The Swedish Data Protection Authority, the Integritetsskyddsmyndigheten (IMY), issued a Report on the matter published, What role does a provider that makes AI applications available, customizes them, or further develops them play under the GDPR?. The report is based on a three-month „express sandbox“ for data protection conducted with the provider Eggsplain. IMY examined three phases of the service cycle: hardware installation, deployment and fine-tuning of AI applications, and ongoing services, based on the Guidelines 07/2020 of the EDSA (on the concepts of controller and processor in the GDPR). For models that have been trained using personal data, IMY also refers to the Opinion 28/2024 of the EDSA (on certain data protection aspects related to the processing of personal data in the context of AI models).
The report contains no surprises. The role under data protection law depends on how the provider processes personal data, not on the nature of its service. However, the report says nothing about the legal basis or the rights of data subjects.
When it comes to fine-tuning, the IMY distinguishes between four scenarios, although it remains unclear whether such a precise distinction is even feasible in practice:
- Deployment without fine-tuning: To the extent that a provider merely facilitates the use of a third-party application without accessing personal data itself and without determining the purpose or essential means, it bears no responsibility.
- Fine-tuning on one’s own initiative: When fine-tuning to reach a broader customer base, the provider is the party responsible.
- Custom fine-tuning: When performing fine-tuning in accordance with a specific customer’s instructions and for that customer’s purposes, the provider is a processor and the customer is a controller. This also applies if the provider has a certain degree of discretion regarding practical or technical matters.
- Joint Further Development: If the provider and the customer jointly determine the purpose and the essential means, there is joint responsibility. However, mere cooperation or a shared commercial interest is not sufficient for this.
For the remaining phases:
- Sale, rental, or installation of hardware: doesn’t matter
- Migration of databases, user accounts, or logs: Order Processing
- Using the Application: To be assessed separately; in principle, the customer is responsible, and the provider acts as a data processor to the extent that it provides the technical environment.
- Support and Consulting: depending on the specific activity. When analyzing support cases to assess the provider’s own service quality, the provider is a data controller; when processing cases solely on behalf of the customer, the provider is a data processor.
- Body Lease: If the provider assigns a specialist to work within the customer’s system under the customer’s direction and supervision, the provider plays no role.