AI Summarize

Share

If you are training AI models for your startup or business, you need to consider what data you are using and whether this is data that you need to obtain consent for.

As a requirement of the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), Personal Information Protection and Electronic Documents Act (PIPEDA), and other privacy laws around the world, consent is required if you are collecting personal data.

You also need to make sure that any consent is clear and active, and consider how your personal data collection affects your AI or machine learning risk assessment under the EU AI Act, if it applies to your business.

This article will cover what types of data AIs and machine learning models collect, what personal data is, what data privacy laws apply, and how to get valid consent.



What Data Do AIs and Machine Learning Collect?

The type of data collected by AI and machine learning (ML) models depends on the particular AI or ML tool. These are broad categories that do not necessarily describe the extent of data collection.

For example, one AI program could use only synthetic data for training and model development, while another could use significant amounts of personal data.

AI and ML models can collect:

  • Text, including users' questions, thoughts, personal information, ideas, creative works, and more
  • Images, including satellite images, medical images, and images of real people and their surroundings
  • Video, including surveillance footage, video clips of copyrighted works, and user-generated videos of real people and their surroundings
  • Audio, including music, podcasts, sound clips and voices belonging to real persons and other persons in their vicinity
  • Semi-structured and structured data, including metadata and tags
  • Industry data, including financial, banking, and credit information, healthcare data, defense information, retail, marketing data, and more

If your AI or ML model uses user data in any way, this data is likely personal data for the purposes of many privacy laws.

What is Personal Data?

Personal data is defined slightly differently depending on the data privacy law that applies. But in most cases, it is simply information that does identify, or could be used to identify a natural person.

In the GDPR, for example, Article 4 defines personal data as "any information relating to an identified or identifiable natural person … in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.”

You can see this definition below:

A definition from GDPR Article 4 that explains what personal data is, focusing on any information relating to an identified or identifiable natural person

Personal information can include, for example:

  • First name or last name
  • Physical or email address
  • IP address
  • Social security number
  • Tax number
  • Credit card number
  • Birthdate
  • Religion
  • Sex
  • A profile of shopping or purchasing preferences

If you use any of these types of data, or other similar types of data, for training your AI or ML models, you will need to ensure that you comply with privacy laws that apply to your business.

Let’s take a look at the relevant laws now.

What Laws Apply to Data Processing for AI and ML?

Privacy laws around the world apply to data collected for AI and ML purposes, just like personal data collection for any other purpose.

You also need to consider AI-specific laws like the EU AI Act, and how your data collection affects the risk level of your AI program. Some of the main laws you might need to consider include:

  • The General Data Protection Regulation (GDPR)
  • The California Consumer Privacy Act (CCPA)
  • The Personal Information Protection and Electronic Documents Act (PIPEDA)
  • The EU AI Act

Depending on your jurisdiction and business approach, there may also be other laws you need to consider.

Let’s take a look at each of these laws in more detail.

General Data Protection Regulation (GDPR)

The General Data Protection Regulation (GDPR) is a data privacy law that applies to anyone collecting or processing the personal data of EU residents.

If your website, app, or your AI or ML program collects or processes the personal data of EU residents, you need to make sure you comply with the GDPR. One of the requirements is that you need to get consent to any collection, processing, use or sharing of personal data.

The GDPR states that “consent should be given by a clear affirmative act establishing a freely given, specific, informed and unambiguous indication of the data subject’s agreement ….".

You can see this in Recital 32 below:

Excerpt from GDPR Recital 32 defining consent as a clear affirmative act that signifies agreement to personal data processing

Some examples given in the recital include ticking a box, choosing technical settings, or other conduct that clearly indicate consent.

Also note that silence, pre-ticked boxes, and inactivity are not considered consent under the GDPR.

California Consumer Privacy Act (CCPA)

If you are processing the data of California residents, you will also need to comply with the California Consumer Privacy Act (CCPA). The CCPA is a California state law that mostly applies to businesses in California.

However, if you operate in California and meet the other CCPA requirements (your annual revenue is over $25 million, or you buy, sell, or share the data of 100,000 or residents or households), you will also need to comply.

For the purposes of the CCPA, you need to get consent if you want to:

  • Sell or share a user's information after they have opted out
  • Sell a minor's data
  • Use sensitive information for additional purposes
  • Use third party cookies

To get appropriate consent under the CCPA, you need to make sure that any consent is a "freely given, specific, informed, and unambiguous indication of the consumer's wishes."

A section from the California Consumer Privacy Act (CCPA) establishing the requirement for obtaining a freely given, specific, informed, and unambiguous indication of consumer consent

If your AI or ML program is likely to use data in these ways, e.g. through sharing data, or using sensitive data for model training purposes beyond the original intended collection, you need to make sure you get consent.

Personal Information Protection and Electronic Documents Act (PIPEDA)

If your business is based in Canada and you are collecting, processing or using the data of Canadian residents, you will have to comply with PIPEDA.

If your business is based elsewhere, but you have substantial connections with Canada or you collect a lot of data of Canadian residents, you will also likely need to comply.

PIPEDA requires that you get the consent of individuals before you process their personal data. Users need to know the purposes for which the information will be used:

A snippet from Canada Personal Information Protection and Electronic Documents Act (PIPEDA) specifying the necessity of obtaining individuals' consent for data processing

Meaningful consent means that users need to actually understand the purposes of data use. This can be difficult with AI models, but you should do your best to describe this in your Privacy Policy.

PIPEDA also provides some information on how you can get consent, which you can see below:

A section from PIPEDA discussing methods for obtaining consent which includes application forms, check boxes, or oral consent

This includes application forms, check boxes, or oral consent. Valid consent is also described in PIPEDA as a consent where the user "would understand the nature, purpose and consequences" of the data collection, use, or disclosure.

An excerpt from PIPEDA defining valid consent as when users understand the consequences of data collection, use, or disclosure

PIPEDA doesn't explicitly state that consent needs to be active, but guidelines from The Office of the Privacy Commissioner in Canada state that consent cannot be passive: users "ust be given a choice. These choices must be explained clearly and made easily accessible". You can see this in the guidelines below:

Guidelines from the Office of the Privacy Commissioner in Canada stating that for consent receipt to be valid, options must be clearly explained and accessible

Like for other privacy laws, the main thing is that consent needs to be clear, obvious, and a true act of the user's wishes, not just an assumption.

EU AI Act

Another important law to consider is the EU AI Act, although it doesn't directly relate to data privacy.

Under the EU AI Act, different types of AI systems are assessed for their level of risk. The Act also requires that AI systems should be "developed and used in accordance with privacy and data protection rules, while processing data that meets high standards in terms of quality and integrity."

It also sets out that for developers testing AI systems, AI and ML system creators should request "informed consent of natural persons to participate in testing in real world conditions."

The definition of informed consent is stated as a "freely given, specific, unambiguous and voluntary expression of his or her willingness to participate in a particular testing in real-world conditions." You can see this in section 59 below:

A section from the EU AI Act stating informed consent as a mandatory requisite for persons participating in AI system testing under real-world conditions

A set of high-risk AI systems have already been described in Section 6 of the EU AI Act, and Annex III. These include systems that are used for safety purposes, as well as those used for biometrics, critical infrastructure, education and training, employment, essential public services, law enforcement, migration, and others. This list can be amended to add additional AI systems, based on a set of criteria that determine their risk.

An AI systems' use of personal data, in particular the use of "special categories" of personal data such as sensitive information, is one of the factors that is considered when determining risk:

Extract from the EU AI Act stating that handling and processing sensitive data by AI systems is a considerable factor when determining risk levels

If your AI tool or ML program uses sensitive personal data, and is not currently classified as a high-risk system under the EU AI Act, you'll need to consider whether it could be classified as high risk at a later date.

Some potential risks that could also arise through your tool include data interception by third parties if your encryption is insufficient, API misuse and exploitation, data manipulation, DDoS attacks, and vulnerabilities in your tool's interface that leave you open to attack. Keeping track of these and patching any issues can protect user data better.

You can also reduce privacy risks inherent in your AI or ML tool. The European Data Protection Board suggests a number of potential actions, including:

  • Limiting sensitive data
  • Encouraging users to avoid sharing more data than is necessary
  • Requiring user authentication and secure password practices
  • Following NIST guidelines and ENISA recommendations
  • Clearly communicate with users about how data is handled
  • Protecting against adversarial attacks by using input sanitization and filtering, monitoring and logging user queries, looking for unusual patterns of behaviour, and validating outputs
  • Educating users on proper usage

While this isn't directly related to collecting consent, if you can show that your AI system uses a good level of data protection and is compliant with data privacy laws, you can increase your compliance with the EU AI Act as well.

Getting consent for data collection for your AI or ML model depends on when and how you collect the data.

If you are collecting data through a website or app, you'll have to include consent processes that are built in. This includes through:

  • Your website footer
  • Check boxes on submission forms
  • Pop-ups
  • Emails

You need to make sure that you get freely given, specific, informed and unambiguous consent. This means that you need to be able to show that your users took an action to show their consent to data collection.

One important thing to note is that for AI applications, consent may be insufficient, even if you get consent perfectly. This is because for a user to give valid consent, they must know what they are consenting to, and for AI applications it can be hard to describe what the application is doing.

However, if you can also show that your AI application pursues a legitimate interest and does not unduly infringe on users rights, you can still go ahead and make use of user data. Asking for consent also helps you to show that you have taken users rights into consideration.

Let's take a look at each of the consent processes in more detail.

In your website footer, you need to include a link to your Privacy Policy that is clear and conspicuous, so that your users can find it easily.

Here's one example from OpenAI of how you can display a link to your Privacy Policy in your website footer.

Screenshot of OpenAI website footer with clearly visible Privacy Policy link

You can also see in the example from Anthropic below, which makes Claude AI, that the Privacy Policy and other privacy documents are in the footer of the website:

Screenshot showcasing Anthropic's website footer displaying a conveniently accessible Privacy Policy link

The website for X AI, which makes Grok, also displays the Privacy Policy in the footer of the website:

Display of X AI's website footer with an evident Privacy Policy link for user accessibility

Note that in all of these examples, the link to the Privacy Policy is the same size and colour as all the other links. It is not obscured or hidden in any way, and it is easy for a user to find when they are browsing the website.

However, displaying your Privacy Policy in your footer is not enough to get consent on its own.

It helps to show that you have provided clear and available information on your website or in your app. But there is no active consent to the policy, and just seeing it during browsing or use is not sufficient.

Now let's take a look at a couple of more active consent processes.

Check Boxes on Submission Forms

Adding check boxes to data fields and submission forms is one way to get active consent to your Privacy Policy, in which you describe how data is collected and used.

The check box should be next to the form field or "Submit" button, and should include a link to your Privacy Policy, so that the user can easily see what they are agreeing to.

Many websites display a statement next to submission form buttons, but they don't include a checkbox to gain clear affirmative consent to the Privacy Policy. Having a statement like this goes some way to showing that a user has consented, but it is not as good as a checkbox, which is really the minimum standard for obtaining active consent.

Here's one example of a statement with a Privacy Policy next to a form field, from the Claude AI signup process:

Screenshot of Claude AI signup process highlighting the declaration for acknowledging Anthropic's Privacy Policy

You can see that there is a clear statement next to the email address field, saying "By continuing, you acknowledge Anthropic's Privacy Policy". However, this is not a clear consent to the contents of the Privacy Policy.

A better approach would be similar to that which is taken by What A Venture, in their newsletter signup process on their website, shown below:

Newsletter signup process on the What A Venture website featuring a check box for accepting the website's Privacy Policy

You can see that below the "Enter Your Email" field, there is a checkbox stating "I accept whataventure's Privacy Policy". While the hyperlink isn't visible in the image, on the website when you mouse over the Privacy Policy text, a link to the policy is given.

Another example from La Via Del Te is shown below, with a checkbox stating "I accept the privacy policy".

Screenshot of La Via Del Te's form with a checkbox accepting the Privacy Policy

In this example, a link to the Privacy Policy is also given in the text.

These checkboxes are a much clearer example of active consent to the Privacy Policy, rather than simply having a statement next to the text.

Pop-Ups or Accept Buttons

Another way to get active consent is by using pop-ups or other forms of "Accept" button when a user will submit information, or as soon as they access your website or open your app.

Clicking a button is one good way to show that your users affirmatively and actively consented to your Privacy Policy and the collection of their data for AI or ML purposes.

In this example from DeepSeek, similar to the examples shown above, you can see a statement next to the "Log In" button.

The statement says "By signing up or logging in, you consent to DeepSeek's Terms of Use and Privacy Policy". This statement is a little clearer than the previous ones (in that it actively says "By logging in, you consent"), but it is not as clear as a checkbox.

Screenshot of DeepSeek login page illustrating a statement capturing user's consent to DeepSeek's Terms of Use and Privacy Policy

A much better example is provided by Google Gemini, which provides a set of Terms and Privacy Policy that users need to scroll through and read, before they can click the "Use Gemini" button.

The user needs to actively scroll through the document and policy information before they can continue, and they are also provided with the option to decline and exit if they don't agree with the information.

Screenshot of Google Gemini highlighting user requirement to actively scroll through policy information before proceeding

Here's another example of a pop-up from La Via Del Te, which appears on the screen when the user begins browsing.

Pop-up window on La Via Del Te's website used for user consent acquisition

The use of pop-ups like this can be done to make sure that users have a real opportunity to see a link to the Privacy Policy and agree to it before they enter any personal information into the website.

Emails

Finally, to make sure that your Privacy Policy is easy to find and frequently shared with your users, you should also include it in the footer of any emails that you send your users. This makes sure that they can easily find it in any communication with you.

Here's one example from MyFitnessPal of how you can include a link to your Privacy Policy in your footer.

Screenshot of MyFitnessPal email footer containing a clear link to the Privacy Policy

You can see that the text is easy to find and easy to read, and is hyperlinked to the Privacy Policy on the website.

Here's another example from WIRED:

Screenshot of WIRED email footer showcasing a simply accessible link to their Privacy Policy

In this example as well, you can see the link to the Privacy Policy is provided clearly and simply, with a hyperlink, so that users can find it without any problems.

Summary

Collecting and using personal data for AI or ML model training means that you need to comply with data privacy laws, such as the GDPR, CCPA, and PIPEDA. This is because much of the information that AI and ML models use, is or can be personal information.

Make sure that you collect clear, unambiguous, and active consent from users, that shows that they actively consented to data collection for your AI or ML model. To do this, use approaches including check boxes and "Accept" buttons, as well as providing links to your Privacy Policy in your website footer and in any emails you send.

Also consider how your use of personal data may affect your risk assessment under the EU AI Act. With these steps, you can make sure that consent is collected validly, and that your business is protected from privacy compliance risks or breaches.

Privacy Policy Generator
The first step to compliance: A Privacy Policy.

Stay compliant with our agreements, policies, and consent banners — everything you need, all in one place.

Generate Privacy Policy