Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models
- Document
- 17 December 2024
- Event
- 17 December 2024
- Retrieved
- 16 September 2026
The design
On 17 December 2024, the European Data Protection Board, which coordinates the EU's national data-protection authorities, adopted Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models. The opinion itself answers a formal request from Ireland's Data Protection Commission under Article 64(2) of the GDPR, covering when a trained AI model can be considered anonymous, how a company can justify "legitimate interest" as its legal basis for training on personal data, and what happens downstream if that training was unlawful. The opinion names, as one example of a legitimate interest a company might claim, "developing the service of a conversational agent to assist users" — language that reaches directly into how a companion chatbot's training data could be defended under EU law.
What the evidence says
The opinion is the EDPB's own interpretation of the GDPR, not a court ruling and not new legislation; its landing page confirms it gives "general application" guidance that national authorities must take utmost account of, without creating new statutory text. On anonymity, the opinion states a model trained on personal data cannot automatically be considered anonymous, and sets a test — that extracting personal data from the model or its outputs must be insignificantly likely — before an anonymity claim can be accepted by a supervisory authority.
What it asks of people
The opinion creates no new right a companion-app user can invoke directly; it tells supervisory authorities what to check when a company's use of personal data for AI training is challenged. In practice a company built on a large volume of conversation data is asked to document why its interest in building or improving that service does not override the interests, rights, and freedoms of the people whose data trained it, weighed through the GDPR's established three-step legitimate-interest test the opinion recites rather than replaces.
Privacy and safeguards
The opinion lists mitigating measures a company can adopt in training and deployment, such as limiting the personal data collected for training and reducing how identifiable it remains, but declines to mandate any single method, leaving authorities to judge case by case. It also addresses unlawfully processed training data later anonymised: a subsequent, separate processing of newly collected personal data still falls under the GDPR even if the earlier unlawful step does not taint it. None of this substitutes for a national authority's own enforcement action against a named company.
- Has any national data-protection authority applied this opinion's anonymity test to a named companion-app maker's model?
- Does a company's privacy policy identify "legitimate interest" as its legal basis for training on chat data, and does it name the balancing test this opinion describes?
- What mitigating measures, if any, does a given companion app disclose for limiting the personal data it collects during training?
Opinion 28/2024 sits a level above the national orders this site already tracks: it does not fine anyone, but it gives every EU data-protection authority a shared, detailed standard for judging how a company trained its conversational model on personal data in the first place.
Sources & reading trail
The opinion's own text on the anonymity test, the legitimate-interest three-step test, the conversational-agent example, and the treatment of unlawfully processed training data.
Source published: 17 December 2024 · Retrieved: 16 September 2026
Confirms the opinion's adoption date, its basis in an Article 64(2) request from Ireland's DPC, and its status as EDPB guidance rather than legislation.
Source published: 17 December 2024 · Retrieved: 16 September 2026
Product documents, regulator records and studies establish the entry; the design reading is AI Companions editorial analysis. This retrospective draft does not imply the site published on the event date.