ON THE SYSTEMATISATION OF RISKS CAUSED BY THE PROCESSING OF PERSONAL DATAUSING ARTIFICIAL INTELLIGENCE TECHNOLOGIES

Authors

  • Vladislav Nekrutenko

DOI:

https://doi.org/10.17721/1728-2195/2021/4.119-10

Keywords:

personal data protection; personal data; Artificial Intelligence; innovative technologies; privacy; machine learning; discrimination.

Abstract

The purpose of the study in this article is to systematise the risks that may be caused by the processing of personal data using artificial intelligence technologies, according to the criteria of stages of personal data processing and legislation that may be violated due to those risks.

Based on the systematisation of risks, the aim was also to analyse the means of preventing and minimising the risks caused by the use of artificial intelligence technologies.

To achieve the purpose of this work, the following methods were used: structural, functional, systemic, comparative, as well as the method of analysis. Among the special scientific methods are methods of systematic and dynamic interpretation of legislation in the field of personal data protection.

The study analysed in accordance with the legislation of Ukraine and systematised legal risks caused by the processing of personal data using artificial intelligence technologies; identified factors and interests with which it is necessary to balance the minimisation of legal risks; proposed components of a comprehensive regulatory system aimed at minimising risks and ensuring a balance between the interests of individuals and organisations that collect and process personal data. The obtained results allowed to come to the following conclusions: 1) The use of artificial intelligence algorithms in human interaction gives undeniable advantages and social benefits; 2) Unregulated use of this technology poses significant risks of violation of the human right for respect for private life and the right to protection of personal data. The main aspects of such risks are the illegal use of collected personal data for machine learning, opacity and loss of control over the logic of decision-making, as well as the risks of breach of personal data security; 3) In order to minimise risks and ensure a balance between private and public interest, it is necessary to find a comprehensive approach that involves all stakeholders. An integrated approach involves the application of mandatory rules of conduct and the rules of so-called soft law.

References

1. Stamford, Conn.: Gartner Survey Shows 37 Percent of Organizations

Have Implemented AI in Some Form // Gartner. January 21, 2019. URL:

https://www.gartner.com/en/newsroom/press-releases/2019-01-21-gartner-

survey-shows-37-percent-of-organizations-have (acceed: 20.02.2021).

2. Copeland, B.J.. "Artificial intelligence". Encyclopedia Britannica,

URL: https://www.britannica.com/technology/artificial-intelligence. Accessed

29 March 2021.

3. Working Party 29: Guidelines on Automated individual decision-

making and Profiling for the purposes of Regulation 2016/679

(wp251rev.01). October 3, 2017. URL: https://ec.europa.eu/newsroom/

article29/item-detail.cfm?item_id=612053 (acceed: 01.03.2021).

4. Veale Michael, Binns Reuben and Edwards Lilian: Algorithms that

remember: model inversion attacks and data protection law. 2018. Phil.

Trans. R. Soc. A.3762018008320180083. URL: http://doi.org/10.1098/

rsta.2018.0083 (acceed: 01.03.2021).

5. Pro zahyst personalnyh danyh, Zakon Ukrain'y [On personal data

protection, Law of Ukraine] № 2297-VI (2010). URL: https://zakon.rada.gov.ua/

laws/main/2297-17 (acceed: 04.03.2021).

6. Wachter, Sandra and Mittelstadt, Brent, A Right to Reasonable

Inferences: Re-Thinking Data Protection Law in the Age of Big Data and AI

(October 5, 2018). Columbia Business Law Review, 2019(2). URL:

https://ssrn.com/abstract=3248829 (дата звернення: 04.03.2021).

7. A man spent 10 days in jail based on a facial recognition error:

Article // Inputmag. December 29, 2020. URL: https://www.inputmag.com/

tech/a-man-spent-10-days-in-jail-based-on-misclassification-by-clearview-ai

(acceed: 05.03.2021).

8. PENAMERICA, CHILLING EFFECTS: NSA SURVEILLANCE

DRIVES U.S. WRITERS TO SELF-CENSOR 3–4 (2013); Jonathon W.

Penney, Chilling Effects: Online Surveillance and Wikipedia Use (Sept. 8,

2016). URL: https://papers.ssrn.com/abstract=2769645[https://perma.cc/

FGW8-WMVP (acceed: 05.03.2021).

9. James Cook, Amazon Patents New Alexa Feature That Knows

When You're Ill and Offers You Medicine, TELEGRAPH (Oct.9, 2018), URL:

https://www.telegraph.co.uk/technology/2018/10/09/amazon-patents-new-

alexa-feature-knows-offers-medicine/ https://perma.cc/V346-HFWE (дата

звернення: 05.03.2021).

10. Finck, Michèle and Biega, Asia, Reviving Purpose Limitation and

Data Minimisation in Personalisation, Profiling and Decision-Making

Systems (January 11, 2021). Max Planck Institute for Innovation &

Competition Research Paper No. 21-04, URL: https://ssrn.com/

abstract=3749078 (acceed: 05.03.2021).

11. White Paper 'On artificial intelligence – A European approach to

excellence and trust', Brussels, 19.2.2020 COM (2020) 65 final. URL:

https://ec.europa.eu/info/sites/info/files/commission-white-paper-artificial-

intelligence-feb2020_en.pdf (acceed: 09.03.2021).

12. Khartiya osnovnykh prav Yevropeysʹkoho Soyuzu [Charter of

Fundamental Rights of the European Union] (2000). URL:

https://zakon.rada.gov.ua/laws/show/994_524 (acceed: 09.03.2021).

13. Regulation (EU) 2016/679 of the European Parliament and of the

Council of 27 April 2016 on the protection of natural persons with regard to

the processing of personal data and on the free movement of such data,

and repealing Directive 95/46/EC (General Data Protection Regulation).

URL: https://eur-lex.europa.eu/eli/reg/2016/679/oj (acceed: 09.03.2021).

14. Zayarnyy, O.A. (2019) Deyaki napryamy udoskonalennya sposobiv

zahystu informatsiynukh prav fizychnyh osib v umovah zastosyvannya

technologiy shtuchnogo intellectu. Aktualʹni problemy zakhystu

informatsiynykh prav osoby v umovakh tekhnolohichnykh vyklykiv ta

tsyfrovoyi realʹnosti [Some directions of improvement of ways of protection

of information rights of individuals in the conditions of application of

technologies of artificial intelligence. Relevant problems of protection of

information rights of the person in the conditions of technological challenges

and digital reality]. Zbirnyk materialiv Mizhnarodnoyi naukovo-praktychnoyi

konferentsiyi. Kherson: VD "Helʹvetyka" [collection of publications of the

International Scientific and Practical Conference. Kherson: Publisher

"Helvetica"] (2019). pp. 94-98.

15. A call for participation: Building the ICO's auditing framework for

Artificial Intelligence // Information commissioner's office official website.

18 March 2019. URL: https://ico.org.uk/about-the-ico/news-and-events/ai-

blog-a-call-for-participation/ (acceed: 07.04.2021).

16. Asilomar AI Principles. January 17, 2017 // Future of life. URL:

https://futureoflife.org/ai-principles/ (дата звернення: 10.03.2021).

17. Pro shvalennya Conceptcii rozvytku shtuchnoho intelektu v Ukraini,

Rosporyadzhennya Cabinetu Ministriv Ukrain'y [On approving of the

Concept of the development of AI in Ukraine, Order of the Cabinet of

Ministers of Ukraine] № 1556-р (2020). URL: https://zakon.rada.gov.ua/

laws/show/1556-2020-%D1%80#Text (acceed: 07.04.2021).

18. Artificial Intelligence and law enforcement: challenges and

opportunities. December 01, 2020 // Interpol website. URL:

https://www.interpol.int/en/News-and-Events/News/2020/Artificial-Intelligence-

and-law-enforcement-challenges-and-opportunities (acceed: 10.03.2021).

19. Kaminski, Margot E. and Malgieri, Gianclaudio, Algorithmic Impact

Assessments under the GDPR: Producing Multi-layered Explanations

(September 18, 2019). International Data Privacy Law, 2020, forthcoming.,

U of Colorado Law Legal Studies Research Paper No. 19-28, URL:

https://ssrn.com/abstract=3456224 (acceed: 10.03.2021).

20. Guidance on AI and data protection // Information commissioner's

office official website. URL: https://ico.org.uk/for-organisations/guide-to-

data-protection/key-data-protection-themes/guidance-on-artificial-intelligence-

and-data-protection/ (acceed: 07.04.2021).

21. Using Artificial Intelligence and Algorithms // FTC official website,

Apr 8 2020. URL: https://www.ftc.gov/news-events/blogs/business-

blog/2020/04/using-artificial-intelligence-algorithms (acceed: 07.04.2021).

22. A guide to good practice for digital and data-driven health

technologies. Updated 19 January 2021 // UK's Department of Health and

Social Care. URL: https://www.gov.uk/government/publications/code-of-

conduct-for-data-driven-health-and-care-technology/initial-code-of-conduct-

for-data-driven-health-and-care-technology (acceed: 10.03.2021).

23. Open Ethics Initiative. Ethics as Open Data. URL:

https://openethics.ai/ (acceed:10.03.2021).

24. Sandbox for responsible artificial intelligence // Datatilsynet website.

URL: https://www.datatilsynet.no/en/regulations-and-tools/sandbox-for-artificial-

intelligence/ (acceed: 07.04.2021).

25. Braychevsʹkyy S.M. Problema personalʹnykh danykh v systemakh

internetu rechey z elementamy shtuchnoho intelektu. Informatsiya i pravo.

[The problem of personal data in the systems of the internet of things with

elements of artificial intelligence. Information and law.] No 4(31)/2019. URL:

https://ippi.org.ua/sites/default/files/9_13.pdf (acceed: 05.11.2021).

26. Katkova T. H. Shtuchnyy intelekt v ukrayini: pravovi aspekty.

Zhurnal "Pravo i Suspilʹstvo" [Artificial intelligence in Ukraine: legal aspects.

Magazine "Law and Society"] No6/2020. Kharkiv – 2020. URL:

http://pravoisuspilstvo.org.ua/archive/2020/6_2020/10.pdf (acceed: 05.11.2021).

27. Horodysʹkyy I.M. Tendentsiyi rozvytku pravovoho rehulyuvannya

shtuchnoho inteleku v Yevropeysʹkomu Soyuzi. IT pravo: problemy i

perspektyvy rozvytku v Ukrayini (druha mizhnarodna shchorichna

konferentsiya) [Trends in the development of legal regulation of artificial

intelligence in the European Union. IT law: problems and prospects of

development in Ukraine (second international annual conference)]. Lviv –

2017. URL: http://aphd.ua/publication-388/ (acceed: 05.11.2021).

Additional Files

Published

27.10.2021

How to Cite

ON THE SYSTEMATISATION OF RISKS CAUSED BY THE PROCESSING OF PERSONAL DATAUSING ARTIFICIAL INTELLIGENCE TECHNOLOGIES. (2021). Bulletin of Taras Shevchenko National University of Kyiv. Legal Studies, 119(4), 53-59. https://doi.org/10.17721/1728-2195/2021/4.119-10