Skip to main content
Category: Data Classification & Identifiers

Inference

Also known as: Inferred data, AI inference, Machine learning inference
Simply put

Inference is the process of reaching a conclusion or forming an opinion from known facts. In a data and privacy context, it typically refers to deriving new information about a person, such as their preferences or characteristics, from existing data rather than collecting that information directly. The resulting derived information is often called inferred data.

Formal definition

In logic, inference is the reasoning step that moves from premises to a logical consequence, traditionally divided into deduction and induction. In machine learning and AI, inference denotes running a trained model against new, previously unseen input data to produce an output or prediction. In a data protection context, inferred data (information derived analytically from other data rather than provided directly by or observed about the data subject) can itself constitute personal data where it relates to an identified or identifiable individual, and may fall within special categories under Article 9 where the inference reveals such attributes; the precise legal treatment, including which Article 6 basis and any Article 9 condition applies, is context and fact dependent and should be assessed against the current official text and applicable regulatory guidance.

Why it matters

Inference matters in data protection because information a person never directly disclosed can still be personal data about them. Where data derived analytically from other data relates to an identified or identifiable individual, it can itself constitute personal data, and the individual may have limited awareness that such conclusions are being drawn. This creates a gap between what a person knowingly provides and what an organisation ultimately holds and acts upon, which is significant for transparency, fairness, and the exercise of data subject rights.

The stakes rise where an inference reveals sensitive attributes. An inference that reveals, for example, health, political opinions, or other special category information may fall within Article 9, which requires an additional condition beyond an Article 6 legal basis. Because inferred data is generated rather than directly collected, organisations can overlook the need to identify a lawful basis and, where relevant, an Article 9 condition for the inferred output specifically. The precise legal treatment is context and fact dependent and should be assessed against the current official text and applicable regulatory guidance.

Who it's relevant to

Data protection officers and privacy leads
DPOs and privacy teams need to account for inferred data when mapping what personal data an organisation actually holds, since derived conclusions may not appear in records of directly collected data. This is relevant to transparency obligations, records of processing, and assessing whether any inference reveals special category data that would require an Article 9 condition in addition to an Article 6 basis.
Engineers and machine learning teams
Engineers building or operating models should recognise that inference in the machine learning sense (running a trained model against new input to produce a prediction) can generate outputs that constitute personal data where they relate to an identifiable individual. Design and documentation choices at the inference stage may affect how lawful basis, transparency, and data subject rights are addressed.
Compliance and legal advisers
Compliance leads and lawyers assessing analytics or profiling activities should treat the legal treatment of inferred data as context and fact dependent, confirming which Article 6 basis and, where an inference reveals sensitive attributes, which Article 9 condition applies. Conclusions should be checked against the current official text and applicable regulatory guidance rather than assumed from the inference alone.

Inside Inference

Derived or inferred personal data
Information produced about an individual by applying analytics, profiling, or algorithmic processing to existing data, rather than data provided directly by the individual. Where an inference relates to an identified or identifiable natural person, it generally constitutes personal data within the scope of the GDPR.
Source data and processing logic
The input data and the reasoning, model, or rules used to generate the inference. The lawfulness of the inference-generating processing typically depends on the legal basis under Article 6, and where special category data under Article 9 is inferred or used, an additional Article 9 condition is generally required.
Relationship to profiling
Inference is closely connected to profiling, which involves automated processing to evaluate personal aspects of an individual. Not all inference is automated profiling, but automated profiling typically produces inferences. The precise boundary can be subject to assessment against the facts.
Accuracy and quality dimension
Inferred data may be probabilistic or uncertain and can be incorrect. Its accuracy is generally relevant to data quality obligations, though the extent to which an individual can contest an opinion or prediction as opposed to a factual error remains an area of interpretive uncertainty and evolving guidance.
Data subject rights interface
Inferred personal data is generally within the reach of data subject rights, such as access and, subject to conditions, rectification and objection. The application of these rights to inferences, particularly rectification of predictions or opinions, is an area where regulator and case law positions can diverge.

Common questions

Answers to the questions practitioners most commonly ask about Inference.

Is data produced by inference exempt from the GDPR because the individual did not directly provide it?
No. Inferred data can constitute personal data where it relates to an identified or identifiable individual, regardless of whether the individual supplied it directly. The origin of data (provided, observed, or inferred) does not by itself remove it from the scope of the GDPR. Whether a specific inference amounts to personal data is assessed on the facts, and this remains an area where regulatory guidance and case law continue to develop.
Does the right to data portability apply to inferences and profiles a controller has generated?
Generally no. Data portability under the GDPR typically covers personal data that the data subject has provided to the controller, which is commonly understood to include data knowingly provided and, in many interpretations, data observed through the individual's activity. Inferred or derived data created by the controller is generally regarded as falling outside the scope of portability, though it may still be subject to other rights such as access. Interpretations can vary, and readers should verify against current official guidance.
How should we identify a legal basis under Article 6 for generating inferences?
The lawful basis depends on the purpose and context of the inference rather than the fact that inference occurs. Controllers should identify one of the Article 6 bases (such as consent, contract, or legitimate interests) appropriate to the processing, document that assessment, and consider whether the inference produces or uses special category data, which would require an additional condition under Article 9. Where legitimate interests is relied upon, a balancing assessment is typically expected. The appropriate basis is context and risk dependent.
When can an inference reveal special category data, and what does that imply?
An inference may fall within Article 9 where it reveals or is used to deduce information such as health, ethnicity, political opinions, or other special categories, even if drawn from data that is not itself special category. Where this occurs, an Article 9 condition is generally required in addition to an Article 6 basis. Whether a given inference triggers Article 9 is a matter of assessment on the specific facts, and regulators may take differing views.
How should inferences be addressed when responding to a data subject access request?
Personal data held in the form of inferences generally falls within the scope of the right of access, meaning individuals may typically be entitled to be informed that inferences relating to them are held and to receive the associated information required by the access provisions, subject to applicable exemptions. Controllers should consider how inferred data is stored and retrievable so it can be located and disclosed where required. The precise treatment can depend on the nature of the inference and on applicable exemptions.
Should a Data Protection Impact Assessment be considered before deploying inference-based processing?
A DPIA under Article 35 should be considered where inference-based processing is likely to result in a high risk to individuals, for example where it involves systematic and extensive profiling with significant effects or large-scale use of special category data. The need for a DPIA is determined by assessing the risk of the specific processing rather than by the presence of inference alone. Supervisory authorities may publish lists indicating processing that requires a DPIA, which readers should verify against current national guidance.

Common misconceptions

Inferred data is not personal data because the individual did not provide it.
The source of the data is not determinative. Where an inference relates to an identified or identifiable natural person, it generally qualifies as personal data regardless of whether it was provided by the individual or generated through analysis. Only genuinely anonymous data falls outside scope.
Generating inferences always requires consent.
Consent is one of several Article 6 legal bases and is not a universal requirement. Depending on context, another basis such as legitimate interests or contract may apply, subject to assessment. However, where special category data under Article 9 is inferred or involved, an additional Article 9 condition is generally needed.
Data subjects can always compel correction of any inference they dispute.
The right to rectification applies to inaccurate personal data, but how it applies to inferences, predictions, and opinions is subject to interpretive uncertainty and can vary between regulators and case law. Practitioners should treat the precise boundary as unsettled rather than assume a fixed outcome.

Best practices

Assess at the outset whether a given inference relates to an identified or identifiable person, and treat it as personal data where it does, rather than assuming derived data falls outside scope.
Identify and document a specific Article 6 legal basis for the processing that generates and uses inferences, and confirm an additional Article 9 condition where special category data is inferred or relied upon.
Determine whether the inference activity constitutes profiling or automated decision-making, and evaluate the corresponding transparency, safeguards, and rights obligations that may apply.
Maintain records of the source data and processing logic used to produce inferences, so that access requests and any accuracy or contestation challenges can be handled and documented.
Adopt processes for handling data subject requests concerning inferred data, and note internally that the application of rectification and related rights to predictions and opinions is an area of evolving guidance to be monitored.
Verify article references, guidance, and any regulator positions against the current official texts, given divergence between regulators and possible national implementing variations.