- A leaked EU document could let AI companies use personal data without your consent.
- The draft removes key safeguards that the European Commission first planned for AI data use.
- Privacy group Noyb calls the plan a big step back for data protection in Europe.
A leaked document from the European Union has sparked new worries about your personal data. The paper shows plans that could let AI companies use people’s data more freely. Companies might not need your permission first in many cases.
Ireland currently holds the presidency of the EU Council. Ireland’s team prepared this document. It suggests that AI companies could rely on a rule called “legitimate interest” to use personal data. This rule already exists under GDPR, Europe’s main data protection law.
Legitimate interest does not usually require a company to ask for your consent first. However, the company must still weigh its own interests against your rights. That balancing act is supposed to protect ordinary people from unfair data use.
Inside the Leaked Document
The leaked paper carries the date September 3, 2026. It is labeled document 12535/26. EU governments have been passing it around ahead of upcoming Council talks. PPC Land first reported on the leak.
The real argument here is about missing protections. Earlier, the European Commission suggested strict rules to guard AI data use. Those rules included limits on how much data companies could collect. They also promised better transparency and blocked companies from pulling personal data out of AI systems. People were also meant to get an unconditional right to say no to their data being used this way.
The newest Council draft cuts out those AI-specific protections. The unconditional right to object is gone too. Still, this does not mean anything goes. Normal GDPR rules linked to legitimate interest still apply. Companies must still pick a proper legal basis. They must still follow other GDPR rules as well.
EU privacy rules have also created challenges for major platforms, including Facebook, which has previously adjusted its approach in response to new European privacy requirements. See how Facebook has responded to new EU privacy rules while regulators continue to tighten their data protection expectations.
This distinction actually matters a lot. The European Data Protection Board already said companies can sometimes use legitimate interest for AI work. But they can only do this after checking each case carefully. According to the Board’s 2024 opinion, a company must prove its data use is necessary. The company’s interest also cannot override a person’s basic rights.
Germany Wants to Go Further
A separate proposal from Germany appears in the same leaked papers. Germany wants processing for AI training and operation to count as legitimate interest automatically. Companies would not need to prove their case each time under this plan.
Germany’s proposal also touches other areas. It suggests changes to people’s data rights. It also proposes new rules for pseudonymised data, meaning data with names and details hidden or coded.
Privacy group noyb published these leaked papers on September 21. The group strongly criticized where these talks are heading. According to NOYB, the changes could let AI companies use large piles of personal data with few real limits. The group called this a major shift in how Europe protects personal data. Keep in mind, these are NOYB’s own views. There is not yet a final ruling on the actual law.
Other outlets have picked up the story too. PPC Land reported that the Council text strips out several safeguards from the Commission’s original AI rule. Spanish outlet El País reported that tech companies could train AI using European data without asking for clear consent, as long as they rely on legitimate interest.
What Happens Next
This proposal is not law yet. It remains part of ongoing talks between EU governments. Before anything changes, the plan must pass through the full EU lawmaking process. That includes negotiations with the European Parliament.
So Europe has not thrown out its consent rules just yet. The real question is different. How much freedom should companies get to use legitimate interest for AI work? And what protections should come attached to that freedom?
For now, millions of Europeans wait to see how far their data protection might shrink. Regulators, companies, and privacy groups will keep pushing their own sides of this fight in the months ahead.
Share this article
About the Author
Rebecca James is an IT consultant with forward thinking approach toward developing IT infrastructures of SMEs. She writes to engage with individuals and raise awareness of digital security, privacy, and better IT infrastructure.
More from Rebecca JamesRelated Posts
Dark Web Seller Claims Android 14–16 Zero-Day Exploit Chain is for Sale
A dark web operator, xynapse, offers an unconfirmed zero-day exploit chain for Android versions 14 t...
Ukrainian Ransomware Developer Sentenced to Nearly 13 Years in Switzerland
A court in Zurich handed a 52-year-old Ukrainian man a sentence of 12 years and nine months for his ...
German Chancellor Merz Renews Call for Real-Name Internet Rules Amid Privacy Debate
German Chancellor Friedrich Merz reaffirmed his position on the adoption of real name policy on the ...
WhatsApp Tests ‘Restricted Chat’ Privacy Feature to Keep Chats Off Linked Devices
WhatsApp is testing a privacy tool called Restricted Chat that keeps a conversation on your main pho...
Palo Alto Networks Warns of Critical PAN-OS Flaw Allowing Remote Code Execution
Palo Alto Networks found a serious bug in its PAN-OS firewall software. Hackers do not need a passwo...
New Mantax Otax Android Malware Combines Ransomware, Spyware and Harassment
Mantax Otax is an Android malware strain operated by Indonesian threat actors that fuses file encryp...