ON THE SYSTEMATISATION OF RISKS CAUSED BY THE PROCESSING OF PERSONAL DATAUSING ARTIFICIAL INTELLIGENCE TECHNOLOGIES
DOI:
https://doi.org/10.17721/1728-2195/2021/4.119-10Keywords:
personal data protection; personal data; Artificial Intelligence; innovative technologies; privacy; machine learning; discrimination.Abstract
The purpose of the study in this article is to systematise the risks that may be caused by the processing of personal data using artificial intelligence technologies, according to the criteria of stages of personal data processing and legislation that may be violated due to those risks.
Based on the systematisation of risks, the aim was also to analyse the means of preventing and minimising the risks caused by the use of artificial intelligence technologies.
To achieve the purpose of this work, the following methods were used: structural, functional, systemic, comparative, as well as the method of analysis. Among the special scientific methods are methods of systematic and dynamic interpretation of legislation in the field of personal data protection.
The study analysed in accordance with the legislation of Ukraine and systematised legal risks caused by the processing of personal data using artificial intelligence technologies; identified factors and interests with which it is necessary to balance the minimisation of legal risks; proposed components of a comprehensive regulatory system aimed at minimising risks and ensuring a balance between the interests of individuals and organisations that collect and process personal data. The obtained results allowed to come to the following conclusions: 1) The use of artificial intelligence algorithms in human interaction gives undeniable advantages and social benefits; 2) Unregulated use of this technology poses significant risks of violation of the human right for respect for private life and the right to protection of personal data. The main aspects of such risks are the illegal use of collected personal data for machine learning, opacity and loss of control over the logic of decision-making, as well as the risks of breach of personal data security; 3) In order to minimise risks and ensure a balance between private and public interest, it is necessary to find a comprehensive approach that involves all stakeholders. An integrated approach involves the application of mandatory rules of conduct and the rules of so-called soft law.
References
1. Stamford, Conn.: Gartner Survey Shows 37 Percent of Organizations
Have Implemented AI in Some Form // Gartner. January 21, 2019. URL:
https://www.gartner.com/en/newsroom/press-releases/2019-01-21-gartner-
survey-shows-37-percent-of-organizations-have (acceed: 20.02.2021).
2. Copeland, B.J.. "Artificial intelligence". Encyclopedia Britannica,
URL: https://www.britannica.com/technology/artificial-intelligence. Accessed
29 March 2021.
3. Working Party 29: Guidelines on Automated individual decision-
making and Profiling for the purposes of Regulation 2016/679
(wp251rev.01). October 3, 2017. URL: https://ec.europa.eu/newsroom/
article29/item-detail.cfm?item_id=612053 (acceed: 01.03.2021).
4. Veale Michael, Binns Reuben and Edwards Lilian: Algorithms that
remember: model inversion attacks and data protection law. 2018. Phil.
Trans. R. Soc. A.3762018008320180083. URL: http://doi.org/10.1098/
rsta.2018.0083 (acceed: 01.03.2021).
5. Pro zahyst personalnyh danyh, Zakon Ukrain'y [On personal data
protection, Law of Ukraine] № 2297-VI (2010). URL: https://zakon.rada.gov.ua/
laws/main/2297-17 (acceed: 04.03.2021).
6. Wachter, Sandra and Mittelstadt, Brent, A Right to Reasonable
Inferences: Re-Thinking Data Protection Law in the Age of Big Data and AI
(October 5, 2018). Columbia Business Law Review, 2019(2). URL:
https://ssrn.com/abstract=3248829 (дата звернення: 04.03.2021).
7. A man spent 10 days in jail based on a facial recognition error:
Article // Inputmag. December 29, 2020. URL: https://www.inputmag.com/
tech/a-man-spent-10-days-in-jail-based-on-misclassification-by-clearview-ai
(acceed: 05.03.2021).
8. PENAMERICA, CHILLING EFFECTS: NSA SURVEILLANCE
DRIVES U.S. WRITERS TO SELF-CENSOR 3–4 (2013); Jonathon W.
Penney, Chilling Effects: Online Surveillance and Wikipedia Use (Sept. 8,
2016). URL: https://papers.ssrn.com/abstract=2769645[https://perma.cc/
FGW8-WMVP (acceed: 05.03.2021).
9. James Cook, Amazon Patents New Alexa Feature That Knows
When You're Ill and Offers You Medicine, TELEGRAPH (Oct.9, 2018), URL:
https://www.telegraph.co.uk/technology/2018/10/09/amazon-patents-new-
alexa-feature-knows-offers-medicine/ https://perma.cc/V346-HFWE (дата
звернення: 05.03.2021).
10. Finck, Michèle and Biega, Asia, Reviving Purpose Limitation and
Data Minimisation in Personalisation, Profiling and Decision-Making
Systems (January 11, 2021). Max Planck Institute for Innovation &
Competition Research Paper No. 21-04, URL: https://ssrn.com/
abstract=3749078 (acceed: 05.03.2021).
11. White Paper 'On artificial intelligence – A European approach to
excellence and trust', Brussels, 19.2.2020 COM (2020) 65 final. URL:
https://ec.europa.eu/info/sites/info/files/commission-white-paper-artificial-
intelligence-feb2020_en.pdf (acceed: 09.03.2021).
12. Khartiya osnovnykh prav Yevropeysʹkoho Soyuzu [Charter of
Fundamental Rights of the European Union] (2000). URL:
https://zakon.rada.gov.ua/laws/show/994_524 (acceed: 09.03.2021).
13. Regulation (EU) 2016/679 of the European Parliament and of the
Council of 27 April 2016 on the protection of natural persons with regard to
the processing of personal data and on the free movement of such data,
and repealing Directive 95/46/EC (General Data Protection Regulation).
URL: https://eur-lex.europa.eu/eli/reg/2016/679/oj (acceed: 09.03.2021).
14. Zayarnyy, O.A. (2019) Deyaki napryamy udoskonalennya sposobiv
zahystu informatsiynukh prav fizychnyh osib v umovah zastosyvannya
technologiy shtuchnogo intellectu. Aktualʹni problemy zakhystu
informatsiynykh prav osoby v umovakh tekhnolohichnykh vyklykiv ta
tsyfrovoyi realʹnosti [Some directions of improvement of ways of protection
of information rights of individuals in the conditions of application of
technologies of artificial intelligence. Relevant problems of protection of
information rights of the person in the conditions of technological challenges
and digital reality]. Zbirnyk materialiv Mizhnarodnoyi naukovo-praktychnoyi
konferentsiyi. Kherson: VD "Helʹvetyka" [collection of publications of the
International Scientific and Practical Conference. Kherson: Publisher
"Helvetica"] (2019). pp. 94-98.
15. A call for participation: Building the ICO's auditing framework for
Artificial Intelligence // Information commissioner's office official website.
18 March 2019. URL: https://ico.org.uk/about-the-ico/news-and-events/ai-
blog-a-call-for-participation/ (acceed: 07.04.2021).
16. Asilomar AI Principles. January 17, 2017 // Future of life. URL:
https://futureoflife.org/ai-principles/ (дата звернення: 10.03.2021).
17. Pro shvalennya Conceptcii rozvytku shtuchnoho intelektu v Ukraini,
Rosporyadzhennya Cabinetu Ministriv Ukrain'y [On approving of the
Concept of the development of AI in Ukraine, Order of the Cabinet of
Ministers of Ukraine] № 1556-р (2020). URL: https://zakon.rada.gov.ua/
laws/show/1556-2020-%D1%80#Text (acceed: 07.04.2021).
18. Artificial Intelligence and law enforcement: challenges and
opportunities. December 01, 2020 // Interpol website. URL:
https://www.interpol.int/en/News-and-Events/News/2020/Artificial-Intelligence-
and-law-enforcement-challenges-and-opportunities (acceed: 10.03.2021).
19. Kaminski, Margot E. and Malgieri, Gianclaudio, Algorithmic Impact
Assessments under the GDPR: Producing Multi-layered Explanations
(September 18, 2019). International Data Privacy Law, 2020, forthcoming.,
U of Colorado Law Legal Studies Research Paper No. 19-28, URL:
https://ssrn.com/abstract=3456224 (acceed: 10.03.2021).
20. Guidance on AI and data protection // Information commissioner's
office official website. URL: https://ico.org.uk/for-organisations/guide-to-
data-protection/key-data-protection-themes/guidance-on-artificial-intelligence-
and-data-protection/ (acceed: 07.04.2021).
21. Using Artificial Intelligence and Algorithms // FTC official website,
Apr 8 2020. URL: https://www.ftc.gov/news-events/blogs/business-
blog/2020/04/using-artificial-intelligence-algorithms (acceed: 07.04.2021).
22. A guide to good practice for digital and data-driven health
technologies. Updated 19 January 2021 // UK's Department of Health and
Social Care. URL: https://www.gov.uk/government/publications/code-of-
conduct-for-data-driven-health-and-care-technology/initial-code-of-conduct-
for-data-driven-health-and-care-technology (acceed: 10.03.2021).
23. Open Ethics Initiative. Ethics as Open Data. URL:
https://openethics.ai/ (acceed:10.03.2021).
24. Sandbox for responsible artificial intelligence // Datatilsynet website.
URL: https://www.datatilsynet.no/en/regulations-and-tools/sandbox-for-artificial-
intelligence/ (acceed: 07.04.2021).
25. Braychevsʹkyy S.M. Problema personalʹnykh danykh v systemakh
internetu rechey z elementamy shtuchnoho intelektu. Informatsiya i pravo.
[The problem of personal data in the systems of the internet of things with
elements of artificial intelligence. Information and law.] No 4(31)/2019. URL:
https://ippi.org.ua/sites/default/files/9_13.pdf (acceed: 05.11.2021).
26. Katkova T. H. Shtuchnyy intelekt v ukrayini: pravovi aspekty.
Zhurnal "Pravo i Suspilʹstvo" [Artificial intelligence in Ukraine: legal aspects.
Magazine "Law and Society"] No6/2020. Kharkiv – 2020. URL:
http://pravoisuspilstvo.org.ua/archive/2020/6_2020/10.pdf (acceed: 05.11.2021).
27. Horodysʹkyy I.M. Tendentsiyi rozvytku pravovoho rehulyuvannya
shtuchnoho inteleku v Yevropeysʹkomu Soyuzi. IT pravo: problemy i
perspektyvy rozvytku v Ukrayini (druha mizhnarodna shchorichna
konferentsiya) [Trends in the development of legal regulation of artificial
intelligence in the European Union. IT law: problems and prospects of
development in Ukraine (second international annual conference)]. Lviv –
2017. URL: http://aphd.ua/publication-388/ (acceed: 05.11.2021).
Additional Files
Published
Issue
Section
License
Copyright (c) 2021 Владіслав Некрутенко

This work is licensed under a Creative Commons Attribution 4.0 International License.
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution License that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work (See The Effect of Open Access).
