The Spanish authority analyzes the quality, accuracy, and minimization of personal data in processing involving artificial intelligence systems

The Spanish Data Protection Agency (AEPD) has published a technical note analyzing the application of the principles of quality, accuracy, and data minimization in processing involving artificial intelligence systems.
The document specifies that the GDPR accuracy principle should not be interpreted absolutely, but in relation to the purpose of the processing. Thus, data do not have to be systematically exhaustive or perfectly up to date, but must be adequate to achieve the intended objective, an approach that prevents conflicts with the minimization principle and avoids disproportionate burdens. Quality must be assessed at the level of the entire dataset used to develop the systems, where representativeness and absence of bias may take precedence over the accuracy of each individual record. This requirement extends to AI-generated results, such as inferences or predictions, which must not produce incorrect representations of data subjects.
The required level of accuracy varies according to the impact of the processing on individuals, and practices such as synthetic data generation or bias correction are considered compatible with the GDPR if justified by the purpose and do not create negative effects. The AEPD distinguishes the data quality required for system development from that required during their operation, the latter phase requiring higher guarantees. The importance of documented data governance is emphasized, with objective quality requirements and continuous monitoring, in accordance with the principle of proactive accountability.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire