Can I use AI to process personal data?
Answered
Yes, but only lawfully. Identify a purpose and lawful basis for each distinct processing operation (training and deployment may need different bases), protect personal data from the outset, and give people privacy information before you use their data to train or apply a model. Seek data protection advice early. ICO AI guidance is currently under review after the Data (Use and Access) Act.
From the guidance
Primary (how) ICO: How do we ensure lawfulness in AI?
Section: What should we consider when deciding lawful bases?
Read this in ICO: How do we ensure lawfulness in AI? (opens in new tab)
Secondary (normative) ICO: How do we ensure transparency in AI?
Section: What are our transparency obligations towards people?
Read this in ICO: How do we ensure transparency in AI? (opens in new tab)
Secondary (normative) Data and AI Ethics Framework
Section: What privacy means in practice
Read this in Data and AI Ethics Framework (opens in new tab)
Secondary (normative) AI Playbook for the UK Government
Section: Principle 2: You use AI lawfully, ethically and responsibly
Read this in AI Playbook for the UK Government (opens in new tab)
Related questions
- Can I rely on consent to process personal data in an AI system?
- Can I reuse existing personal data to train or run an AI system?
- What lawful basis can a public authority use for AI that processes personal data?
- How do I stop an AI system from leaking personal or sensitive data? Security and safe use of tools
- What is data poisoning in an AI system? Security and safe use of tools