Skip to content

Council of Europe Drafts LLM Privacy Guidelines

29 September 2025

Council of Europe Drafts LLM Privacy Guidelines

The Council of Europe announced draft guidelines on privacy and data protection in the context of Large Language Models (LLMs).

 

 

The guidance aims to support stakeholders in identifying, assessing, mitigating, and monitoring privacy risks in the use of LLMs. 

Key sections from the guidance include: 

➡️ Key definitions and terminology such as the distinction between an LLM and an LLM-based system; 

➡️ The principles from Convention 108+ relevant to LLM-based systems; 

➡️ Stakeholder-specific guidance tailored to providers, deployers, users, and regulators; and 

➡️ General recommendations and points for implementation. 

✅ Firms should review their AI assurance controls and accountability frameworks, ensuring data privacy and protection is pervasive to safeguard personal and company data from misuse. 

💡 Plenitude’s AI Assurance Service supports clients with AI Risk and Control Assessments, diagnosing and mitigating AI risks through the development of controls and governance frameworks.

Visit our website for more information: https://www.plenitudeconsulting.com/services/ai-assurance-services