Skip to main content

LUP Student Papers

LUND UNIVERSITY LIBRARIES

Bias Detection and Correction in AI - Legal relationship between Article 10(5) of the AI Act and Article 9 of GDPR

Wu, Zhiqiang LU (2026) HARN63 20261
Department of Business Law
Abstract
In recent years, the issue of algorithmic bias in systems has gradually drawn the European Union’s attention to the relationship between data protection and non-discrimination principles. To detect and mitigate bias in high-risk AI systems, developers often need to process special categories of personal data such as information relating to race, gender or health. However, Article 9 of the GDPR prohibits the processing of such data in principle, whereas Article 10(5) of the AI Act permits relevant processing for bias detection and mitigation under specific conditions. On this basis, this paper aims to analyse the legal relationship as well as the interplay and impacts between Article 9 of the GDPR and Article 10(5) of the AI Act. Adopting a... (More)
In recent years, the issue of algorithmic bias in systems has gradually drawn the European Union’s attention to the relationship between data protection and non-discrimination principles. To detect and mitigate bias in high-risk AI systems, developers often need to process special categories of personal data such as information relating to race, gender or health. However, Article 9 of the GDPR prohibits the processing of such data in principle, whereas Article 10(5) of the AI Act permits relevant processing for bias detection and mitigation under specific conditions. On this basis, this paper aims to analyse the legal relationship as well as the interplay and impacts between Article 9 of the GDPR and Article 10(5) of the AI Act. Adopting a legal dogmatic approach, this paper analyses EU legislation, CJEU case law, EDPB documents and relevant academic literature through literal interpretation, systematic interpretation and teleological interpretation. The study concludes that there is no genuine normative conflict between the GDPR and the AI Act.Instead, they form a mutually complementary regulatory structure: the GDPR constitutes the general legal framework for personal data protection, while Article 10(5) of the AI Act provides conditional and stringent exceptions for bias governance in high-risk AI systems to supplement the protection of fundamental human rights. Meanwhile, “strict necessity” should be interpreted as a highly stringent legal threshold, requiring data controllers to demonstrate the absence of less intrusive alternatives. Overall, the EU legal framework seeks to strike a balance between preventing algorithmic discrimination and protecting personal data, and promote the sound development of AI governance through the coordinated application of the GDPR and the AI Act. (Less)
Please use this url to cite or link to this publication:
author
Wu, Zhiqiang LU
supervisor
organization
course
HARN63 20261
year
type
H1 - Master's Degree (One Year)
subject
keywords
GDPR, AI Act, High-risk AI systems, Bias detection and correction, Strict necessity, Data protection, interplay, relationship.
language
English
id
9231056
date added to LUP
2026-06-09 12:07:30
date last changed
2026-06-09 12:07:30
@misc{9231056,
  abstract     = {{In recent years, the issue of algorithmic bias in systems has gradually drawn the European Union’s attention to the relationship between data protection and non-discrimination principles. To detect and mitigate bias in high-risk AI systems, developers often need to process special categories of personal data such as information relating to race, gender or health. However, Article 9 of the GDPR prohibits the processing of such data in principle, whereas Article 10(5) of the AI Act permits relevant processing for bias detection and mitigation under specific conditions. On this basis, this paper aims to analyse the legal relationship as well as the interplay and impacts between Article 9 of the GDPR and Article 10(5) of the AI Act. Adopting a legal dogmatic approach, this paper analyses EU legislation, CJEU case law, EDPB documents and relevant academic literature through literal interpretation, systematic interpretation and teleological interpretation. The study concludes that there is no genuine normative conflict between the GDPR and the AI Act.Instead, they form a mutually complementary regulatory structure: the GDPR constitutes the general legal framework for personal data protection, while Article 10(5) of the AI Act provides conditional and stringent exceptions for bias governance in high-risk AI systems to supplement the protection of fundamental human rights. Meanwhile, “strict necessity” should be interpreted as a highly stringent legal threshold, requiring data controllers to demonstrate the absence of less intrusive alternatives. Overall, the EU legal framework seeks to strike a balance between preventing algorithmic discrimination and protecting personal data, and promote the sound development of AI governance through the coordinated application of the GDPR and the AI Act.}},
  author       = {{Wu, Zhiqiang}},
  language     = {{eng}},
  note         = {{Student Paper}},
  title        = {{Bias Detection and Correction in AI - Legal relationship between Article 10(5) of the AI Act and Article 9 of GDPR}},
  year         = {{2026}},
}