Spanish regulator clarifies GDPR accuracy rules for AI data
New guidance says AI datasets lacking quality cannot be deemed necessary.
The Spanish Data Protection Agency (AEPD) has published guidance examining how data quality relates to the GDPR’s accuracy principle when personal data is processed using AI. The document argues that, although closely linked, data quality is broader than the GDPR’s concept of accuracy because it also applies to non-personal data and encompasses requirements beyond the regulation.
According to the guide, properties such as veracity and currentness should only be required where they are genuinely necessary for the intended purpose.
The AEPD also stresses that non-personal data feeding into processes involving personal data must meet appropriate quality standards whenever it could influence the outcome. Assessing quality should not stop at the input stage: without objective metrics to evaluate the quality of outputs, the guide argues, organisations cannot determine whether a system is fulfilling its intended purpose.
The guidance has particular significance for AI datasets, stating that data which does not meet the required quality standards cannot be considered necessary for processing. Access to such data may therefore only be justified for the purpose of assessing its quality.
Why does it matter?
The guidance addresses a practical challenge that has become increasingly important as AI adoption expands. Organisations need large volumes of data to develop effective systems, while data protection law requires that personal data be limited to what is genuinely necessary. By distinguishing the broader concept of data quality from the GDPR’s narrower accuracy principle, the AEPD provides organisations with a more practical framework for deciding how much veracity, precision or currentness their data actually requires for a given purpose.
The emphasis on evaluating outputs as well as inputs also reflects a broader evolution in AI governance. Rather than treating data protection as a one-off compliance exercise at the point of data collection, the guidance encourages organisations to embed data quality assessment, accountability and multidisciplinary oversight throughout an AI system’s entire life cycle.
Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!
