{"id":6187,"date":"2021-09-30T08:48:00","date_gmt":"2021-09-30T06:48:00","guid":{"rendered":"https:\/\/serengetitech.com\/?p=6187"},"modified":"2026-02-18T13:10:14","modified_gmt":"2026-02-18T12:10:14","slug":"machine-learning-meets-gdpr","status":"publish","type":"post","link":"https:\/\/serengetitech.com\/de\/business\/machine-learning-meets-gdpr\/","title":{"rendered":"Machine Learning meets GDPR"},"content":{"rendered":"<p class=\"eplus-Zdq0ZD eplus-wrapper\"><\/p>\n\n\n<h2 class=\"eplus-r6EKui wp-block-heading eplus-wrapper eplus-styles-uid-ee84c0\">The impact of GDPR on Machine Learning and Artificial Intelligence<\/h2>\n\n\n<p class=\"eplus-GAPN4j eplus-wrapper\">Many AI applications process personal data that can be used to analyze, predict, and affect human behavior. Thanks to AI, we can turn such data and the results of its processing into valuable commodities.<\/p>\n\n\n\n<p class=\"eplus-xFUw8v eplus-wrapper\">Machine Learning algorithms are based on large amounts of data that <a href=\"https:\/\/serengetitech.com\/de\/tech\/the-importance-of-data-in-machine-learning\/\">need to be processed<\/a> for the algorithm to learn. The way this data is used is a critical component in determining fairness. Personal data can be used for research reasons alone, such as detecting patterns and correlations. On the other hand, the data can also be used to make choices that impact individuals. Even in sectors where complicated decisions must be made based on many aspects and non-predefined criteria, the combination of AI and Big Data allows automatic decision-making. In recent years, there has been much discussion over the benefits and drawbacks of algorithmic assessments and choices affecting people.<\/p>\n\n\n\n<p class=\"eplus-Yueeip eplus-wrapper\">For example, displaying a specific online advertisement to a person based on their social media and web activities may not be considered intrusive and may even be appreciated if suits their interest. However, in some cases, this can be perceived as discrimination. An example that took place recently relates to the Facebook AI system, that labelled a video of black men as \u201eprimates\u201d. The video, which showed recordings of Black men in altercations with police and white bystanders, automatically prompted viewers to \u201c<a href=\"https:\/\/www.nytimes.com\/2021\/09\/03\/technology\/facebook-ai-race-primates.html\">keep seeing videos about Primates.<\/a>\u201d<\/p>\n\n\n\n<p class=\"eplus-VFLm1o eplus-wrapper\">Another example shows a bias against women \u2013 a female doctor&nbsp;<a rel=\"noreferrer noopener\" href=\"https:\/\/www.mirror.co.uk\/news\/uk-news\/doctor-locked-out-womens-changing-5358594\" target=\"_blank\">was shut out of a women's gym locker<\/a>&nbsp;area because the automated safety system mistook her for a man because the term \u201cDr.\u201d was associated with men only.&nbsp;<\/p>\n\n\n\n<p class=\"eplus-RFZRFs eplus-wrapper\"><\/p>\n\n\n<h3 class=\"eplus-8VvVJN wp-block-heading eplus-wrapper eplus-styles-uid-ee84c0\"><strong>The Connection Between AI and GDPR<\/strong><\/h3>\n\n\n<p class=\"eplus-itXJa9 eplus-wrapper\">GDPR requires companies to comply with regulations that will secure consumer data. But questions have been raised about how this regulation will address automation in analytics as the AI and machine learning market grows.<\/p>\n\n\n\n<p class=\"eplus-xdZEjg eplus-wrapper\">As stated by the&nbsp;<a href=\"https:\/\/edpb.europa.eu\/sites\/default\/files\/files\/file1\/edpb_letter_out2020_0004_intveldalgorithms_en.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">European Data Protection Board<\/a>, \u201eAny processing of personal data through an algorithm falls within the scope of the GDPR.\u201c Therefore, whenever a Machine Learning algorithm or AI system uses personal data, GDPR may apply.&nbsp;<\/p>\n\n\n\n<p class=\"eplus-bJsi1k eplus-wrapper\">The two significant components of machine learning are addressed by the GDPR legislation. First, it improves data security by combining AI with data privacy. Companies that collect and process personal data are subject to stringent responsibilities under the law. Second, this regulation specifically targets \u201eautomated individual decision-making\u201d and profiling.<\/p>\n\n\n\n<p class=\"eplus-NVc4Ai eplus-wrapper\">According to&nbsp;<a href=\"https:\/\/www.privacy-regulation.eu\/en\/article-22-automated-individual-decision-making-including-profiling-GDPR.htm\" target=\"_blank\" rel=\"noreferrer noopener\">Article 22<\/a>&nbsp;of GDPR, an individual has the right not to be subject to either if they have legal effects on them. This gives data subjects the right to be excluded from exclusively automated processing, including profiling. While Article 22 is a general restriction, Article 15 gives stricter requirements that are linked to automated decision-making and profiling, that include:<\/p>\n\n\n<ul class=\"eplus-KCBfJ3 wp-block-list eplus-wrapper eplus-styles-uid-571a43\">\n<li class=\"eplus-wrapper\">The \u201cexistence\u201d of automated decision-making, including profiling.<\/li>\n\n\n\n<li class=\"eplus-wrapper\">\u201cMeaningful information about the logic involved.\u201d<\/li>\n\n\n\n<li class=\"eplus-wrapper\">\u201cThe significance and the envisaged consequences of such processing\u201d for the individual.<\/li>\n<\/ul>\n\n<h3 class=\"eplus-Cz21fq wp-block-heading eplus-wrapper eplus-styles-uid-ee84c0\"><strong>Legal Challenges Related to AI<\/strong><\/h3>\n\n\n<p class=\"eplus-ir0FL3 eplus-wrapper\">GDPR outlines six&nbsp;<a href=\"https:\/\/www.itgovernance.eu\/blog\/en\/the-gdpr-understanding-the-6-data-protection-principles\" target=\"_blank\" rel=\"noreferrer noopener\">data protection principles<\/a>, and according to&nbsp;<a href=\"https:\/\/www.datatilsynet.no\/globalassets\/global\/english\/ai-and-privacy.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">Norwegian Data Protection Authority<\/a>, AI is facing four of them:<\/p>\n\n\n<ol class=\"eplus-YPNPLd wp-block-list eplus-wrapper eplus-styles-uid-b94b62\">\n<li class=\"eplus-wrapper\">Fairness\u00a0and bias<\/li>\n<\/ol>\n\n\n<p class=\"eplus-QALtYr eplus-wrapper\">As shown in the examples at the beginning of this post, there are possibilities that algorithmic decisions may be discriminatory or mistaken. There are steps you can take to minimize bias. Choosing the correct learning model (supervised or unsupervised), the right training data, and monitoring the performance should have a positive impact on bias minimization.<\/p>\n\n\n<ol start=\"2\" class=\"eplus-OVvOro wp-block-list eplus-wrapper eplus-styles-uid-a0bc9b\">\n<li class=\"eplus-wrapper\">Data minimization<\/li>\n<\/ol>\n\n\n<p class=\"eplus-hBdnrq eplus-wrapper\">Companies must minimize the quantity of data they gather and analyze. They must guarantee that the personal information is adequate \u2013 that it is sufficient to correctly fulfill the specified purpose; relevant \u2013 that it has a reasonable relationship to that goal; and restricted to what is necessary \u2013 that they do not keep more than they need for that objective.<\/p>\n\n\n<ol start=\"3\" class=\"eplus-W3xM3c wp-block-list eplus-wrapper eplus-styles-uid-597d96\">\n<li class=\"eplus-wrapper\">Purpose limitation<\/li>\n<\/ol>\n\n\n<p class=\"eplus-ePvB1K eplus-wrapper\">Besides minimization, personal data may only be collected for a specific and precisely defined purpose.<\/p>\n\n\n<ol start=\"4\" class=\"eplus-i3gfgg wp-block-list eplus-wrapper eplus-styles-uid-18a22b\">\n<li class=\"eplus-wrapper\">Transparency<\/li>\n<\/ol>\n\n\n<p class=\"eplus-MvyMZM eplus-wrapper\">Transparency entails providing individuals with clear information on how their personal data is processed using AI, as well as any possible impact on their privacy. People must be aware that their data is being gathered and how it is being processed.&nbsp;<\/p>\n\n\n<h3 class=\"eplus-RZYSGZ wp-block-heading eplus-wrapper eplus-styles-uid-ee84c0\"><strong>Building a Trustworthy AI<\/strong><\/h3>\n\n\n<p class=\"eplus-IapynX eplus-wrapper\">According to the <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/expert-group-ai\">High-Level Expert Group<\/a>, seven conditions must be satisfied to deploy and establish trustworthy AI:<\/p>\n\n\n<ul class=\"eplus-yVgBEr wp-block-list eplus-wrapper eplus-styles-uid-f799b5\">\n<li class=\"eplus-wrapper\">Human agency and oversight, including fundamental rights.<\/li>\n\n\n\n<li class=\"eplus-wrapper\">Technical robustness and safety, including attack resilience and security, a backup plan, general safety, accuracy, dependability, and repeatability.<\/li>\n\n\n\n<li class=\"eplus-wrapper\">Privacy and data governance.<\/li>\n\n\n\n<li class=\"eplus-wrapper\">Transparency, which includes traceability, explanation, and communication.<\/li>\n\n\n\n<li class=\"eplus-wrapper\">Diversity and non-discrimination.<\/li>\n\n\n\n<li class=\"eplus-wrapper\">Societal and environmental wellbeing.<\/li>\n\n\n\n<li class=\"eplus-wrapper\">Accountability, includes audibility, negative effect reduction and reporting, trade-offs, and restitution.<\/li>\n<\/ul>\n\n\n<p class=\"eplus-0wkYL3 eplus-wrapper\">For companies that are purchasing or building IT solutions based on AI, there are a couple of recommendations for the protection of personal data:<\/p>\n\n\n<ul class=\"eplus-gFGVnR wp-block-list eplus-wrapper eplus-styles-uid-8a0ad2\">\n<li class=\"eplus-wrapper\">Before you buy a solution, perform risk assessment.<\/li>\n\n\n\n<li class=\"eplus-wrapper\">Require that the system you build or buy meets the privacy needs by design.<\/li>\n\n\n\n<li class=\"eplus-wrapper\">Conduct regular tests for regulatory requirements compilation.<\/li>\n\n\n\n<li class=\"eplus-wrapper\">Use good systems for subjects\u2019 data protection.<\/li>\n<\/ul>\n\n\n<p class=\"eplus-KYLx6R eplus-wrapper\">If you are looking for a business consultant, or even an entire team of experts who are already familiar with the best practices and who have seen what strategies work in different places and projects, feel free to <a href=\"https:\/\/serengetitech.com\/de\/kontakt\/\">reach out<\/a>.<\/p>\n\n\n\n<p class=\"eplus-KmOzeq eplus-wrapper\"><\/p>\n\n\n\n<p class=\"eplus-RL9yrS eplus-wrapper\"><\/p>","protected":false},"excerpt":{"rendered":"<p>Machine Learning algorithms are based on large amounts of data that need to be processed for the algorithm to learn. GDPR requires companies to comply with regulations that will secure consumer data. But questions have been raised about how this regulation will address automation in analytics as the AI and machine learning market grows. GDPR outlines six data protection principles, and according to Norwegian Data Protection Authority, AI is facing four of them.<\/p>","protected":false},"author":4,"featured_media":6190,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_seopress_robots_primary_cat":"none","_seopress_titles_title":"Machine Learning meets GDPR %%sep%% Serengeti","_seopress_titles_desc":"How will GDPR address automation in analytics as the AI and machine learning market grows? There are six\u00a0data protection principles, and AI is facing four of them","_seopress_robots_index":"","inline_featured_image":false,"_kad_blocks_custom_css":"","_kad_blocks_head_custom_js":"","_kad_blocks_body_custom_js":"","_kad_blocks_footer_custom_js":"","editor_plus_copied_stylings":"{}","footnotes":""},"categories":[10],"tags":[167,83,55],"class_list":["post-6187","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-business","tag-ai","tag-gdpr","tag-machine-learning"],"acf":[],"taxonomy_info":{"category":[{"value":10,"label":"Business"}],"post_tag":[{"value":167,"label":"Ai"},{"value":83,"label":"GDPR"},{"value":55,"label":"Machine Learning"}]},"featured_image_src_large":["https:\/\/cdn.shortpixel.ai\/spai\/q_glossy+ret_img+to_auto\/serengetitech.com\/wp-content\/uploads\/2021\/09\/shutterstock_1898086354-1-1024x527.jpg",1024,527,true],"author_info":{"display_name":"Malina Kri\u0161to","author_link":"https:\/\/serengetitech.com\/de\/author\/malina-kristo\/"},"comment_info":"","category_info":[{"term_id":10,"name":"Business","slug":"business","term_group":0,"term_taxonomy_id":10,"taxonomy":"category","description":"Business - blog section dedicated to business topics, both traditional ones and trends.","parent":0,"count":187,"filter":"raw","cat_ID":10,"category_count":187,"category_description":"Business - blog section dedicated to business topics, both traditional ones and trends.","cat_name":"Business","category_nicename":"business","category_parent":0}],"tag_info":[{"term_id":167,"name":"Ai","slug":"ai","term_group":0,"term_taxonomy_id":167,"taxonomy":"post_tag","description":"","parent":0,"count":9,"filter":"raw"},{"term_id":83,"name":"GDPR","slug":"gdpr","term_group":0,"term_taxonomy_id":83,"taxonomy":"post_tag","description":"","parent":0,"count":2,"filter":"raw"},{"term_id":55,"name":"Machine Learning","slug":"machine-learning","term_group":0,"term_taxonomy_id":55,"taxonomy":"post_tag","description":"","parent":0,"count":15,"filter":"raw"}],"_links":{"self":[{"href":"https:\/\/serengetitech.com\/de\/wp-json\/wp\/v2\/posts\/6187","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/serengetitech.com\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serengetitech.com\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serengetitech.com\/de\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/serengetitech.com\/de\/wp-json\/wp\/v2\/comments?post=6187"}],"version-history":[{"count":0,"href":"https:\/\/serengetitech.com\/de\/wp-json\/wp\/v2\/posts\/6187\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/serengetitech.com\/de\/wp-json\/wp\/v2\/media\/6190"}],"wp:attachment":[{"href":"https:\/\/serengetitech.com\/de\/wp-json\/wp\/v2\/media?parent=6187"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serengetitech.com\/de\/wp-json\/wp\/v2\/categories?post=6187"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serengetitech.com\/de\/wp-json\/wp\/v2\/tags?post=6187"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}