In June 2026, the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, “IMY”) published a report on how the roles of controller and processor under the GDPR should be assessed when pre-trained AI models are fine-tuned. The guidance is relevant both to providers of AI solutions and to organisations procuring and adapting such solutions.
Fine-tuning raises new GDPR questions
Many AI services are based on pre-trained models that are subsequently adapted to a particular organisation or use case. One way of doing this is through fine-tuning, where an existing model is further trained using more specific or specialised data.
Where such data contains personal data, the GDPR applies. A key question is then who acts as controller in respect of the processing and whether the AI provider instead – or in relation to certain processing activities – acts as a processor.
During spring 2026, IMY examined these issues as part of a pilot project conducted together with the Swedish AI company Eggsplain.
The actual processing determines the parties' roles
A central conclusion in IMY's report is that a provider's role under the GDPR cannot be determined simply by looking at the type of service being provided.
The fact that a supplier provides, for example, AI technology, infrastructure or technical support does not in itself mean that the supplier acts as a processor.
Instead, each processing activity must be assessed on the basis of what the supplier actually does with the personal data, why the processing takes place and who determines the purposes and means of the processing.
This reflects the fundamental GDPR principle that the roles of controller and processor are determined by the parties' actual functions rather than merely by how their relationship is described in an agreement.
Three fine-tuning scenarios
IMY examines, among other things, three different scenarios.
1. The provider fine-tunes the model for its own product development
Where an AI provider, on its own initiative, uses personal data to fine-tune a model as part of its own product development, this indicates that the provider acts as controller for that processing.
This may, for example, be the case where a provider uses data to generally improve a product or model that can subsequently be offered to other customers.
The provider must then itself ensure that there is a lawful basis for the processing and that the other applicable requirements of the GDPR are met.
2. Fine-tuning is carried out for a specific customer
The assessment is different where the provider fine-tunes the model on behalf of a particular customer, in accordance with that customer's instructions and for the customer's purposes.
In this situation, IMY considers that the customer will generally be the controller and the provider the processor.
Among other things, this means that the processing must be governed by a data processing agreement and that, as a starting point, the provider may only process the personal data on the customer's documented instructions.
3. The customer and provider develop the solution together
AI projects are not always divided so clearly between customer and provider.
The customer and provider may jointly influence how personal data is to be used when developing or fine-tuning the model. Where the parties jointly determine the purposes and essential means of the processing, they may instead be joint controllers.
This requires a different contractual and regulatory structure from a traditional controller–processor relationship.
An AI provider may have several GDPR roles at the same time
An important practical consequence is that it may not be possible to assign a single GDPR role to the entire relationship between a customer and an AI provider.
For example, a provider may act as a processor when processing customer data to provide the agreed AI service, while acting as a controller for separate processing where personal data is used for the provider's own product development.
It is therefore important to identify the different processing activities and assess the parties' roles separately for each activity.
What does this mean for AI agreements?
IMY's guidance has practical implications for both the procurement and negotiation of AI services.
Customers should, among other things, understand:
- what data is used to provide the service;
- whether customer data is used for training or fine-tuning;
- whether data may be used for the provider's general product development;
- who determines the purpose of each processing activity;
- whether the provider acts as processor, independent controller or potentially as a joint controller; and
- how each processing activity is addressed contractually.
A standard data processing agreement stating that the provider is a processor for all processing activities may therefore not always be sufficient.
In particular, provisions allowing an AI provider to use customer data to train, improve or further develop its own models should be carefully analysed. Such use may mean that the provider processes personal data for its own purposes and therefore becomes a controller in respect of that processing.
Mapping the data flows is key
IMY's report illustrates a broader issue that is becoming increasingly important when procuring AI services: the legal analysis must reflect how data is actually used.
Both customers and providers therefore have reason to map data flows and processing purposes before determining the parties' GDPR roles and drafting the relevant contractual provisions.
This is particularly important where an AI solution is not merely used as a static service but is continuously adapted, trained or further developed using data from the customer's business.

