If you are training AI models for your startup or business, you need to consider what data you are using and whether this is data that you need to obtain consent for.
As a requirement of the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), Personal Information Protection and Electronic Documents Act (PIPEDA), and other privacy laws around the world, consent is required if you are collecting personal data.
You also need to make sure that any consent is clear and active, and consider how your personal data collection affects your AI or machine learning risk assessment under the EU AI Act, if it applies to your business.
This article will cover what types of data AIs and machine learning models collect, what personal data is, what data privacy laws apply, and how to get valid consent.
Use our Cookie Consent all-in-one solution (Privacy Consent) for cookies management to comply with GDPR & CCPA/CPRA and other privacy laws:
- For GDPR, CCPA/CPRA and other privacy laws
- Apply privacy requirements based on user location
- Get consent prior to third-party scripts loading
- Works for desktop, tables and mobile devices
- Customize the appearance to match your brand style
Create your Cookie Consent banner today to comply with GDPR, CCPA/CPRA and other privacy laws:
-
Start the Privacy Consent wizard to create the Cookie Consent code by adding your website information.
-
At Step 2, add in information about your business.
-
At Step 3, select a plan for the Cookie Consent.
-
You're done! Your Cookie Consent Banner is ready. Install the Cookie Consent banner on your website:
Display the Cookie Consent banner on your website by copy-paste the installation code in the
<head></head>section of your website. Instructions how to add in the code for specific platforms (WordPress, Shopify, Wix and more) are available on the Install page.
- 1. What Data Do AIs and Machine Learning Collect?
- 2. What is Personal Data?
- 3. What Laws Apply to Data Processing for AI and ML?
- 3.1. General Data Protection Regulation (GDPR)
- 3.2. California Consumer Privacy Act (CCPA)
- 3.3. Personal Information Protection and Electronic Documents Act (PIPEDA)
- 3.4. EU AI Act
- 4. How Do You Get Consent to Use Data for AI and ML?
- 4.1. Website Footer
- 4.2. Check Boxes on Submission Forms
- 4.3. Pop-Ups or Accept Buttons
- 4.4. Emails
- 5. Summary
What Data Do AIs and Machine Learning Collect?
The type of data collected by AI and machine learning (ML) models depends on the particular AI or ML tool. These are broad categories that do not necessarily describe the extent of data collection.
For example, one AI program could use only synthetic data for training and model development, while another could use significant amounts of personal data.
AI and ML models can collect:
- Text, including users' questions, thoughts, personal information, ideas, creative works, and more
- Images, including satellite images, medical images, and images of real people and their surroundings
- Video, including surveillance footage, video clips of copyrighted works, and user-generated videos of real people and their surroundings
- Audio, including music, podcasts, sound clips and voices belonging to real persons and other persons in their vicinity
- Semi-structured and structured data, including metadata and tags
- Industry data, including financial, banking, and credit information, healthcare data, defense information, retail, marketing data, and more
If your AI or ML model uses user data in any way, this data is likely personal data for the purposes of many privacy laws.
What is Personal Data?
Personal data is defined slightly differently depending on the data privacy law that applies. But in most cases, it is simply information that does identify, or could be used to identify a natural person.
In the GDPR, for example, Article 4 defines personal data as "any information relating to an identified or identifiable natural person … in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.”
You can see this definition below:
Personal information can include, for example:
- First name or last name
- Physical or email address
- IP address
- Social security number
- Tax number
- Credit card number
- Birthdate
- Religion
- Sex
- A profile of shopping or purchasing preferences
If you use any of these types of data, or other similar types of data, for training your AI or ML models, you will need to ensure that you comply with privacy laws that apply to your business.
Let’s take a look at the relevant laws now.
What Laws Apply to Data Processing for AI and ML?
Privacy laws around the world apply to data collected for AI and ML purposes, just like personal data collection for any other purpose.
You also need to consider AI-specific laws like the EU AI Act, and how your data collection affects the risk level of your AI program. Some of the main laws you might need to consider include:
- The General Data Protection Regulation (GDPR)
- The California Consumer Privacy Act (CCPA)
- The Personal Information Protection and Electronic Documents Act (PIPEDA)
- The EU AI Act
Depending on your jurisdiction and business approach, there may also be other laws you need to consider.
Let’s take a look at each of these laws in more detail.
General Data Protection Regulation (GDPR)
The General Data Protection Regulation (GDPR) is a data privacy law that applies to anyone collecting or processing the personal data of EU residents.
If your website, app, or your AI or ML program collects or processes the personal data of EU residents, you need to make sure you comply with the GDPR. One of the requirements is that you need to get consent to any collection, processing, use or sharing of personal data.
The GDPR states that “consent should be given by a clear affirmative act establishing a freely given, specific, informed and unambiguous indication of the data subject’s agreement ….".
You can see this in Recital 32 below:
Some examples given in the recital include ticking a box, choosing technical settings, or other conduct that clearly indicate consent.
Also note that silence, pre-ticked boxes, and inactivity are not considered consent under the GDPR.
California Consumer Privacy Act (CCPA)
If you are processing the data of California residents, you will also need to comply with the California Consumer Privacy Act (CCPA). The CCPA is a California state law that mostly applies to businesses in California.
However, if you operate in California and meet the other CCPA requirements (your annual revenue is over $25 million, or you buy, sell, or share the data of 100,000 or residents or households), you will also need to comply.
For the purposes of the CCPA, you need to get consent if you want to:
- Sell or share a user's information after they have opted out
- Sell a minor's data
- Use sensitive information for additional purposes
- Use third party cookies
To get appropriate consent under the CCPA, you need to make sure that any consent is a "freely given, specific, informed, and unambiguous indication of the consumer's wishes."
If your AI or ML program is likely to use data in these ways, e.g. through sharing data, or using sensitive data for model training purposes beyond the original intended collection, you need to make sure you get consent.
Personal Information Protection and Electronic Documents Act (PIPEDA)
If your business is based in Canada and you are collecting, processing or using the data of Canadian residents, you will have to comply with PIPEDA.
If your business is based elsewhere, but you have substantial connections with Canada or you collect a lot of data of Canadian residents, you will also likely need to comply.
PIPEDA requires that you get the consent of individuals before you process their personal data. Users need to know the purposes for which the information will be used:
Meaningful consent means that users need to actually understand the purposes of data use. This can be difficult with AI models, but you should do your best to describe this in your Privacy Policy.
PIPEDA also provides some information on how you can get consent, which you can see below:
This includes application forms, check boxes, or oral consent. Valid consent is also described in PIPEDA as a consent where the user "would understand the nature, purpose and consequences" of the data collection, use, or disclosure.
PIPEDA doesn't explicitly state that consent needs to be active, but guidelines from The Office of the Privacy Commissioner in Canada state that consent cannot be passive: users "ust be given a choice. These choices must be explained clearly and made easily accessible". You can see this in the guidelines below:
Like for other privacy laws, the main thing is that consent needs to be clear, obvious, and a true act of the user's wishes, not just an assumption.
EU AI Act
Another important law to consider is the EU AI Act, although it doesn't directly relate to data privacy.
Under the EU AI Act, different types of AI systems are assessed for their level of risk. The Act also requires that AI systems should be "developed and used in accordance with privacy and data protection rules, while processing data that meets high standards in terms of quality and integrity."
It also sets out that for developers testing AI systems, AI and ML system creators should request "informed consent of natural persons to participate in testing in real world conditions."
The definition of informed consent is stated as a "freely given, specific, unambiguous and voluntary expression of his or her willingness to participate in a particular testing in real-world conditions." You can see this in section 59 below:
A set of high-risk AI systems have already been described in Section 6 of the EU AI Act, and Annex III. These include systems that are used for safety purposes, as well as those used for biometrics, critical infrastructure, education and training, employment, essential public services, law enforcement, migration, and others. This list can be amended to add additional AI systems, based on a set of criteria that determine their risk.
An AI systems' use of personal data, in particular the use of "special categories" of personal data such as sensitive information, is one of the factors that is considered when determining risk:
If your AI tool or ML program uses sensitive personal data, and is not currently classified as a high-risk system under the EU AI Act, you'll need to consider whether it could be classified as high risk at a later date.
Some potential risks that could also arise through your tool include data interception by third parties if your encryption is insufficient, API misuse and exploitation, data manipulation, DDoS attacks, and vulnerabilities in your tool's interface that leave you open to attack. Keeping track of these and patching any issues can protect user data better.
You can also reduce privacy risks inherent in your AI or ML tool. The European Data Protection Board suggests a number of potential actions, including:
- Limiting sensitive data
- Encouraging users to avoid sharing more data than is necessary
- Requiring user authentication and secure password practices
- Following NIST guidelines and ENISA recommendations
- Clearly communicate with users about how data is handled
- Protecting against adversarial attacks by using input sanitization and filtering, monitoring and logging user queries, looking for unusual patterns of behaviour, and validating outputs
- Educating users on proper usage
While this isn't directly related to collecting consent, if you can show that your AI system uses a good level of data protection and is compliant with data privacy laws, you can increase your compliance with the EU AI Act as well.
How Do You Get Consent to Use Data for AI and ML?
Getting consent for data collection for your AI or ML model depends on when and how you collect the data.
If you are collecting data through a website or app, you'll have to include consent processes that are built in. This includes through:
- Your website footer
- Check boxes on submission forms
- Pop-ups
- Emails
You need to make sure that you get freely given, specific, informed and unambiguous consent. This means that you need to be able to show that your users took an action to show their consent to data collection.
One important thing to note is that for AI applications, consent may be insufficient, even if you get consent perfectly. This is because for a user to give valid consent, they must know what they are consenting to, and for AI applications it can be hard to describe what the application is doing.
However, if you can also show that your AI application pursues a legitimate interest and does not unduly infringe on users rights, you can still go ahead and make use of user data. Asking for consent also helps you to show that you have taken users rights into consideration.
Let's take a look at each of the consent processes in more detail.
Website Footer
In your website footer, you need to include a link to your Privacy Policy that is clear and conspicuous, so that your users can find it easily.
Here's one example from OpenAI of how you can display a link to your Privacy Policy in your website footer.
You can also see in the example from Anthropic below, which makes Claude AI, that the Privacy Policy and other privacy documents are in the footer of the website:
The website for X AI, which makes Grok, also displays the Privacy Policy in the footer of the website:
Note that in all of these examples, the link to the Privacy Policy is the same size and colour as all the other links. It is not obscured or hidden in any way, and it is easy for a user to find when they are browsing the website.
However, displaying your Privacy Policy in your footer is not enough to get consent on its own.
It helps to show that you have provided clear and available information on your website or in your app. But there is no active consent to the policy, and just seeing it during browsing or use is not sufficient.
Now let's take a look at a couple of more active consent processes.
Check Boxes on Submission Forms
Adding check boxes to data fields and submission forms is one way to get active consent to your Privacy Policy, in which you describe how data is collected and used.
The check box should be next to the form field or "Submit" button, and should include a link to your Privacy Policy, so that the user can easily see what they are agreeing to.
Many websites display a statement next to submission form buttons, but they don't include a checkbox to gain clear affirmative consent to the Privacy Policy. Having a statement like this goes some way to showing that a user has consented, but it is not as good as a checkbox, which is really the minimum standard for obtaining active consent.
Here's one example of a statement with a Privacy Policy next to a form field, from the Claude AI signup process:
You can see that there is a clear statement next to the email address field, saying "By continuing, you acknowledge Anthropic's Privacy Policy". However, this is not a clear consent to the contents of the Privacy Policy.
A better approach would be similar to that which is taken by What A Venture, in their newsletter signup process on their website, shown below:
You can see that below the "Enter Your Email" field, there is a checkbox stating "I accept whataventure's Privacy Policy". While the hyperlink isn't visible in the image, on the website when you mouse over the Privacy Policy text, a link to the policy is given.
Another example from La Via Del Te is shown below, with a checkbox stating "I accept the privacy policy".
In this example, a link to the Privacy Policy is also given in the text.
These checkboxes are a much clearer example of active consent to the Privacy Policy, rather than simply having a statement next to the text.
Pop-Ups or Accept Buttons
Another way to get active consent is by using pop-ups or other forms of "Accept" button when a user will submit information, or as soon as they access your website or open your app.
Clicking a button is one good way to show that your users affirmatively and actively consented to your Privacy Policy and the collection of their data for AI or ML purposes.
In this example from DeepSeek, similar to the examples shown above, you can see a statement next to the "Log In" button.
The statement says "By signing up or logging in, you consent to DeepSeek's Terms of Use and Privacy Policy". This statement is a little clearer than the previous ones (in that it actively says "By logging in, you consent"), but it is not as clear as a checkbox.
A much better example is provided by Google Gemini, which provides a set of Terms and Privacy Policy that users need to scroll through and read, before they can click the "Use Gemini" button.
The user needs to actively scroll through the document and policy information before they can continue, and they are also provided with the option to decline and exit if they don't agree with the information.
Here's another example of a pop-up from La Via Del Te, which appears on the screen when the user begins browsing.
The use of pop-ups like this can be done to make sure that users have a real opportunity to see a link to the Privacy Policy and agree to it before they enter any personal information into the website.
Emails
Finally, to make sure that your Privacy Policy is easy to find and frequently shared with your users, you should also include it in the footer of any emails that you send your users. This makes sure that they can easily find it in any communication with you.
Here's one example from MyFitnessPal of how you can include a link to your Privacy Policy in your footer.
You can see that the text is easy to find and easy to read, and is hyperlinked to the Privacy Policy on the website.
Here's another example from WIRED:
In this example as well, you can see the link to the Privacy Policy is provided clearly and simply, with a hyperlink, so that users can find it without any problems.
Summary
Collecting and using personal data for AI or ML model training means that you need to comply with data privacy laws, such as the GDPR, CCPA, and PIPEDA. This is because much of the information that AI and ML models use, is or can be personal information.
Make sure that you collect clear, unambiguous, and active consent from users, that shows that they actively consented to data collection for your AI or ML model. To do this, use approaches including check boxes and "Accept" buttons, as well as providing links to your Privacy Policy in your website footer and in any emails you send.
Also consider how your use of personal data may affect your risk assessment under the EU AI Act. With these steps, you can make sure that consent is collected validly, and that your business is protected from privacy compliance risks or breaches.
The first step to compliance: A Privacy Policy.
Stay compliant with our agreements, policies, and consent banners — everything you need, all in one place.