Article content
In briefShow moreShow lessThe EDPB adopted Opinion 28/2024 on personal data in developing and deploying AI models.
- The EDPB adopted Opinion 28/2024 on personal data in developing and deploying AI models.
- The EDPB rejected a general assumption that a trained model is always anonymous.
- EDPB guidance is relevant to Norwegian controllers because the GDPR applies through the EEA. It is not a legislative amendment.
What happened
The EDPB adopted Opinion 28/2024 on personal data in developing and deploying AI models. It addresses when a model may be anonymous, how legitimate interests can be assessed, and how unlawful processing during development may affect deployment.
The EDPB rejected a general assumption that a trained model is always anonymous. Authorities must assess whether people can be identified or training data extracted. Legitimate interests require purpose, necessity and a concrete balancing test.
Legal status in Norway
EDPB guidance is relevant to Norwegian controllers because the GDPR applies through the EEA. It is not a legislative amendment.
What the sources clarify
For anonymity, the EDPB required a concrete assessment of whether people could be identified or personal data extracted through model queries. Reliance on legitimate interests required a documented purpose, necessity and balancing test, including what individuals could reasonably expect. The EDPB also said unlawful processing during development could affect the legality of deployment unless the model had subsequently become duly anonymous.
Training-data provenance, filtering and deletion capability therefore became supplier due-diligence questions. A statement that a model 'does not store data' is not evidence that the legal threshold for anonymity has been met.
Practical supplier review should cover data categories and sources, filtering of special-category data, extraction and memorisation tests, and handling of individual objections. Answers must be assessed against the planned use; a generic model card does not replace the organisation's necessity and balancing tests. New model versions should trigger review when training sources or safeguards change.
Practical implications
A use decision should record the data sources and model tests supporting it, and the changes that invalidate the assessment. Where the supplier cannot adequately describe training sources or extraction tests, the organisation should restrict inputs, disable retention or choose a solution with stronger evidence.
Sources
European Data Protection Board: “EDPB opinion on AI models,” 18 December 2024.
European Data Protection Board: “EDPB Opinion 28/2024 on AI models,” 18 December 2024.
For discussion
Which control should we verify first?







