative) ICO: How do we ensure lawfulness in AI?
Section: Can we rely on legitimate interests?
Read this in ICO: How do we ensure lawfulness in AI? (opens in new tab)
Related questions
- Can I use AI to process personal data?
- Can I rely on consent to process personal data in an AI system?
- How do I stop an AI system from leaking personal or sensitive data? Security and safe use of tools
- What is data poisoning in an AI system? Security and safe use of tools
- What lawful basis can a public authority use for AI that processes personal data?