| 英文摘要 |
The rapid development of Generative Artificial Intelligence (Generative AI) has posed unprecedented challenges to personal data protection. Throughout the AI lifecycle, including data collection, model training, and deployment, large volumes of personal data may be collected, processed, and used. Accordingly, the legal basis for data processing has become one of the core issues in AI governance. This article uses the Italian Replika enforcement decision as a case study to examine the supervisory authority's assessment of the lawfulness of personal data processing in Generative AI systems, with a particular focus on the legal basis for personal data processing during the model training stage. In the context of large language model (LLM) training, obtaining valid consent from every data subject is highly impracticable. Moreover, consent originally obtained for a specific purpose of data collection generally does not extend to the subsequent use of personal data for AI model training. Consequently, consent as the primary legal basis for data processing is subject to significant limitations. By contrast, legitimate interests under Article 6(1)(f) of the General Data Protection Regulation (GDPR) have gradually become an important legal basis discussed by European supervisory authorities and scholars in relation to AI model training. Nevertheless, reliance on legitimate interests must satisfy the requirements of a legitimate interest, necessity, and the balancing of interests. In addition, appropriate safeguards, including data minimization, transparency, anonymization, opt-out mechanisms, and Data Protection Impact Assessments (DPIAs), should be implemented to reduce the impact on the rights and interests of data subjects. Finally, this article suggests that Taiwan may draw upon the legitimate interests balancing mechanism under the GDPR to achieve an appropriate balance between the development of Generative AI and the protection of personal data. |