Handling of personal data by technology
Personal data is a significant resource for the development of the digital economy, but it also belongs to individuals who have a right to privacy. In September 2024, regulators in several EU countries, following investigations, decided on rules for the use of personal data for AI training, databases and cookie banners.
Из выпуска мониторинга No. 9, September 2024 · выпуск целиком, PDF · на сайте Института Гайдара

Personal data is a significant resource for the development of the digital economy, but it also belongs to individuals who have a right to privacy. In September 2024, regulators in several EU countries, following investigations, decided on rules for the use of personal data for AI training, databases and cookie banners.
Experience of the EU countries
On September 4, 2024, the Irish DPC concluded the proceedings against X (formerly1 Twitter), which began in the High Court on2 August 8. The cause was the processing by X, between May 7 and August 1, 2024, of personal data from the public posts of Europeans to train its AI tool Grok. The Commission sued X, seeking an urgent order to compel the company to suspend, restrict or prohibit their processing. This was the first time this had been undertaken
On August 8, 2024, X agreed to suspend the contested processing of personal data. As a result, the proceedings were concluded on the basis of X's agreement to adhere to the terms of the undertakings on the permanent basis, the specific content of which the Commission does not disclose.
In doing so, the Commission has requested clarification from the European Data3 Protection Board pursuant to Article 64(2)4 GDPR on the extent to which personal data may be processed for the development and training of AI and the legal basis for such processing. The clarification has not yet been released.
This case shows that at the current stage the regulation of the use of personal data has gaps, the filling of which in practice depends on agreements between the regulator and the data processor.
Also in September 2024, the Dutch Data5 Protection Authority imposed a €30.5 million6 fine on the US company Clearview AI.
Clearview AI, a for-profit company with no presence in Europe, offers facial recognition services to intelligence and investigation agencies. The company's customers provide it with images to find out the identity of the people in the pictures. For this purpose, the company has a database of more than 30 billion photos of people, which it automatically collects from the Internet and then creates a unique biometric code for each face without people's knowledge or consent.
Thus, any person whose photo is available on the Internet can end up in this database. Note that the automatic collection and storage of information from the Internet (scraping) by private companies and individuals7 is generally unacceptable in the Netherlands. In addition, according to the Authority, Clearview AI violated the GDPR in terms of: 1) the processing of biometric personal data, as the company does not fall under the exceptions to the general prohibition in the law (e.g., where the data subject has given explicit consent to the processing or the processing is necessary to protect the vital interests of the data subject); and 2) the awareness of data subjects, as it does not cooperate with requests for access to the data. If the company does not stop the violations, it must pay an additional fine of up to €5.1 million in addition to the main fine.
Clearview AI has already been fined €20 million in 2022 by the Greek data protection8 authority for similar GDPR violations, which did not change the company's practices. In this regard, the Dutch Data Protection Authority is looking for ways to influence the company, including exploring ways to impose liability on its directors who were aware of the violations but did not prevent them within the scope of their authority. Thus, this case confirms the practice in the case of Mr. Durov and Telegram: If European regulators cannot “reach” a company, they try to influence its managers.
On September 6, 2024, the Belgian Data9 Protection Authority ruled on Mediahuis' illegal use of cookie notification banners on 4 press websites, such as the Antwerp newspaper. The Authority received a complaint from a user that the sites did not have a “reject all” button that was quickly enough distinguishable and used deceptive practices (misleading button colors) and that it was not easy to withdraw consent to the use of cookie banners. The Authority concluded that:
1) Consent cannot be considered freely given (as required by the GDPR) if the choice to “accept/reject all” is not offered at the same level, e.g. buttons side by side. It is also not unambiguous, as the user does not know that the “reject all” button is on the next step.
2) On the websites in question, the “accept all” button is highlighted in a bright color, which encourages the user to click it. In this way, the principle of fairness prescribed by GDPR is violated and therefore the consent is invalid.
3) Withdrawal of consent is only possible after several clicks, whereas one click is sufficient for consent, which is a violation of the GDPR.
The Data Protection Authority gives the company 45 days to correct these deficiencies, including by setting an opt-out cookie button and not using misleading button colors. After this period expires, the company will be fined €25,000 per day for each deficiency on each of the sites. The company may appeal this decision10 in court.
It should be noted that in Monitoring No. 7 we have already discussed deceptive practices related to illegal data collection.
The Mediahuis case shows that the use of personal data, even by companies whose activities are open to an unlimited number of people (mass media), can significantly violate the current legislation, which gives reason to search for alternative solutions.
Germany, for example, is creating an alternative to cookie notification banners: on September 4, 2024, the German government passed a Decree on the establishment of11 consent management services. These services save the user's settings when they first use a digital service and allow them to review the decision at any time, and digital service providers who voluntarily join the service will be informed of the users' decision upon request. This new, EU-wide tool is expected to relieve digital content users of repetitive cookie requests, enable better website design by reducing banners and reduce the flow of cookies. The success of the approach depends on the emergence of consent service providers on the market, which will be favored by users and digital service providers. The effectiveness of the approach is planned to be evaluated 2 years after the Regulation comes into force.
Users have the right to change the consent management service at any time, for which purpose the latter shall save the settings in machine-readable format and transfer them free of charge to another service of the user's choice.
To increase trust, consent management services must be recognized by the federal data12 protection and freedom of information commissioner, who includes them in a public register. To do so, they must submit an electronic notification with information about themselves, including name, legal form and economic structure, including funding sources. The notification is required to be accompanied by a statement that the consent management service provider will not process users' personal data for other purposes. It is also required to provide a security concept including, inter alia, information on the place of storage of personal data, technical and organizational measures for data protection and risk management. The notified body has the right to withdraw the recognition of a consent management service provider if it fails to comply with the requirements.
This tool, by reducing the flow of cookie banners, can reduce personal data breaches.
Russia’s experience
In Russia, according to Roskomnadzor's position, cookie data is also recognized as personal data, i.e. the subject's consent is required for its processing, and failure to inform about the use of such files is considered a violation. At the same time, there is no information about relevant cases, as well as about cases related to the use of personal data for illegal creation of databases and training of AI in court practice.
- Data Protection Commission. ↑
- Irish High Court. ↑
- https://www.dataprotection.ie/en/news-media/press-releases/data-protection-commission-welcomes-conclusion-proceedings-relating-xs-ai-tool-grok ↑
- https://www.dataprotection.ie/en/news-media/press-releases/dpc-welcomes-xs-agreement-suspend-its-processing-personal-data-purpose-training-ai-tool-grok ↑
- Data Protection Act 2018, https://www.irishstatutebook.ie/eli/2018/act/7/enacted/en/html ↑
- European Data Protection Board. ↑
- Общие положения о защите данных (Регламент ЕС 2016/679), https://eur-lex.europa.eu/eli/reg/2016/679/oj ↑
- Autoriteit Persoonsgegevens. ↑
- https://www.autoriteitpersoonsgegevens.nl/actueel/ap-legt-clearview-boete-op-voor-illegale-dataverzameling-voor-gezichtsherkenning ↑
- https://www.autoriteitpersoonsgegevens.nl/actueel/ap-scraping-bijna-altijd-illegaal ↑
- https://www.edpb.europa.eu/news/national-news/2022/hellenic-dpa-fines-clearview-ai-20-million-euros_en ↑
- Gegevensbeschermingsautoriteit. 30,31 ↑
- Gazet van Antwerpen. ↑
- https://www.gegevensbeschermingsautoriteit.be/burger/gba-neemt-maatregelen-tegen-mediahuis-voor-onrechtmatig-gebruik-van-cookiebanners-op-perssites ↑
- https://bmdv.bund.de/SharedDocs/DE/Pressemitteilungen/2024/073-wissing-wir-wollen-die-cookie-flut-reduzieren.html; https://bmdv.bund.de/SharedDocs/DE/Anlage/K/veordnung-nach-26-absatz-2-tdddg-und-zur-aenderung-der-besonderen- gebuehrenverordnung- telekommunikation.pdf?__blob=publicationFile ↑
- Bundesbeauftragte für den Datenschutz und die Informationsfreiheit. ↑
From the monitoring issue No. 9, September 2024. Download the full issue (PDF) · issue page at the Gaidar Institute