Can I use AI to process personal data?

Answered

Yes, but only lawfully. Identify a purpose and lawful basis for each distinct processing operation (training and deployment may need different bases), protect personal data from the outset, and give people privacy information before you use their data to train or apply a model. Seek data protection advice early. ICO AI guidance is currently under review after the Data (Use and Access) Act.

From the guidance

Primary (how) ICO: How do we ensure lawfulness in AI?

The development and deployment of AI systems involve processing personal data in different ways for different purposes. You must break down and separate each distinct processing operation, and identify the purpose and an appropriate lawful basis for each one, in order to comply with the principle of lawfulness.

Section: What should we consider when deciding lawful bases?

Read this in ICO: How do we ensure lawfulness in AI? (opens in new tab)

Secondary (normative) ICO: How do we ensure transparency in AI?

If you collect data directly from individuals, you must provide that privacy information to them at the time you collect it, before you use it to train a model or apply that model on those individuals.

Section: What are our transparency obligations towards people?

Read this in ICO: How do we ensure transparency in AI? (opens in new tab)

Secondary (normative) Data and AI Ethics Framework

You must design and build privacy into your project from the start. This includes: the very first decisions you make about what information you intend to record; every way that the data, or AI system built using this data, is used throughout your project; the safe decommissioning of the system and data set.

Secondary (normative) AI Playbook for the UK Government

You should seek data protection advice on your use of AI. This may be from your lawyers or your data protection officer. AI systems can process personal data, so you need to consider how you protect this personal data, be compliant with data protection legislation, and minimise the risk of privacy intrusion from the outset.

Section: Principle 2: You use AI lawfully, ethically and responsibly

Read this in AI Playbook for the UK Government (opens in new tab)

Related questions