Logo ECIJA

    The AEPD requests "clear" regulations on the use of personal data to train AI

    The president of the Spanish Data Protection Agency points out that artificial intelligence should not be seen as a barrier to employment, but we should accept that work will evolve towards a hybrid model that will combine people and intelligent systems.


    The president of the Spanish Data Protection Agency, Lorenzo Cotino, defended the role of artificial intelligence (AI) as one of the main drivers of economic and legal transformation during his speech at a meeting organized by the International Association of Privacy Professionals (IAPP), in collaboration with Google, Ecija, and the Spanish Association of Compliance.


    During the event, held at the Ecija headquarters, Cotino stated that artificial intelligence represents “the greatest of the great technological and legal turning points of our time” and emphasized that both supervisory authorities and privacy professionals must have an active role in shaping this new landscape. "We are actors, not spectators, in shaping this future and ensuring it follows the path of security and the protection of rights," said the president of the AEPD.


    In this regard, he argued that the advance of artificial intelligence should not be interpreted as an obstacle to employment or business activity, but rather as a structural transformation of work. “We must not put the brakes on artificial intelligence, but start to internalize that the natural evolution of work in virtually every sector involves a hybrid model,” he pointed out. As he explained, this new model will mean that people will "manage, validate, and control" the artificial intelligence systems that are routinely integrated into the management and decision-making processes of organizations.


    Cotino also highlighted that the AEPD itself has been the first Spanish public administration to develop an internal policy on the use of artificial intelligence with the aim of conveying a message of trust to the market: to advance in the adoption of these tools, but in accordance with criteria of legal security and privacy.


    The president of the agency also pointed out the impact that this transformation will have on privacy officers, as well as data protection delegates and officers. In his view, these professionals will be destined to assume a strategic role within companies, leading advanced automation processes and new services related to the control and supervision of intelligent systems.


    He also warned that the growth of AI will also require the automation of some processes of human supervision. “The necessary human supervision will inevitably have to be automated in many of its tasks, as it clearly exceeds human capabilities”, he noted.


    Regarding the European regulatory debate, Cotino defended the need to move towards a clearer regulatory framework that facilitates the use of personal data for training artificial intelligence models, although he insisted that this development must be accompanied by enhanced guarantees. Specifically, he called for a regulation that improved the functioning of AI systems and reduced biases, including certain treatments of particularly protected data, but under legal conditions that are "better defined" than those initially proposed in the Omnibus amendment to the GDPR.


    Meanwhile, the president of the AEPD announced an update of the agency's biometric systems guide and welcomed the European Commission's proposal to ease certain restrictions of Article 9 of the GDPR concerning some processing operations related to the use of biometric data.


    Read the full article here.


    Related professionals

    LATEST FROM #ECIJA

    Articles
    28 July 2026
    Prodhab’s guidelines on debt recovery procedures

    It sets out new rules for the processing of personal data in debt collection procedures and communications with third parties.

    Read more
    Reports
    28 July 2026
    Data Protection Officer (DPO): Chile and Spain

    A comparative analysis of the regulation, functions and requirements of the Data Protection Officer (DPO) in Chile and Spain, highlighting their strategic role in governance and compliance in the field of personal data protection.

    Read more
    Articles
    24 July 2026
    Alfredo Moreno publishes a letter to the editor on the challenges posed by the new Data Protection Act

    The Managing Partner of ECIJA Chile has published a letter to the editor in *Diario Constitucional* in which he analyses the main challenges posed by the implementation of the new Personal Data Protection Act in Chile.

    Read more
    Reports
    22 July 2026
    Joint guidelines on the ASEAN and RIPD model contractual clauses for international transfers of personal data

    ECIJA Ecuador analyses the Joint ASEAN–RIPD Guidelines on international data transfers.

    Read more
    Articles
    8 July 2026
    Your company processes far more personal data than you realise

    Most companies believe they have a clear understanding of what personal data they process. However, this perception is often limited to their customer database, when in fact the processing of personal data covers much more than that.

    Read more
    News
    30 June 2026
    ECIJA strengthens its team in Pamplona and consolidates its presence in Navarra with the recruitment of 20 professionals

    The initiative expands ECIJA's coverage in Navarra and incorporates a team of experts in taxation, labor law, commercial law, financial consulting, and international affairs.

    Read more
    Articles
    29 June 2026
    The World Cup of Brands: How to Ride Football Euphoria Without Facing a Multi-Million Penalty

    The World Cup kicked off on June 11 in Mexico City and, for a little over a month, will be the most-watched event on the planet. Industry estimates point to a cumulative audience of nearly five billion people and more than USD 10 billion in additional global advertising spend. For fans, it is a celebration. For brands, it is the most coveted communications platform in the world.

    Read more
    Articles
    22 June 2026
    Certifying compliance with the GDPR is already a reality

    Ten years after the GDPR came into effect, the certification mechanisms established in Articles 42 and 43 are emerging as advanced tools to demonstrate regulatory compliance in a verifiable and structured manner.

    Read more
    Articles
    18 June 2026
    Judicial Prompt Injection: the case that highlights the new legal risks posed by AI

    The episode opens up the debate on security, algorithmic governance, human oversight and the regulatory challenges faced by organisations and authorities in the face of a new generation of technological risks.

    Read more