Using artificial intelligence to support compliance with the general data protection regulation

Artificial Intelligence and Law 25 (4):429-443 (2017)
  Copy   BIBTEX

Abstract

The General Data Protection Regulation is a European Union regulation that will replace the existing Data Protection Directive on 25 May 2018. The most significant change is a huge increase in the maximum fine that can be levied for breaches of the regulation. Yet fewer than half of UK companies are fully aware of GDPR—and a number of those who were preparing for it stopped doing so when the Brexit vote was announced. A last-minute rush to become compliant is therefore expected, and numerous companies are starting to offer advice, checklists and consultancy on how to comply with GDPR. In such an environment, artificial intelligence technologies ought to be able to assist by providing best advice; asking all and only the relevant questions; monitoring activities; and carrying out assessments. The paper considers four areas of GDPR compliance where rule based technologies and/or machine learning techniques may be relevant: Following compliance checklists and codes of conduct; Supporting risk assessments; Complying with the new regulations regarding technologies that perform automatic profiling; Complying with the new regulations concerning recognising and reporting breaches of security. It concludes that AI technology can support each of these four areas. The requirements that GDPR state for explanation and justification of reasoning imply that rule-based approaches are likely to be more helpful than machine learning approaches. However, there may be good business reasons to take a different approach in some circumstances.

Links

PhilArchive



    Upload a copy of this work     Papers currently archived: 91,219

External links

Setup an account with your affiliations in order to access resources via your University's proxy server

Through your library

Similar books and articles

Algo-Rhythms and the Beat of the Legal Drum.Ugo Pagallo - 2018 - Philosophy and Technology 31 (4):507-524.
Risks of artificial general intelligence.Vincent C. Müller (ed.) - 2014 - Taylor & Francis (JETAI).
Prescription Data Mining and the Protection of Patients' Interests.David Orentlicher - 2010 - Journal of Law, Medicine and Ethics 38 (1):74-84.
Legal Regulation of Electronic Marketing.Mindaugas Kiškis - 2010 - Jurisprudencija: Mokslo darbu žurnalas 121 (3):349-370.

Analytics

Added to PP
2017-09-21

Downloads
28 (#538,947)

6 months
7 (#350,235)

Historical graph of downloads
How can I increase my downloads?

Citations of this work

No citations found.

Add more citations