Skip to main content
Category: Data Classification & Identifiers

Inferred Data

Also known as: Inferred Information, Derived Data
Simply put

Inferred data is information about a person that an organization works out or predicts, rather than collecting it directly from the person. For example, a person's likely health status, interests, or characteristics might be inferred by analyzing other signals such as their location or browsing behavior. Because this data is attributed to an individual without being directly captured, questions often arise about how privacy rules apply to it.

Formal definition

Inferred data is data attributed to a data subject through the analytical or predictive processing of other data, rather than being directly captured during or observed from an interaction with them. The source data may be collected directly from the individual, obtained indirectly (for example from external sensors or third parties), and then processed using data analysis techniques to generate new, predictive attributes. Where inferred data relates to an identified or identifiable individual, it will generally constitute personal data, and inferences bearing on health or other Article 9 special categories may attract additional protections subject to assessment. How existing legal definitions of personal data and consent apply to AI-generated inferences remains an area of recognized uncertainty and ongoing debate; practitioners should verify the treatment of specific inferences against current official text and regulatory guidance.

Why it matters

Inferred data sits at a difficult intersection of privacy law because it is attributed to a person without being directly captured from them. When an inference relates to an identified or identifiable individual, it will generally constitute personal data and fall within the scope of data protection rules, yet the individual may be entirely unaware that the attribute exists. This creates practical challenges for transparency, for the exercise of data subject rights, and for identifying an appropriate legal basis under Article 6, since the data is generated by the organization rather than provided by the individual.

A further concern arises where inferences bear on Article 9 special categories. Inferred health data, for example, may be derived from non-health signals such as location or browsing behaviour, meaning an organization can end up processing sensitive information about a person without having deliberately collected health data at all. Where such inferences relate to an identifiable person, they may attract the additional protections applicable to special category data, subject to assessment of the specific processing. This makes inference a category that can quietly escalate the sensitivity and risk profile of an otherwise ordinary dataset.

How existing legal definitions of personal data and consent apply to inferences, particularly those generated by AI systems, remains an area of recognized uncertainty and ongoing debate. Regulators and commentators continue to examine whether current frameworks adequately account for predictive attributes, and treatment may vary in practice. Practitioners should therefore avoid treating any single interpretation as settled and should verify the position for specific inferences against current official text and regulatory guidance.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance teams need to identify where inference-based processing occurs, since inferred attributes can be personal data even though they were never directly collected. This affects transparency obligations, the identification of an appropriate legal basis, and the handling of data subject rights over attributes the individual may not know exist. Where inferences may touch on special categories, an assessment of whether additional Article 9 conditions apply is generally warranted.
Privacy and Data Protection Lawyers
Lawyers advising on inferred data must grapple with recognized uncertainty about how definitions of personal data and consent apply to predictive and AI-generated inferences. Advice should be framed cautiously, flag areas of ongoing debate and potential regulatory divergence, and direct clients to verify the treatment of specific inferences against current official text and guidance rather than relying on a single settled interpretation.
Engineers and Data Scientists Building Analytical or AI Systems
Teams designing systems that generate predictive attributes from source data should recognize that their outputs may create new personal data, and potentially special category data, even when the input signals appear non-sensitive. This has implications for how models are documented, how inferred attributes are stored and surfaced, and how the design supports downstream transparency and rights obligations.
Organizations Processing Health-Adjacent Signals
Organizations that process signals such as location or browsing behaviour should be aware that health status can be inferred from non-health data. Where such inferences relate to identifiable individuals, they may raise the sensitivity and risk profile of the processing and, subject to assessment, may attract the additional protections applicable to special category data.

Inside Inferred Data

Derived or inferred information
Data that is not directly provided by or observed from the individual but is produced by an organization through analysis, correlation, or algorithmic processing of other data (for example, a predicted preference, credit risk score, or health indicator inferred from behavioral signals).
Underlying source data
The provided or observed personal data, and potentially anonymous or aggregated inputs, from which the inference is generated. The characterization of the inputs does not by itself determine the status of the output.
Personal data status of the inference
Where an inference relates to an identified or identifiable individual, it generally constitutes personal data in its own right and falls within scope of the GDPR, subject to assessment of identifiability in the specific context.
Potential special category character
An inference may reveal or predict special category data under Article 9 (such as health, ethnicity, or sexual orientation) even where the input data is not itself special category. Whether this triggers Article 9 conditions depends on the nature and purpose of the inference and remains an area where regulator views can differ.
Legal basis for the inferring activity
Generating inferred data is a processing operation that requires an Article 6 basis (and, where applicable, an Article 9 condition). Consent is one possible basis but is not universally required; legitimate interests, contract, or other bases may apply subject to assessment.

Common questions

Answers to the questions practitioners most commonly ask about Inferred Data.

Is inferred data exempt from the GDPR because the organisation created it rather than collecting it directly from the individual?
No. The fact that an organisation generates data through analysis, profiling, or algorithmic processing rather than obtaining it directly from the data subject does not remove it from the scope of the GDPR. Where an inference relates to an identified or identifiable individual, it will generally constitute personal data and the organisation processing it will typically act as a controller with corresponding obligations. The manner of creation does not alter this analysis; what matters is whether the data relates to an identifiable person.
Because inferred data is only a probability or prediction rather than a verified fact, does that mean data subject rights such as access and rectification do not apply?
This is a misconception. The probabilistic or predictive nature of an inference does not exclude it from data subject rights where it qualifies as personal data. Rights such as access can generally apply to inferences held about an individual, subject to recognised limits. The position on rectification is more nuanced and subject to debate, because a right to correct an opinion or prediction differs from correcting a factual error; regulators and case law have addressed aspects of this and the boundary remains an area of some uncertainty. Readers should assess each situation on its facts and verify against current guidance.
How should an organisation identify a legal basis under Article 6 for generating and using inferred data?
The organisation should identify a distinct lawful basis for the processing activity that produces and uses the inference, chosen from the Article 6 bases and assessed against the specific purpose. Consent is not automatically required; legitimate interests may be relevant in some contexts subject to a balancing assessment, while other bases may be more appropriate depending on the circumstances. Where the inference concerns special category data under Article 9, an additional Article 9 condition is generally needed. The basis should be determined before processing and documented.
When can an inference amount to special category data requiring an Article 9 condition?
An inference can fall within special category data where it reveals information such as health, racial or ethnic origin, or other categories protected under Article 9, even if the underlying inputs were not themselves special category data. This assessment depends on what the inference reveals and the purpose of the processing, and there is recognised complexity in determining when an inference crosses into a special category. Where it does, an appropriate Article 9 condition must be identified in addition to the Article 6 basis. The precise boundary should be assessed case by case and checked against current regulatory guidance.
What should an organisation disclose about inferred data in its transparency information?
Transparency information should generally reflect that the organisation derives or infers data about individuals, describing the purposes and, where applicable, the logic and consequences relevant to automated decision-making or profiling. The level of detail should be sufficient to inform the data subject meaningfully, subject to assessment of what is proportionate in the specific context. Organisations should ensure that inferences are not omitted from privacy information simply because they were generated internally.
Should the creation of inferred data through profiling be considered in a Data Protection Impact Assessment?
In many cases, yes. Where inferred data is produced through profiling or other processing that is likely to result in a high risk to individuals, a Data Protection Impact Assessment under Article 35 may be required, and it is generally advisable to consider inference-related risks within that assessment. Whether a DPIA is mandatory depends on the nature, scope, context, and purposes of the processing and should be assessed against the relevant criteria and any applicable regulator lists, which can vary between member states.

Common misconceptions

Inferred data is not personal data because the individual did not supply it.
Whether data is provided, observed, or inferred does not change its classification. If an inference relates to an identified or identifiable person, it is generally personal data and within scope of the GDPR, subject to an identifiability assessment in context.
If the input data is not special category, the inference cannot be special category either.
An inference can reveal or predict special category information (for example, health or ethnicity) from ordinary inputs. Whether Article 9 applies to such inferences depends on their nature and purpose, and this is an area where regulator and case law positions can diverge; readers should verify against current guidance.
Data subject rights, such as access, do not extend to inferences.
Where an inference is personal data, rights such as access, rectification, and erasure can in principle apply to it, though the precise extent, particularly for rectification of predictive or opinion-based inferences, is subject to assessment and can vary by context and regulator interpretation.

Best practices

Map and document your inference-generating activities, recording what inferences are produced, the source data used, and the purposes, so the processing is transparent within your records.
Assess and document the applicable Article 6 legal basis for the act of generating and using inferences, and do not assume consent is required or sufficient without evaluating the specific processing.
Evaluate whether any inference reveals or predicts special category data and, if so, identify a valid Article 9 condition; treat borderline cases conservatively and revisit them as regulator guidance develops.
Reflect inferred data in transparency notices and in your handling of data subject requests, including access, rectification, and erasure, recognizing that the extent of these rights over predictive inferences may be subject to assessment.
Conduct a risk assessment before deploying inferences that may significantly affect individuals, and consider whether a Data Protection Impact Assessment under Article 35 is warranted given the nature and impact of the processing.
Periodically review inference practices against evolving case law and regulator guidance, and verify any specific legal positions against the current official text rather than relying on a fixed snapshot.