AI Act
Navigation log
Table of Contents
Chapter I – General provisions
Chapter II – Prohibited AI practices
Chapter III – High-risk AI systems
Chapter IV – Transparency obligations for providers and deployers of certain AI systems
Chapter V – General-purpose AI models
Chapter VI – Measures in support of innovation
Chapter VII – Governance
Chapter VIII – EU database for high-risk AI systems
Chapter IX – Post-market monitoring, information sharing and market surveillance
Chapter X – Codes of conduct and guidelines
Chapter XI – Delegation of power and committee procedure
Chapter XII – Penalties
Chapter XIII – Final provisions
Recitals (180)
Annexes
Chapter I – General provisions
Article 4a
Processing of special categories of personal data for bias detection and correction
1. To the extent strictly necessary to ensure bias detection and correction in relation to high-risk AI systems in accordance with Article 10(2), points (f) and (g), of this Regulation, providers of such systems may exceptionally process special categories of personal data, subject to appropriate safeguards for the fundamental rights and freedoms of natural persons. In addition to the provisions set out in General Data Protection Regulation (GDPR) and (EU) 2018/1725 and Law Enforcement Directive (LED), as applicable, all the following conditions shall be met in order for such processing to occur:
(a) the bias detection and correction cannot be effectively fulfilled by processing other data, including synthetic or anonymised data;
(b) the special categories of personal data are subject to technical limitations on the re-use of personal data, and state-of-the-art security and privacy-preserving measures, including pseudonymisation;
(c) the special categories of personal data are subject to measures to ensure that the personal data processed are secured and protected, subject to suitable safeguards, including strict controls and documentation of the access, to avoid misuse and to ensure that only authorised persons have access to those personal data with appropriate confidentiality obligations;
(d) the special categories of personal data are not transmitted, transferred or otherwise accessed by other parties;
(e) the special categories of personal data are deleted once the bias has been corrected or the personal data has reached the end of its retention period, whichever comes first; and
(f) the records of processing activities pursuant to General Data Protection Regulation (GDPR) and (EU) 2018/1725 and Law Enforcement Directive (LED) include the reasons why the processing of special categories of personal data was strictly necessary to detect and correct biases, and why that objective could not be achieved by processing other data.
2. Providers and deployers of other AI systems and models and deployers of high-risk AI systems may exceptionally process special categories of personal data to the extent that:
(a) such processing is strictly necessary to ensure bias detection and correction in view of possible biases that are likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited pursuant to Union law, especially where data outputs influence inputs for future operations; and
(b) all of the conditions and safeguards set out in paragraph 1 are applied.
This paragraph does not create any obligation to conduct such bias detection and correction.
Related insights
- EU AI Act Compliance Timeline & FAQPillar15 Sept 2026