Inferred Data
Inferred data is information about a person that an organization works out or predicts, rather than collecting it directly from the person. For example, a person's likely health status, interests, or characteristics might be inferred by analyzing other signals such as their location or browsing behavior. Because this data is attributed to an individual without being directly captured, questions often arise about how privacy rules apply to it.
Inferred data is data attributed to a data subject through the analytical or predictive processing of other data, rather than being directly captured during or observed from an interaction with them. The source data may be collected directly from the individual, obtained indirectly (for example from external sensors or third parties), and then processed using data analysis techniques to generate new, predictive attributes. Where inferred data relates to an identified or identifiable individual, it will generally constitute personal data, and inferences bearing on health or other Article 9 special categories may attract additional protections subject to assessment. How existing legal definitions of personal data and consent apply to AI-generated inferences remains an area of recognized uncertainty and ongoing debate; practitioners should verify the treatment of specific inferences against current official text and regulatory guidance.
Why it matters
Inferred data sits at a difficult intersection of privacy law because it is attributed to a person without being directly captured from them. When an inference relates to an identified or identifiable individual, it will generally constitute personal data and fall within the scope of data protection rules, yet the individual may be entirely unaware that the attribute exists. This creates practical challenges for transparency, for the exercise of data subject rights, and for identifying an appropriate legal basis under Article 6, since the data is generated by the organization rather than provided by the individual.
A further concern arises where inferences bear on Article 9 special categories. Inferred health data, for example, may be derived from non-health signals such as location or browsing behaviour, meaning an organization can end up processing sensitive information about a person without having deliberately collected health data at all. Where such inferences relate to an identifiable person, they may attract the additional protections applicable to special category data, subject to assessment of the specific processing. This makes inference a category that can quietly escalate the sensitivity and risk profile of an otherwise ordinary dataset.
How existing legal definitions of personal data and consent apply to inferences, particularly those generated by AI systems, remains an area of recognized uncertainty and ongoing debate. Regulators and commentators continue to examine whether current frameworks adequately account for predictive attributes, and treatment may vary in practice. Practitioners should therefore avoid treating any single interpretation as settled and should verify the position for specific inferences against current official text and regulatory guidance.
Who it's relevant to
Inside Inferred Data
Common questions
Answers to the questions practitioners most commonly ask about Inferred Data.