Lawful Basis for AI Processing: A UK GDPR Guide

UK businesses: Master the lawful basis for AI processing under UK GDPR. This guide demystifies consent, legitimate interests, and ICO guidance. Ensure compliance today!

· AI & Digital Health

Understanding Your Obligations: AI and the UK GDPR

From personalised marketing to streamlining operations, the potential of AI is vast. However, with great power comes great responsibility, particularly when it comes to personal data. For any organisation in the UK, this responsibility is framed by the UK General Data Protection Regulation (UK GDPR).

A fundamental pillar of the UK GDPR is the principle of lawfulness. You cannot process personal data simply because you want to. You must first identify and document a valid ‘lawful basis’ for doing so. This requirement becomes significantly more complex when dealing with AI systems, which can process enormous volumes of data in ways that are not always transparent. This article provides a clear, practical guide to choosing a lawful basis for AI processing, helping you navigate the guidance from the Information Commissioner’s Office (ICO) with confidence.

What is a Lawful Basis? A Quick Refresher

Before we delve into the specifics of AI, it is essential to be clear on what a lawful basis is. Think of it as your legal permission slip to process someone’s personal data. The UK GDPR provides six possible lawful bases, and you must choose the one that best fits your purpose for processing.

The six lawful bases are:

  • Consent: The individual has given clear, affirmative agreement for you to process their personal data for a specific purpose.

  • Contract: The processing is necessary for a contract you have with the individual, or because they have asked you to take specific steps before entering into a contract.

  • Legal Obligation: The processing is necessary for you to comply with the law (not including contractual obligations).

  • Vital Interests: The processing is necessary to protect someone’s life.

  • Public Task: The processing is necessary for you to perform a task in the public interest or for your official functions.

  • Legitimate Interests: The processing is necessary for your legitimate interests or the legitimate interests of a third party, unless there is a good reason to protect the individual’s personal data which overrides those legitimate interests.

You must determine your lawful basis before you begin processing and document it. You cannot swap to a different basis later without a very good reason. This initial decision is therefore critical to your overall compliance.

The Unique Challenges of AI for Data Protection

Choosing a lawful basis for a simple process, like sending a contractual invoice, is straightforward. For AI, the picture is far more complicated. AI systems introduce unique challenges that require careful consideration.

Scale and Complexity

AI models are often trained on vast datasets. It can be difficult to be fully transparent with individuals about precisely how their data will be used, especially when the system's logic is complex or evolves over time. This complexity can make it challenging to obtain valid, specific consent.

Inferred and Generated Data

AI doesn’t just process the data you feed it; it creates new data. This is known as ‘inferred’ or ‘derived’ data. For example, an AI might analyse a customer's shopping habits to infer their income bracket, lifestyle choices, or even health status. The ICO is clear that this inferred data is still personal data and requires a lawful basis for its creation and use.

The 'Black Box' Problem

Some advanced AI models are so complex that even their developers cannot fully explain how they reached a specific conclusion. This ‘black box’ nature poses a significant challenge to the UK GDPR principle of transparency. If you cannot explain the processing, how can you justify it to individuals or the regulator? For more on this, see our guide on Explaining AI Decisions: A UK GDPR Guide to Transparency.

Analysing the Most Relevant Lawful Bases for AI Processing

While all six bases are theoretically available, in practice, only a few are likely to be appropriate for most commercial AI applications. Let’s examine the most common contenders.

Can You Rely on Consent?

Consent might seem like a safe option, but it is often unsuitable for AI processing. Under UK GDPR, consent must be freely given, specific, informed, and unambiguous. For an AI system that constantly learns and adapts, it is difficult to be specific and fully inform the individual about all potential future processing activities at the outset. If you cannot meet this high standard, any consent you obtain will be invalid. You can learn more about these standards by reading our detailed article on the UK GDPR's consent requirements.

Consent may be appropriate for very narrow and clearly defined AI functions, but for broad or evolving systems, it is a fragile choice.

When is AI 'Necessary for a Contract'?

The lawful basis of 'contract' has a strict definition of 'necessary'. It means the processing must be essential to deliver the contractual service. If you can deliver the service without the AI processing, then it is not necessary. For example, using AI to detect payment fraud might be considered necessary for an e-commerce contract. However, using AI to provide personalised product recommendations is likely a 'nice-to-have' feature, not a contractual necessity. You must be prepared to justify this distinction.

Legitimate Interests: The Most Likely, and Most Complex, Option

For many AI applications, 'legitimate interests' will be the most appropriate lawful basis for AI processing. However, it is not a simple default option. It requires you to conduct and document a three-part assessment, known as a Legitimate Interests Assessment (LIA):

  1. Purpose Test: Identify your legitimate interest. Is it a genuine interest for your organisation (e.g., preventing fraud, improving your service, direct marketing)?

  2. Necessity Test: Is the AI processing necessary to achieve that interest? Could you reasonably achieve the same result in a less intrusive way?

  3. Balancing Test: This is the most crucial step. You must weigh your legitimate interests against the rights, freedoms, and interests of the individuals whose data you are processing.

The balancing test for AI must be particularly robust. You need to consider the potential impact on individuals, including the risk of bias, inaccuracy, or discrimination. The more intrusive the AI, and the more significant the potential negative impact, the harder it will be to justify that your interests override the individual’s.

Navigating the ICO's Guidance on AI and Inferences

Recognising these complexities, the ICO has updated its guidance to specifically address AI. Its advice, found within the ICO Lawful Basis Guidance, highlights key areas of risk that organisations must manage.

Special Focus on Inferences and Affinity Groups

The ICO guidance now explicitly states that you need a lawful basis not just for the data you collect, but also for the data you infer. If your AI creates new information about someone, such as predicting they belong to a certain ‘affinity group’ (e.g., ‘high-value customers’ or ‘likely to churn’), that is a processing activity that needs its own justification.

This is particularly important because AI can infer special category data. Special category data is a specific set of personal information that is more sensitive and requires higher levels of protection. It includes data on race or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, health data, and a person's sex life or sexual orientation.

An AI system could, for example, infer a person's health condition from their online search history or purchasing patterns. If your AI is likely to infer this type of data, you must not only have a lawful basis under Article 6 of the UK GDPR, but also satisfy a separate, specific condition for processing special category data under Article 9. This is a much higher bar to clear.

A Practical Checklist for Choosing Your Lawful Basis for AI

Feeling overwhelmed? Following a structured process can bring clarity and ensure you meet your obligations. A commitment to good AI governance and accountability is your best defence.

Here is a step-by-step checklist to guide your decision-making:

  • 1. Define Your Purpose: Be absolutely clear about what you are trying to achieve with the AI system. Vague objectives make it impossible to assess necessity or fairness.

  • 2. Conduct a Data Protection Impact Assessment (DPIA): For almost any AI system, a DPIA is mandatory under UK GDPR. This process will force you to systematically think through the risks to individuals and how to mitigate them.

  • 3. Map Your Data: Identify all personal data being processed. This includes the data you collect directly and, crucially, any data the AI might infer or generate.

  • 4. Analyse All Six Lawful Bases: Go through each of the six bases and document why they do or do not apply to your specific purpose. Do not just default to legitimate interests.

  • 5. Document Your LIA (if applicable): If you land on legitimate interests, complete the three-part test in full and keep a written record of your balancing exercise. This is your evidence of compliance.

  • 6. Check for Special Category Data: Actively consider whether your AI could infer special category data. If there is a risk, you must identify and document an Article 9 condition.

  • 7. Be Transparent: Update your privacy notice to explain that you use AI, what you use it for, what data is involved, and what the individual's rights are. The information must be clear and easy to understand. For more help, check out our UK GDPR compliance checklist for small businesses.

  • 8. Review Regularly: AI systems can change over time. Regularly review your lawful basis and DPIA to ensure they remain appropriate as the technology and its uses evolve.

Navigating the requirements for the lawful basis for AI processing demands careful thought and rigorous documentation. It is not a box-ticking exercise but a fundamental part of responsible innovation. By taking a structured approach, focusing on transparency, and placing the rights of individuals at the centre of your design, you can harness the power of AI while building trust and ensuring you comply with UK data protection law. Your efforts to get this right from the start will provide a solid foundation for using AI safely and effectively.