Hostname: page-component-89b8bd64d-5bvrz Total loading time: 0 Render date: 2026-05-08T01:49:03.904Z Has data issue: false hasContentIssue false

Generative AI and data protection

Published online by Cambridge University Press:  06 January 2025

Hannah Ruschemeier*
Affiliation:
Faculty of Law, University of Hagen, Hagen, Germany
Rights & Permissions [Opens in a new window]

Abstract

Generative artificial intelligence (AI) has catapulted into the legal debate through the popular applications ChatGPT, Bard, Dall-E and others. While the predominant focus has hitherto centred on issues of copyright infringement and regulatory strategies, particularly in the context of the AI Act, a critical but often overlooked issue lies in the friction between generative AI and data protection laws. The rise of these technologies highlights unresolved tension between safeguarding fundamental protection rights and and the vast, almost universal, of scale of data processing required for machine learning. Large language models, which scrape nearly the whole Internet rely on and may even generate personal data falling under the GDPR. This tension manifests across multiple dimensions, encompassing data subjects’ rights, the foundational principles of data protection and the fundamental categories of data protection. Drawing on ongoing investigations by data protection authorities in Europe, this paper undertakes a comprehensive analysis of the intricate interplay between generative AI and data protection within the European legal framework.

Information

Type
Research Article
Creative Commons
Creative Common License - CCCreative Common License - BY
This is an Open Access article, distributed under the terms of the Creative Commons Attribution licence (http://creativecommons.org/licenses/by/4.0), which permits unrestricted re-use, distribution and reproduction, provided the original article is properly cited.
Copyright
© The Author(s), 2025. Published by Cambridge University Press.