The draft GDPR revision under discussion in the EU Council would make it explicit that personal data can be processed on the basis of legitimate interest when an AI system or model is developed and operated. It would also add a narrow exception covering sensitive data that ends up in the process unintentionally. This is still a working text, not the law in force. A political direction can be criticised before it becomes an obligation.
My problem is not understanding the sales pitch. Everyone understands less bureaucracy and more competitiveness. The problem is working out which protection is supposed to survive the journey, and why the answer keeps turning up in passages that have been struck through.
Legitimate interest is not ownership
Legitimate interest already exists under Article 6(1)(f). It is not a magic formula that converts somebody else’s personal information into company property. It requires an interest that genuinely exists, processing that is genuinely necessary, and a balancing exercise that does not hand the organisation automatic priority over the rights of the people involved.
The EDPB’s December 2024 opinion accepted that this basis can be invoked for AI models, provided the three-step assessment is actually carried out case by case. The proposed Article 88 bis would write an explicit reference to AI into the regulation itself. That is not the same as declaring that every AI project wins the balancing exercise, and it would be careless to pretend otherwise.
The distinction matters because a political argument can be ferocious without becoming legally sloppy. Calling this a permission already granted to everyone would be wrong. Equally, pointing out that some safeguards remain does not settle an argument about the safeguards that are being taken away.
What disappears between one version and the next
In the revision described, the specific provision for an unconditional right to object to AI processing is deleted in full. What replaces it is lighter: a reminder that the controller must still choose an appropriate legal basis under Article 6, plus a new paragraph calling for appropriate technical and organisational measures. The recitals that spelled out the same guarantee are struck through, and the reference to an unconditional objection does not reappear in the text that absorbs them.
The ordinary right to object under Article 21 remains. When processing rests on legitimate interest, however, that right is not absolute: the controller may try to demonstrate compelling legitimate grounds that override the individual’s interests. Swapping a stronger proposed guarantee for the existing framework is not a stylistic edit.
That is the practical question hiding underneath the drafting: when a person says no, what actually happens next? A clear stopping rule and a contested balancing exercise are not the same burden. Both are written in legal language, but only one makes the citizen negotiate the meaning of their own refusal after the fact.
Sensitive data and the price of cleaning up
The proposed exception concerns the unintended and residual processing of special categories of data during the development and technical operation of an AI system. The controller would first have to take measures to avoid collecting such information, and then remove it without delay if it turns up anyway.
Where removal is technically impossible or would demand disproportionate effort, the data could be retained under conditions that prevent further processing, use in outputs and disclosure to third parties. That is not an unrestricted licence, and the conditions cannot honestly be edited out of a criticism.
The threshold, though, deserves a hard look. In this revision the word equivalent to “manifestly” is dropped from the disproportionate-effort test. That deletion is not decorative. It lowers the bar an organisation has to clear in order to argue that cleaning up its own dataset would simply cost too much. The accompanying recital even offers the helpful example of data already memorised inside the model, where removal would mean rebuilding the system.
A hard engineering problem does not evaporate because a legislator writes a prohibition. But it does not become the citizen’s problem either, purely because solving it would be expensive for the company that built the thing.
An administration that communicates through deletions
The stated aim is regulatory simplification and European competitiveness. Where the text is actually heading is much harder to say, and I doubt it is any clearer inside the institutions that produced it. Read one version against the next and the office responsible for industrial policy and the office responsible for fundamental rights look far enough apart that their only working communication channel is the strikethrough, while the word simplification sends everybody within earshot to sleep. Underneath the drafting sits a requirement nobody has met: a person should be able to understand whether their information can be used, how to object, and what protection actually follows from objecting.
Nothing here is settled. Member states still have to agree a position, and the trilogue with the European Parliament can change the text substantially. Necessity, proportionality, minimisation and purpose limitation do not vanish because a draft mentions AI. But a reform that forces citizens to compare successive drafts, crossed-out recitals and technical exceptions just to work out how to say no has simplified somebody’s work. It has not simplified theirs.
Raffaele Di Marzio
All my “insane” books on cybersecurity and governance are here 👇 https://www.amazon.it/stores/author/B0FB47T6Q4/allbooks
