A new scientific publication by Julie Mannekens from KU Leuven’s Centre for IT & IP Law (CiTiP) examines an increasingly relevant data protection challenge: what happens when artificial intelligence systems process or infer special categories of personal data without this being intended?
The publication, “Addressing unintended processing of special categories of personal data in AI: between Article 9(1) and Article 9(2) GDPR”, explores the relationship between the general prohibition on processing special categories of personal data under Article 9(1) of the General Data Protection Regulation (GDPR) and the exceptions provided under Article 9(2).
As AI systems become increasingly sophisticated, they may derive or generate sensitive information that was not explicitly provided as input and whose processing was not originally intended. This raises important legal questions concerning the circumstances in which such processing falls within the scope of Article 9 GDPR and the implications for organisations developing and deploying AI systems.
The publication contributes to the broader discussion on how existing data protection requirements can be effectively applied in the context of rapidly evolving AI technologies. These questions are particularly relevant to the ACHILLES project, which combines technical innovation with legal and ethical perspectives to support the development of AI systems that are lighter, clearer and safer.
Through the involvement of KU Leuven, ACHILLES addresses legal, ethical and privacy-related considerations alongside its technological research, helping ensure that advances in AI are accompanied by a careful assessment of their implications for fundamental rights, data protection and regulatory compliance.