1. Home
  2. News
  3. Artificial Intelligence and Data Protection: LDI NRW Highlights New Challenges for Businesses
  • Data Protection

Artificial Intelligence and Data Protection: LDI NRW Highlights New Challenges for Businesses

The 30th Activity Report by the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW) sheds light on the current challenges companies face when using artificial intelligence (AI). The report focuses on ensuring compliance with data protection regulations while deploying generative AI systems and critically examines the use of emotion recognition software.

Generative AI Models: A Legal Minefield for Data Protection

The LDI NRW emphasizes that generative AI systems—such as large language models (LLMs)—often process vast amounts of personal data, frequently without the data subjects' knowledge. This often occurs through the automated collection of publicly available web content. While companies may rely on the “legitimate interest” basis under Article 6(1)(f) of the GDPR, the LDI NRW makes it clear that a careful balancing of interests is absolutely essential. Simply making data publicly available online does not automatically justify its use for training AI models.

According to the report, a particularly problematic issue is the risk of so-called inference errors: AI systems can generate false or misleading information about individuals, where the origin and truthfulness of such data is often no longer traceable. Deleting or correcting personal data is technically complex and, with generative models, remains an unsolved problem in many cases—it often requires retraining the entire model.

Emotion Recognition Software: Strong Criticism and Clear Boundaries

A serious case highlighted: A company in a call center used AI-based emotion recognition software to analyze the moods of employees and customers based on voice data—without informed consent and without performing a data protection impact assessment. The LDI NRW regards this as a severe intrusion on personal rights and therefore banned further use. A sanction is also being considered.

Obligations for Companies: Clear Rules for the Use of AI

The report underscores that data protection remains non-negotiable in the age of artificial intelligence. Companies developing or deploying AI systems are required to:

  • Establish a clear legal basis for every processing of personal data,
  • Effectively implement data subject rights such as access, rectification, and erasure,
  • Conduct data protection impact assessments (DPIA) at an early stage.

Especially for generative AI systems, principles such as “privacy by design” and “privacy by default” must be upheld. In case of doubt, seeking advice from specialized legal counsel is recommended.

Conclusion

The activity report makes it clear: Artificial intelligence must not pose a risk to the rights and freedoms of individuals. For businesses, this means data protection is mandatory—it is essential to avoid fines and to sustainably maintain the trust of customers and staff.

About Cookies

This website uses cookies. Those have two functions: On the one hand they are providing basic functionality for this website. On the other hand they allow us to improve our content for you by saving and analyzing anonymized user data. You can redraw your consent to to using these cookies at any time. Find more information regarding cookies on our Data Protection Declaration and regarding us on the Imprint.
Mandatory

These cookies are needed for a smooth operation of our website.

Name Purpose Lifetime Type Provider
CookieConsent Saves your consent to using cookies. 1 year HTML Website
fe_typo_user Assigns your browser to a session on the server. session HTTP Website
PHPSESSID Temporary cookies which is required by PHP to temporarily store data. session HTTP Website
__cfduid missing translation: trackingobject.__cfduid.desc 30 missing translation: duration.days-session HTTP Cloudflare/ report-uri.com
Statistics

With the help of these statistics cookies we check how visitors interact with our website. The information is collected anonymously.

Name Purpose Lifetime Type Provider
_pk_id Used to store a few details about the user such as the unique visitor ID. 13 months HTML Matomo
_pk_ref Used to store the attribution information, the referrer initially used to visit the website. 6 months HTML Matomo
_pk_ses Short lived cookie used to temporarily store data for the visit. 30 minutes HTML Matomo
_pk_cvar Short lived cookie used to temporarily store data for the visit. 30 minutes HTML Matomo
MATOMO_SESSID Temporary cookies which is set when the Matomo Out-out is used. session HTTP Matomo
_pk_testcookie missing translation: trackingobject._pk_testcookie.desc session HTML Matomo