Logo RGPD
RGPD.click
/
  1. Home
  2. Resources
  3. AI and personal data
Courses Guides Blog Resources News
Français (Belgique / France) English Nederlands (België / Nederland)
EU Legal Reference📚 Legal Doctrine Synthesis✓ Controlled Official Sources

The Great Shift: AI, the Web and Our Personal Data

Editorial legal synthesis · Controlled official sources

⚡ In 30 seconds:

Generative AI turns the web into both training material and a distribution channel. The GDPR does not prohibit AI or web scraping, but it requires a purpose, a lawful basis, proportionate collection, effective rights and accountable design.

A Silent Acceleration

Generative tools have made text, image, voice and video production nearly instantaneous. No robust method can establish one precise worldwide percentage of AI-generated web content, especially when human and machine contributions are intertwined.

The relevant question is therefore not only how much content is synthetic, but which personal data was used, who is responsible and how individuals can exercise control.

When the Web Becomes Training Material

Publicly accessible information may still be personal data. Web scraping is not prohibited as such, but purpose, lawful basis, necessity, reasonable expectations, sensitive data and safeguards must be assessed.

A robots.txt file is a relevant technical signal, not a universal GDPR objection mechanism. Its absence is not consent. Effective governance combines exclusions, filtering, provenance records, information and accessible rights channels.

The Difficult Right to Be Forgotten

Deleting the source may not remove copies, indexes or learned effects. Yet it is equally inaccurate to claim that every item is irreversibly dissolved into model weights. Memorisation, extraction and identifiability require a case-specific assessment.

Article 17 does not disappear after training. Depending on the circumstances, an effective response may concern source datasets, retrieval indexes, outputs, filters, unlearning or retraining. Privacy by design should anticipate these requests.

Collective Risks Without an Apocalypse Narrative

Research shows that indiscriminate recursive training on model-generated data can erode diversity and rare cases. This is a conditional scientific risk, not proof that every model must collapse.

Automation can also dilute responsibility and homogenise expression. Data quality, fairness, transparency, profiling risks and the ability to identify the source become central governance concerns.

GDPR and the AI Act

The AI Act and the GDPR are complementary. An AI label does not legalise unlawful data collection, and a GDPR lawful basis does not satisfy every AI Act obligation.

Content Credentials can provide verifiable provenance, but do not certify that a statement is true or exclusively human. Trust requires provenance, accountable actors, effective rights and careful design.

  • Define purposes and responsibilities before collection;
  • Document lawful basis, necessity, exclusions and retention;
  • Assess memorisation, extraction and high-risk impacts;
  • Provide information and workable access, objection and erasure channels.

Verified Official Sources

⚖️ Binding Source
Regulation (EU) 2016/679 (GDPR) · CELEX: 32016R0679 · 2016-04-27

General Data Protection Regulation — EU Reference Legal Framework

Consult official source →
💡 EDPB Art. 64 Opinion
Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models · 2024-12-17

Traitement de données personnelles dans le cadre du développement de modèles d'IA, évaluation du risque de mémorisation/extraction, anonymisation des pondérations, intérêt légitime et mesures d'atténuation (Avis Art. 64 du CEPD)

Consult official source →
📝 Open Public Consultation Draft
Guidelines 03/2026 on web scraping in the context of generative AI · 2026-07-07

Web scraping pour l'entraînement de modèles d'IA générative, licéité (Art. 6), catégories particulières (Art. 9), transparence (Art. 14) et minimisation (version 1.0 adoptée le 7 juillet 2026, consultation publique ouverte jusqu'au 30 oct. 2026)

Consult official source →
⚖️ Binding Source
Règlement (UE) 2024/1689 sur l'intelligence artificielle · CELEX: 32024R1689 · 2024-06-13

Cadre harmonisé de l'intelligence artificielle, notamment transparence de certains systèmes et contenus générés ou manipulés par IA (Article 50)

Consult official source →
🇪🇺 Adopted EDPB Guidelines
Développement des systèmes d’IA : recommandations de la CNIL pour respecter le RGPD · 2025-07-22

Finalité, qualification, base légale, réutilisation, web scraping, minimisation, information, droits, AIPD et protection des données dès la conception

Consult official source →
⚖️ Official Reference
AI models collapse when trained on recursively generated data · 2024-07-24

Risque de dégradation lors d'un entraînement récursif indiscriminé sur des données produites par les générations précédentes de modèles

Consult official source →
📚 Official Explanation
C2PA Content Credentials · 2026-05-01

Standard technique de provenance vérifiable des contenus numériques ; ne constitue pas à lui seul une certification de vérité

Consult official source →

See Also in the Legal Framework

Article 17 GDPR Official Text

Article 17 GDPR : The Right to Erasure and Lawful Exceptions

Conditions for applying Article 17 GDPR: 6 legitimate grounds for erasure, 5 statutory exceptions (freedom of expression...

View document
Article 25 GDPR Official Text

Article 25 GDPR : Data Protection by Design and by Default Principles

Practical implementation of Article 25 GDPR and EDPB Guidelines 4/2019: integrating data protection principles upstream ...

View document
EDPB Guidelines 03/2026 EDPB Doctrine

EDPB Guidelines 03/2026: Web Scraping for Generative AI

Legal analysis of EDPB Guidelines 03/2026 (Draft Version 1.0 open for consultation until 30 Oct 2026): lawful grounds fo...

View document
← Explore this topic in the interactive RGPD.click knowledge base
Reviewed date: 2026-09-10 Last modified: 2026-09-10

Independent legal reference documentation on Regulation (EU) 2016/679 (GDPR).

Home · Resources Index · Privacy Policy · Legal Notice