Since several years, data protection regulators have been active in analysing the privacy risks to individuals from the advanced use of neurodata in health-related applications and progressively adapting their policy response. While debates are still ongoing, a discernible pattern of regulatory analysis is emerging, which was visible at the workshop. That pattern consistently revolves around several key themes presented in the following paragraphs and summarised in Table 2.3.
The European Data Protection Supervisor (EDPS) and the Spanish Data Protection Authority (AEPD) have warned of unprecedented intrusions into private life, noting that neurodata are inherently personal, and often sensitive (European Data Protection Supervisor, 2024[7]). They also noted increased risks of discriminatory uses, especially in employment, education, and insurance contexts. France’s bioethics law, which restricts brain‑imaging technologies to medical, scientific, or judicial uses, was highlighted as a precautionary approach to preventing misuse (Légifrance, 2021[23]). The UK ICO identified significant risks to information rights, urged clarity on when neurodata becomes special‑category data, warned against discriminatory or opaque uses, and prepared targeted neurodata guidance to ensure privacy‑by‑design (ICO, 2023[3]).
Regulators observed that recent technological advances make it increasingly feasible to record and analyse brain activity without an individual’s awareness or meaningful consent. At the workshop, authorities from Spain, the UK, France, and the EU emphasised that neurotechnology can capture both conscious and subconscious mental processes, making covert or involuntary data collection a realistic risk that requires enhanced safeguards.
They further noted that meaningful consent may be difficult to obtain in neurotechnology contexts. The depth and sensitivity of neurodata, combined with the possibility that neurotechnologies may influence users’ mental states or decision‑making capacity, challenge the assumption that consent alone, even if provided by the individuals concerned, can sufficiently protect them.
A fundamental challenge is the absence of a clear, broadly accepted definition of brain or neurodata in data protection laws, which creates uncertainty on the applicability of data protection laws and/or on the breadth of related data protection obligations. For instance, as mentioned earlier, an ongoing debate is whether all neurodata should automatically fall under health data provisions. In such cases, the processing of neurodata is subject to reinforced requirements, such as express consent. Additionally, neurotechnology applications in some settings collect a broader range of nervous system data, which added to brain data enriches the output. Alternatively, regulators also discuss where distinctions are needed, depending on the type of signal, context, and use, so that privacy protection measures are effectively adapted to the assessment level of the sensitivity of this data. In its recent guidance, the UK ICO specifically urged clarity on when neurodata becomes special‑category data (ICO, 2024[24]).
Together with industry and civil society, privacy regulators readily acknowledge that latest advances in neurotechnology challenge some foundational privacy principles. For instance, many applications generate large volumes of neurodata effortlessly, raising questions about the implementation of core data protection principles such as purpose limitation and data minimisation.
Another debate concerns whether certain uses should be prohibited outright due to extreme risks such as manipulation, behavioural control, harmful stimulation, or surveillance, or whether the admissibility of every use should be assessed on a case‑by‑case basis, based on risks—subject to strict oversight, informed consent, and privacy‑by‑design approaches. In this regard, the Global Privacy Assembly adopted a resolution stipulating that neurodata should be treated as highly sensitive, with prohibitions on harmful uses and requirements for transparency, privacy‑by‑design, and protections for vulnerable groups (GPA, 2024[25]).1
Another highlight is the growing reliance of neurotechnology on AI to decode raw neural signals, enabling the extraction of highly sensitive insights such as emotions, intentions, or cognitive patterns. A related concern is the status of AI‑generated inferences derived from neural recordings. Regulators cautioned that without clear rules, inferred data could fall outside existing privacy protections, despite being equally or more sensitive as the original data itself, therefore requiring equivalent governance.
Regulators noted that this level of sensitivity may justify protections that go beyond existing health data classifications, particularly in the face of growing commercial neurotechnology. Based on this reflection, some privacy regulators including the EDPS, AEPD and UK ICO, have been participating in legal and policy debates on the creation of new “neurorights” and on their explicit addition to frameworks like the Oviedo Convention2. On the other hand, the European Parliamentary Research Service argues that existing human rights frameworks already provide strong protection—rendering new neurorights unnecessary—while recommending targeted reforms such as explicitly adding neurodata to Article 9 GDPR and creating a risk based Neurotechnology Act (EPRS, 2024[26]).
Experts at the workshop added that strengthened regulatory frameworks should be complemented by technical protections embedded directly into neurotechnologies and AI systems. Such safeguards may include design‑level constraints, built‑in limitations on data capture and processing, and specific privacy enhancing architectures and technologies (PETs) aimed at reducing risks before data leaves the device and when it is stored (OECD, 2023[27]).