The Swe­dish Data Pro­tec­tion Aut­ho­ri­ty, the Inte­gri­tets­skydds­myn­di­ghe­ten (IMY), issued a Report on the mat­ter published, What role does a pro­vi­der that makes AI appli­ca­ti­ons available, cus­to­mi­zes them, or fur­ther deve­lo­ps them play under the GDPR?. The report is based on a three-month „express sand­box“ for data pro­tec­tion con­duc­ted with the pro­vi­der Eggs­plain. IMY exami­ned three pha­ses of the ser­vice cycle: hard­ware instal­la­ti­on, deployment and fine-tuning of AI appli­ca­ti­ons, and ongo­ing ser­vices, based on the Gui­de­lines 07/2020 of the EDSA (on the con­cepts of con­trol­ler and pro­ces­sor in the GDPR). For models that have been trai­ned using per­so­nal data, IMY also refers to the Opi­ni­on 28/2024 of the EDSA (on cer­tain data pro­tec­tion aspects rela­ted to the pro­ce­s­sing of per­so­nal data in the con­text of AI models).

The report con­ta­ins no sur­pri­ses. The role under data pro­tec­tion law depends on how the pro­vi­der pro­ce­s­ses per­so­nal data, not on the natu­re of its ser­vice. Howe­ver, the report says not­hing about the legal basis or the rights of data subjects.

When it comes to fine-tuning, the IMY distin­gu­is­hes bet­ween four sce­na­ri­os, alt­hough it remains unclear whe­ther such a pre­cise distinc­tion is even fea­si­ble in practice:

  • Deployment wit­hout fine-tuning: To the ext­ent that a pro­vi­der mere­ly faci­li­ta­tes the use of a third-par­ty appli­ca­ti­on wit­hout acce­s­sing per­so­nal data its­elf and wit­hout deter­mi­ning the pur­po­se or essen­ti­al means, it bears no responsibility.
  • Fine-tuning on one’s own initia­ti­ve: When fine-tuning to reach a broa­der cus­to­mer base, the pro­vi­der is the par­ty responsible.
  • Cus­tom fine-tuning: When per­forming fine-tuning in accordance with a spe­ci­fic customer’s ins­truc­tions and for that customer’s pur­po­ses, the pro­vi­der is a pro­ces­sor and the cus­to­mer is a con­trol­ler. This also applies if the pro­vi­der has a cer­tain degree of dis­creti­on regar­ding prac­ti­cal or tech­ni­cal matters.
  • Joint Fur­ther Deve­lo­p­ment: If the pro­vi­der and the cus­to­mer joint­ly deter­mi­ne the pur­po­se and the essen­ti­al means, the­re is joint respon­si­bi­li­ty. Howe­ver, mere coope­ra­ti­on or a shared com­mer­cial inte­rest is not suf­fi­ci­ent for this.

For the remai­ning phases:

  • Sale, ren­tal, or instal­la­ti­on of hard­ware: does­n’t matter
  • Migra­ti­on of data­ba­ses, user accounts, or logs: Order Processing
  • Using the Appli­ca­ti­on: To be asses­sed sepa­ra­te­ly; in prin­ci­ple, the cus­to­mer is respon­si­ble, and the pro­vi­der acts as a data pro­ces­sor to the ext­ent that it pro­vi­des the tech­ni­cal environment.
  • Sup­port and Con­sul­ting: depen­ding on the spe­ci­fic acti­vi­ty. When ana­ly­zing sup­port cases to assess the provider’s own ser­vice qua­li­ty, the pro­vi­der is a data con­trol­ler; when pro­ce­s­sing cases sole­ly on behalf of the cus­to­mer, the pro­vi­der is a data processor.
  • Body Lea­se: If the pro­vi­der assigns a spe­cia­list to work within the customer’s system under the customer’s direc­tion and super­vi­si­on, the pro­vi­der plays no role.