Can I reuse existing personal data to train or run an AI system?

Answered

Only with a lawful basis for that new purpose. Training and deployment are often distinct purposes with different risks, so they may need different lawful bases. Playbook purpose-limitation still applies: repurposing personal data is only legitimate if the new purpose is compatible with the original collection purpose. Public authorities usually cannot rely on legitimate interests for their public tasks.

From the guidance

Primary (how) ICO: How do we ensure lawfulness in AI?

In many cases, when determining your purpose(s) and lawful basis, it will make sense for you to separate the research and development phase (including conceptualisation, design, training and model selection) of AI systems from the deployment phase. This is because these are distinct and separate purposes, with different circumstances and risks.

Section: How should we distinguish purposes between AI development and deployment?

Read this in ICO: How do we ensure lawfulness in AI? (opens in new tab)

Secondary (normative) AI Playbook for the UK Government

AI systems often reuse personal data for new purposes that are different from those for which it was originally collected. This may cause tension with the purpose limitation of the UK GDPR. Repurposing of personal data is only legitimate if a new purpose is ‘compatible’ with the purpose for which the data was originally collected.

Secondary (normative) ICO: How do we ensure lawfulness in AI?

Additionally, if you are a public authority you can only rely on legitimate interests if you are processing for a legitimate reason other than performing your tasks as a public authority.

Related questions