In our May newsletter, you will find the following topics: |
|
|
|
|
|
|
|
European Parliament and Council publish compromise text on AI Omnibus |
On 7 May, the European Parliament (the Parliament) and the Council of the European Union (the Council) published a compromise text on the AI Omnibus legislative proposal. The compromise text was published by the Council and forms part of the broader European agenda to make the implementation of the AI regulatory framework more practical, particularly for smaller market participants and innovative companies.
The AI Omnibus contains amendments to the AI Act. The purpose of the AI Omnibus is simplifying existing and upcoming AI regulations and limiting overlap between obligations, without undermining the level of protection for fundamental rights, safety and consumers. The Council and Parliament also emphasise that the core obligations and the risk-based nature of this framework remain fully intact.
The amendments are intended to make it easier for smaller parties to determine which obligations apply to them and how to comply with them. The simplification focusses on administrative burdens, reporting obligations and supervisory structures arising from the AI Act. The compromise text clarifies, among other things, that while organisations developing or deploying AI must take measures to support the development of AI literacy of their staff, they are not expected to meet any specific threshold levels of AI literacy. The compromise also maintains the delay of the entry into force of obligations for high-risk AI systems proposed by the European Commission (the Commission). According to the compromise, the obligations for high-risk AI systems under Annexes I and II will apply from 2 December 2027 and 2 August 2028, respectively.
The compromise fits within the EU’s broader policy to stimulate innovation and make the AI Act flexible, sustainable and resilient to technological and market developments, whilst at the same time providing legal certainty to market participants. In doing so, explicit attention has been paid to the position of SMEs and start-ups.
The compromise text of the AI Omnibus must be formally approved by both the Council and the Parliament |
|
|
|
| |
|
|
Commission publishes draft guidelines for transparency obligations under the AI Act |
On 8 May, the Commission published draft guidelines on the transparency obligations set out in the AI Regulation for public consultation. With this consultation, the Commission aims to clarify the obligations applicable to providers and deployers of certain AI systems.
The guidelines are intended to promote the uniform application of the transparency obligations for providers and deployers of AI systems. They address, among other things, the obligation to inform individuals that they are interacting with an AI system. Additionally, the Commission addresses labelling and disclaimers for AI-generated or manipulated content, such as synthetic images, audio and video. The guidelines also further clarify the transparency obligations regarding the use of emotion recognition systems and biometric categorisation in more detail.
The Commission elaborates on various key concepts, such as ‘interaction with an AI system’, ‘AI-generated content’ and ‘deepfakes’. It emphasises that the transparency obligations are context-dependent and that, in certain situations, limited or implicit provision of information may suffice, for example where the use of AI is evident to the user. At the same time, the Commission stresses that transparency constitutes an independent obligation, which is separate from the risk level of the AI system and therefore also applies outside the scope of high-risk AI systems.
The guidelines are of practical importance because they provide concrete guidance on the design of information and communication processes when using and providing information about the output of AI systems.
The consultation is open until 3 June and offers stakeholders the opportunity to provide input and feedback that the Commission can take into account in the final guidelines. |
|
|
|
| |
|
|
Commission publishes draft guidelines for the classification of high-risk AI systems |
On 19 May, the Commission published draft guidelines on the classification of high-risk AI systems under the AI Regulation for public consultation. With these guidelines, the Commission clarifies when an AI system falls under the stringent regime for high-risk AI systems.
The guidelines provide operationalise the dual classification of high-risk AI systems. For example, AI systems are classified as high-risk if they are a safety component of a product covered by existing EU legislation listed in Annex I to the AI Act and for which a conformity assessment is required. Additionally, standalone AI systems also qualify as high-risk if used for the purposes listed in Annex III, such as biometric identification, creditworthiness assessment, recruitment and selection, and access to essential public and private services.
The guidelines clarify that the intended use and actual deployment are decisive for this classification. Accordingly, the mere fact that an AI system falls within one of the use cases listed in Annex III does not automatically mean that it must be classified as high-risk. Decisive is whether, based on its functionalities and the context of use, the AI system can pose a significant risk to the health, safety or fundamental rights of natural persons. Specific attention is given to the exceptions for AI systems of a purely ancillary and/or preparatory nature and do not have a decisive influence or produce legal effects.
Finally, the guidelines clarify the division of responsibilities between providers and deployers. The primary responsibility for classifying an AI system rests with the provider. If a deployer substantially modifies the AI system or uses it for a different purpose, that deployer may itself be qualified as a provider and fall under the full compliance regime for high-risk AI systems.
The consultation is open until 23 June and offers stakeholders the opportunity to provide input and feedback for consideration in the final guidelines. |
|
|
|
| |
|
|
Dutch Data Protection Authority publishes decision on appeal against €10 million fine for Uber |
On 8 May, the Dutch Data Protection Authority (DDPA) published its decision on the appeal in the proceedings against Uber Technologies Inc. and Uber B.V. (jointly, Uber). The decision concerns the appeal lodged by Uber against the fine of € 10 million imposed on 11 December 2023 for breaches of two GDPR infringements by Uber.
Firstly, the DDPA establishes that Uber failed to adequately facilitate the right of access of its drivers. Uber exclusively provided personal data in CSV files, without any explanation or instructions regarding their structure or format. Furthermore, essential explanations regarding the interpretation of the CSV files (“guidance notes”) were provided in English only whilst the group of data subjects included (among others) French drivers. According to the DDPA, this method does not meet the requirements that information must be concise, transparent, understandable and easily accessible given the language proficiency of the data subjects concerned.
Secondly, the DDPA concludes that Uber failed to comply with its transparency obligations. The privacy notices did not contain sufficiently specific information on transfers of personal data to third countries, retention periods, or the existence of the right to data portability. Uber’s general statement that personal data is retained “for as long as necessary for specific purposes” was too vague and impedes on the data subjects ability to determine the retention periods or assess their lawfulness according to the DDPA. In particular, the DDPA considers the lack of specific information regarding third countries to which data is transferred and the associated safeguards to be contrary to the principles of fairness and transparency, as it prevented the data subjects from exercising effective control over their personal data. According to the DDPA, providing information about third countries to which personal data is transferred is essential for retaining control over one’s personal data and may even be of crucial importance for drivers to avoid safety risks in specific countries.
The DDPA rejects the grounds for appeal put forward by Uber, including the invocation of the lex certa principle, the absence of culpability, and the alleged disproportionate nature of the fine. Referring to Article 83 GDPR and recent case law of the Court of Justice, the DDPA holds that a professional, internationally operating company such as Uber may be expected to organise its data processing in accordance with the GDPR. The fine was calculated on the basis of Uber’s global annual turnover as an economic entity, with the fine imposed remaining well below the statutory maximum of € 1.19 billion, or 4% of Uber’s global turnover in 2022.
The decision confirms that regulators set high standards for the provision of practical, clear and comprehensible information and for facilitating the exercise of data subjects’ rights, particularly in the context of digital platform environments. |
|
|
|
| |
|
|
DCAM publishes guidelines on ‘Data sharing of connected products and related services |
On 15 May, the Dutch Consumers and Markets Authority (DCAM) published the guidelines “Data sharing of connected products and related services”. The guidelines offer practical guidance on compliance with the new rules flowing in the Data Act regarding access to and reuse of data. In doing so, the DCAM focuses on manufacturers of connected products, providers of related services and parties acting as data recipients.
The guidelines address the core obligations under the Data Act in detail. Central to this is the right of users to access data generated through the use of connected products, including smart devices and Internet of Things devices, and the right to share this data or have it shared with third parties. The DCAM explains which data is covered by these rights, such as raw user data, derived data and metadata.
The DCAM emphasises that contractual provisions that restrict these rights are, in principle, void. Attention is also drawn to the obligation for data holders to make data available to users of connected products and/or related services on fair, reasonable and non-discriminatory terms. In this regard, the DCAM highlights the overlap with competition law and the prohibition on unfair contract terms. The DCAM warns that it may take enforcement actions on the basis of both the Data Act and competition law against the use of technical or contractual barriers to restrict data sharing. In doing so, DCAM emphasises the importance of timely adaptation of contracts, IT architecture and internal processes.
In addition, the DCAM addresses the relationship between the Data Act and data protection law. If shared product or related services data also contains personal data, the GDPR remains fully applicable to the processing of that data. This means that a valid legal basis is required for the processing of that data and that principles such as data minimisation and purpose limitation must be complied with. It also addresses the division of roles between controllers and processors when sharing data at the request of the user of a connected product or related service. |
|
|
|
| |
|
|
|
|
Marc Elshof attorney-at-law | partner
T: +31 70 376 06 87 M:+31 6 46 37 61 08 marc.elshof@barentskrans.nl
|
|
|
|
|
Lars Groeneveld attorney-at-law | senior associate
T: +31 70 376 06 48 M:+31 6 46 11 04 57 lars.groeneveld@barentskrans.nl
|
|
|
|
|
Job Julicher attorney-at-law
T: +31 70 376 08 10 M:+31 6 27 42 99 77 job.julicher@barentskrans.nl
|
|
|
|
|
Julius Louter attorney-at-law
T: +31 70 376 06 40 M:+31 6 15 43 37 52 julius.louter@barentskrans.nl
|
|
|
|
|
|
BarentsKrans
The Hague | Amsterdam +31 70 376 06 06 communicatie@barentskrans.nl www.barentskrans.nl |
| |
|
|
| |
|
|
|