GUIDELINES ON ARTIFICIAL INTELLIGENCE AND DATA PROTECTION

21 june 2019

According to CONSULTATIVE COMMITTEE OF THE CONVENTION FOR THE PROTECTION OF INDIVIDUALS WITH REGARD TO AUTOMATIC PROCESSING
OF PERSONAL DATA, (Convention 108) (T-PD(2019)01)developers, manufacturers and service providers should take into account the following guidelines:

  1. AI developers, manufacturers and service providers should adopt a values-oriented approach in the design of their products and services, consistent with Convention 108+, in particular with article 10.2, and other relevant instruments of the Council of Europe. 
  2. AI developers, manufacturers and service providers should assess the possible adverse consequences of AI applications on human rights and fundamental freedoms, and, considering these consequences, adopt a precautionary approach based on appropriate risk prevention and mitigation measures. 
  3. In all phases of the processing, including data collection, AI developers, manufacturers and service providers should adopt a human rights by-design approach and avoid any potential biases, including unintentional or hidden, and the risk of discrimination or other adverse impacts on the human rights and fundamental freedoms of data subjects. 
  4. AI developers should critically assess the quality, nature, origin and amount of personal data used, reducing unnecessary, redundant or marginal data during the development, and training phases and then monitoring the model’s accuracy as it is fed with new data. The use of synthetic data5 may be considered as one possible solution to minimise the amount of personal data processed by AI applications. 
  5. The risk of adverse impacts on individuals and society due to de-contextualised data6 and de-contextualised algorithmic models7 should be adequately considered in developing and using AI applications. 
  6. AI developers, manufacturers and service providers are encouraged to set up and consult independent committees of experts from a range of fields, as well as engage with independent academic institutions, which can contribute to designing human rights- based and ethically and socially-oriented AI applications, and to detecting potential bias. Such committees may play an especially important role in areas where transparency and stakeholder engagement can be more difficult due to competing interests and rights, such as in the fields of predictive justice, crime prevention and detection. 
  7. Participatory forms of risk assessment, based on the active engagement of the individuals and groups potentially affected by AI applications, should be encouraged. 
  8. All products and services should be designed in a manner that ensures the right of  individuals not to be subject to a decision significantly affecting them based solely on  automated processing, without having their views taken into consideration. 
  9. In order to enhance users’ trust, AI developers, manufacturers and service providers are encouraged to design their products and services in a manner that safeguards users’ freedom of choice over the use of AI, by providing feasible alternatives to AI 
  10. AI developers, manufacturers, and service providers should adopt forms of algorithm  vigilance that promote the accountability of all relevant stakeholders throughout the entire life cycle of these applications, to ensure compliance with data protection and human rights law and principles. 
  11. Data subjects should be informed if they interact with an AI application and have a right to obtain information on the reasoning underlying AI data processing operations applied to them. This should include the consequences of such reasoning.
  12. The right to object should be ensured in relation to processing based on technologies that influence the opinions and personal development of individuals. 

 

 

News archive

 

Firm news

mar19

19/03/2026

Credito d’imposta per investimenti in beni strumentali

Incentivi per la trasformazione tecnologica e digitale delle imprese Pubblicato il decreto 28 gennaio 2026 che proroga al 31 marzo 2026 i termini per la presentazione delle comunicazioni

mar19

19/03/2026

Sostegno alla domanda di servizi di cloud computing e cyber security

Voucher Cloud & Cybersecurity - Agevolazioni per PMI e lavoratori autonomi  È attiva dal 27 febbraio 2026 la procedura di preregistrazione dedicata ai fornitori interessati

mar19

19/03/2026

Garante Privacy: oltre 40 ispezioni nel primo semestre 2026 tra NIS2, AI nelle scuole e big data

Con il Provvedimento del 30 dicembre 2025 n. 797, il Garante per la protezione dei dati personali (“Garante”) ha approvato il piano delle attività ispettive per il periodo gennaio

Lawyer News

mar21

21/03/2026

Le carte etiche delle piattaforme di intelligenza artificiale

I limiti dell'autoregolamentazione, i profili

mar20

20/03/2026

Divisione (giudiziale) e assegnazione in natura di immobili non divisibili

<p>L’ordinanza n. 3703/2026 della