Found in 3 comments on Hacker News
downandout · 2018-05-26 · Original thread
”The GDPR, as a matter of law, does contain a blanket prohibition on the use of automated decision-making, so long as that decision-making occurs without human intervention and produces significant effects on data subjects. Importantly, the GDPR itself applies to all uses of EU data that could potentially identify a data subject—which, in any data science program using large volumes of data, means that the GDPR will apply to almost all activities (as study after study has illustrated the ability to identify individuals given enough data).”

From https://www.oreilly.com/ideas/how-will-the-gdpr-impact-machi...

downandout · 2018-05-26 · Original thread
Can you point to the specific bit of GDPR that outlaws machine learning?

Here's a whole article on the subject [1] and HN discussion thread [2] . Any machine learning application that utilizes automated decision making - which is the entire point of machine learning - is forbidden under the GDPR. This can be overcome with explicit consent for that specific application of ML, but getting that in most circumstances will be a low percentage shot.

There are no additional risks imposed by GDPR; all of those risks already exist in other privacy directives.

Fines of up to 20 million EUR are a significant and new risk.

[1] https://www.oreilly.com/ideas/how-will-the-gdpr-impact-machi...

[2] https://news.ycombinator.com/item?id=17138354