Consent-Aware Data Processing Frameworks for Ethical AI Systems

Authors

  • Eva Novak Associate Professor, School of Data Science, Central European Tech University, Vienna, Austria Author
  • Lukas Silva Senior Lecturer, Department of Machine Learning, Baltic AI Research University, Tallinn, Estonia Author

DOI:

https://doi.org/10.5281/

Keywords:

consent management, AI data processing, GDPR, machine unlearning, consent enforcement, responsible AI, data subject rights, EU AI Act

Abstract

Consent -- the freely given, specific, informed, and unambiguous indication of agreement to the processing of personal data -- is a foundational legal basis for AI systems that train on or process personal data under the GDPR (2016). Yet consent management in AI contexts presents distinctive technical and architectural challenges that conventional consent management platforms (CMPs) are not designed to address: consent scope must be mapped to specific AI training or inference uses; consent withdrawal must propagate through trained models in the form of machine unlearning or model retraining; consent must be dynamically managed across the full AI data lifecycle including model updates and federated deployments; and consent validity must be continuously verified as AI system purposes evolve. This paper proposes the Consent-Aware AI Processing (CAAP) framework, a technical and governance architecture for managing consent across the full AI data processing lifecycle. CAAP comprises five components: Consent Registry (CR), Purpose-Consent Mapper (PCM), Consent Enforcement Engine (CEE), Machine Unlearning Interface (MUI), and Consent Audit Trail (CAT). The framework is evaluated through a proof-of-concept implementation on two production AI systems -- a clinical risk prediction system and a personalised recommendation engine -- and through an expert assessment involving 28 data protection and AI governance specialists. Expert consensus (Kendall W = 0.78, p < 0.001) confirms strong agreement on CAAP component importance. Proof-of-concept evaluation demonstrates 100% consent enforcement accuracy for the CEE component, sub-200ms consent verification latency at inference, and technically feasible machine unlearning for both linear and neural network model classes. The study contributes the CAAP specification, a Consent Compliance Assessment (CCA) instrument, and practical guidance for GDPR-compliant AI consent architecture design.

Author Biographies

  • Eva Novak, Associate Professor, School of Data Science, Central European Tech University, Vienna, Austria

    Associate Professor, School of Data Science, Central European Tech University, Vienna, Austria

  • Lukas Silva, Senior Lecturer, Department of Machine Learning, Baltic AI Research University, Tallinn, Estonia

    Senior Lecturer, Department of Machine Learning, Baltic AI Research University, Tallinn, Estonia

Downloads

Published

2025-09-18

How to Cite

Consent-Aware Data Processing Frameworks for Ethical AI Systems. (2025). AI Governance and Society Journal P-ISSN 3117-6097 and E-ISSN 3117-6100, 2(3), 42-49. https://doi.org/10.5281/