Skip to content

Privacy vs progress: the UK and EU’s AI balancing act

Avatar photo

By Elizabeth Flynn on

Languages student Elizabeth Flynn explores the tension between promoting tech development and innovation and protecting data privacy laws


The technology space, in particular artificial intelligence (AI), is a rapidly growing sector globally. The UN Trade and Development report (UNCTAD) estimated that by 2033, the global AI market will reach $4.8 trillion (£3.7 trillion), a significant increase from 2023, when it was worth $189 billion (£140 billion). While a divisive topic, raising environmental and ethical concerns, given the rapid growth and prevalence of AI development, legislatures have felt pressure to review and adapt their technology and data privacy regulation, while maintaining their data privacy frameworks.

In November 2025, following former Italian primer minister Mario Draghi’s 2024 report on European Competitiveness, the EU published its Digital Simplification Package, also known as the ‘Digital Omnibus’. It proposes amendments to the well-known General Data Protection Regulation (GDPR) 2018 and EU AI Act 2024, among other pieces of legislation. The EU Commission claims that the package streamlines the EU’s complex digital legislation, “cuts red tape” for businesses and promotes innovation. Similarly, in 2025, the UK relaxed its digital regulation, with the Data (Use and Access) Act 2025 (DUAA) receiving royal assent, amending the UK GDPR and marking the UK’s most significant post-Brexit split from EU digital regulation.

While these changes could eventually reduce reliance on US Big Tech, making the EU and UK valuable competitors, evidence suggests that lobbying from US tech giants might actually be affecting our data privacy protections. Can a balance be struck between promoting competitiveness and digital advancement, while still protecting the well-founded right to privacy?

Want to write for the Legal Cheek Journal?

Find out more

Legitimate interest in the training AI models

AI Large Language Models (LLMs) such as ChatGPT are trained, in part, through Text and Data Mining (TDM). This is when a model scans through text and data which is already on the internet and uses it to help replicate human speech and ideas. The internet, however, holds an abundance of personal data, thus creating legal and ethical concerns when it comes to TDM. The new changes within the EU could simplify said legal ambiguity when it comes to training AI on personal data.

The European Data Protection Board and Member State authorities such as France’s Commission nationale de l’informatique et des libertés, have previously indicated that developers in the EU can use Article 6(1) of the GDPR to claim “legitimate interest” when using personal data for AI development. International law firm Osborne Clarke claims, however, that “in practice, reliance on Art, 6(1)(f) GDPR in the context of AI development and operation often proves challenging”. The EU’s Digital Omnibus proposal could clarify the basis on which developers can train models using personal data, by proposing Article 88c. This amendment would allow data controllers to rely on ‘legitimate interest’10 when processing personal data, alongside a balancing test and specific technical measures including:

– Data minimisation
– Disclosure of residually stored data
– The unconditional right for data subject to object to processing

The latter of which has received criticism from the International Association of Privacy Professionals (The IAPP) as being impractical and difficult to enforce. While in the context of first-party data (data collected directly from the company) it would be easy for subjects to opt out of the processing, in the context of third-party data, and mass web-scraping, how can subjects be aware that their data is being processed in order to then opt out?

The UK’s DUAA has also created space for tech companies to train their models on personal data, through clarifying that the ‘scientific research’ exemptions of the UK GDPR also apply to ‘commercially funded, private sector research’.16 The ICO has specified that individuals can give ‘broad consent to an area of scientific research’ and that entities can re-use personal information for scientific research without providing people with a privacy notice.17 Initially, the House of Lords fought back, claiming that that ‘scientific research’ should only apply to research which was in the public interest, however, this was later rejected.

This clarification that ‘scientific research’ exemptions will apply to private companies means that AI companies will be most likely to be able cut costs and speed up the development process. While on one hand this could be seen as a positive, promoting the UK’s place in a massively growing sector, just as in the EU, it raises ethical concerns regarding the relaxation of personal data protection laws.

Want to write for the Legal Cheek Journal?

Find out more

Definition of personal data

“Legitimate interest” is not the only avenue through which the new EU proposals could benefit AI developers. The EU’s ‘Digital Omnibus’ package could heighten the threshold for what the GDPR currently defines as personal data, thus significantly reducing the scope of protection. Why is the definition of personal data important? Data that is considered “personal data” becomes subject to specific rules and regulations under the GDPR.

The package proposes that data might not be considered “personal data” if an entity
could not reasonably identify an individual from that data set.20 This would mean that a dataset which contains identifiable personal data for one entity might not necessarily contain personal data for another entity if they lack the reasonable means for re- identification (for example, a re-identification key)21. This change is significant, as it would codify the recent decision in Case C-413/23 P EDPS v SRB, and would establish a relative approach to personal data within the EU.22 The EU Commission claims that, in practice, for businesses, this more relaxed approach would remove regulatory hurdles, particularly in the context of sharing pseudonymised data.23 In the context of technological development, this could potentially allow companies to use personal data to train and operate AI systems.

Importantly, however, this has faced significant backlash, including from the EDPB and EDPS who have said that changing the definition of personal data goes ‘far beyond a targeted or technical amendment of the GDPR’. This pushback has been so effective, that a leaked draft from February 2026 suggests that the changes to personal data might not make the final negotiation stages.

While introducing smaller changes, for example to the definition of direct marketing, the UK’s DUAA did not make changes to what is considered personal data, and the UK has kept its original position on pseudonymisation. While the EU’s proposal may seem drastic compared to that of the UK’s, it’s important to remember that the DUAA has been passed into law, whereas the ‘Digital Omnibus’ is likely to be subject to significant changes, particularly after facing harsh criticism.

Criticisms

The proposed changes through have faced significant criticism. Global human rights movement Amnesty International claims that weakening the definition of personal data could “potentially allow Big Tech to harvest more personal data for the training and operation of AI systems” and ultimately put the privacy of individuals at risk.28 Their claim is supported by the fact that in one year alone, US Tech Giant Amazon spent €7 million on lobbying in Brussels.

In addition, when interviewed by EUobserver, Gianclaudio Malgieri, Associate Professor of digital law at Leiden University claimed that “the identifiability of personal data now depends on what a controller claims to know” highlighting how the controller-relative approach may lead to companies having excessive leeway over what data they can process, particularly in the context of AI development.

Want to write for the Legal Cheek Journal?

Find out more

Conclusion

For businesses, these changes and proposals are mostly positive, as they would cut the costs and regulatory burdens which sometimes stand in the way of development. On the other hand, however, both Amnesty International and Gianclaudio Malgieri highlight relevant concerns that arise when proposing changes to the GDPR. As the UK’s DUAA has already been passed into law, a true comparison with the EU’s proposal cannot be made, as the latter remains subject to, and is likely to, change. Ultimately, however, legislatures have a responsibility to find a balance between promoting innovation and protecting our privacy. It would seem, at the moment, that both the UK and the EU have taken a business first approach when considering changes to digital regulation.

Elizabeth Flynn is a penultimate year Spanish and Italian student at Durham University, and has just completed an internship at a law firm in Barcelona as part of her year abroad. During her internship she focused on intellectual property and data privacy regulation and also has an interest in commercial law. 

guest

0 Comments
Oldest
Newest Most Voted

Related Stories

Can AI close the justice gap?

LLM grad Sakshi Sahoo examines whether AI-powered legal services could put justice within reach for more people across the UK

5 days ago
1