29 September 2019Murat Volkan DülgerCommentary

Introduction

This work was written in Turkish. The summary on this page is a translation; the citation gives the original title in parentheses.

Artificial intelligence (AI) software and the systems that run on it, whether as software or as devices, offer new and valuable solutions for accomplishing tasks that people find difficult and for meeting various needs in fields such as smart homes, smart cities, industry, health, the armed forces and crime prevention. As with all technological developments, developments in AI technologies offer humanity great conveniences on the one hand, while on the other they bring some serious risks for fundamental rights and freedoms.

AI technologies are built on information systems processing ever more data and taking decisions by drawing meaningful conclusions from them; they therefore inevitably raise the processing of personal data and the problems connected with it. The role of AI technologies in the processing of personal data, and their position in relation to the principles and rules of data protection law, is in fact an important subject that calls for a very extensive and careful examination. Although I cannot deal with the subject in this study on the scale it requires, I will try to set out the conceptual framework and to show the dimensions of the relationship between AI technologies and data protection law.

Full text

This text is a translation of the Turkish original, prepared for this website. Numbers in square brackets are the page numbers of the original; sources in the footnotes are given as in the original. For citation, the original publication (PDF) is authoritative.

ARTIFICIAL INTELLIGENCE TECHNOLOGIES AND DATA PROTECTION LAW

Assoc. Prof. Dr. Murat Volkan Dülger*

Artificial intelligence software and the systems that run on it offer, as software or as devices, new and valuable solutions for accomplishing tasks that are demanding for human beings and for meeting a variety of needs in fields as diverse as smart homes, smart cities, industry, health care, the armed forces and crime prevention. As with all technological developments, advances in artificial intelligence technologies offer humanity great conveniences while at the same time bringing with them certain serious risks for fundamental rights and freedoms. Artificial intelligence technologies, which are built on information systems processing ever more data and taking decisions by drawing meaningful conclusions from them, inevitably raise the issue of the processing of personal data and the problems associated with it.

The role of artificial intelligence technologies in the processing of personal data and their position in relation to the principles and rules of data protection law is in fact an important subject that calls for a very comprehensive and careful examination. Although I shall not be able to address the subject in this study on the scale it requires, I shall try to determine the conceptual framework and to set out the dimensions of the relationship between artificial intelligence technologies and data protection law.

A. Concepts Relating to the Subject

Artificial intelligence and related concepts such as machine learning and the internet of things are mostly used incorrectly or interchangeably1. In order to be able to address the subject correctly in the context of the protection of personal data, I consider it useful first of all to clarify the relevant concepts.

In its most general definition, artificial intelligence technology denotes the performance by information systems of tasks which, when performed by a human being, require intelligence, such as visual perception, speech recognition, decision-making or translation between languages2. On a more technical approach, artificial intelligence denotes intelligent machines that are able to perceive their environment and to take decisions in such a way as to maximise their chance of success with regard to any given goal3. In sum, artificial intelligence technologies combine the general features of digital technologies, such as the very rapid copying and processing of data, with features that are normally peculiar to human beings, such as experience.

The strategy games, driverless vehicles, translation programmes, facial recognition systems and the statistical programmes used in commerce, health care and research which we frequently encounter in everyday life today are in fact artificial intelligence technologies “in the narrow sense”4. Artificial intelligence technologies in the true sense go far beyond the pattern recognition and prediction performed by artificial intelligence in the narrow sense; they are technologies that can learn and behave just like the cognitive behaviours and tasks which an intelligent human being would develop in an environment full of unlimited variables5. In this sense, perhaps the most important feature of artificial intelligence in the true sense is unpredictability.

The concept of machine learning is used synonymously with artificial intelligence and is in fact one of the factors that made the emergence of artificial intelligence technologies possible6. Machine learning denotes a series of methodologies and techniques that discover new information, patterns and forms and build models that can be used to make effective predictions about data7. Machine learning programmes and techniques develop and acquire experience without having been explicitly programmed in advance8. Artificial intelligence technologies are built on machine learning techniques9.

Artificial intelligence technologies are not an independent and isolated field; they interact with a number of specific developments and trends. The main factors supporting artificial intelligence technologies are the availability and accessibility of computing infrastructure on a massive scale and at low cost, the ever-increasing accessibility of large data sets from various fields, the development of increasingly sophisticated statistical and probabilistic methods, and the trend towards a growing number of fields that are driven by, or compatible with, artificial intelligence. Accordingly, another concept that is very closely related to artificial intelligence technologies, particularly in the context of data processing, is big data.

In the digital environment, data are processed at every moment on an unbelievably large scale by a very large number of users and of virtual or physical devices. Although these data may be manageable or meaningful with regard to particular processes, when they come together en masse in the form of data sets, a body of data arises that cannot be managed with traditional processing tools. Structured or unstructured data sets on this scale are called big data. Artificial intelligence technologies, however, can cope with big data of various scales, sizes and forms. For this reason artificial intelligence and big data are inseparable concepts10. The relationship between artificial intelligence technologies and big data is two-way: on the one hand, data on a large scale are needed for machine learning, which is the source of artificial intelligence; on the other hand, artificial intelligence technologies are needed in order to extract meaning from big data sets11.

One of the concepts which, together with artificial intelligence technology, indicate the direction in which technology is evolving is the Internet of Things. The Internet of Things may be defined as a system of devices which communicate with one another by means of various communication protocols and which, by connecting to one another and sharing information, have formed a smart network. Put more simply, the network formed by computing devices that communicate with one another without the human factor is called the Internet of Things. This increasingly widespread network of interconnected devices stands in an inseparable relationship with artificial intelligence. As with big data, there is a two-way relationship between the Internet of Things and artificial intelligence as well: while the Internet of Things needs artificial intelligence in order to reach its full potential, the presence of artificial intelligence in every sphere of life needs to be complemented by the Internet of Things12.

B. Artificial Intelligence and the Processing of Personal Data

The processes involved in artificial intelligence technologies entail the processing of very large quantities of data (big data). Although what is meant here is data of every kind, personal data too are inevitably processed by artificial intelligence technologies. Although not all artificial intelligence technologies require the processing of personal information, machine learning and artificial intelligence software have a very large and wide field of application, in terms of both number and value, in the processing of personal data. Profiling carried out in the context of big data and machine learning has gone far beyond manual profiling and has acquired a new qualitative and quantitative dimension13. Thanks to machine learning, the capabilities of data mining, which denotes the extraction of meaningful pieces and conclusions from big data, have increased. It has become possible to discover valuable information in very large public or commercial databases containing equipment maintenance records, loan applications, financial transactions or medical records, and to make predictions or recommendations on that basis.

Since the artificial intelligence technologies used in data mining need, depending on their structure and purposes, a great deal of data about natural persons, they collect ever more data about them. Personal data and artificial intelligence stand in a two-way relationship: on the one hand, personal data, like all other data, feed artificial intelligence technologies and serve as material for decision-making processes; on the other hand, artificial intelligence technologies generate more personal data by drawing inferences14.

The display of advertisements that are related, sometimes only very remotely related, to the words we have searched for in a search engine, which we frequently encounter in everyday life; social media applications suggesting people we may know or people who may interest us; every kind of profiling to which we are exposed on the internet; map applications suggesting the route on which traffic is most favourable; and translation applications making their results more accurate over time: these are the most widespread and most readily understandable examples of the processing of data by means of artificial intelligence.

Artificial intelligence technologies are problematic in many respects in the context of personal data protection law:

• The collection of “all personal data” or of “as much personal data as possible” in the context of the need for big data,

• The derivation of new data from data, as the existing data become the subject of further learning and analysis,

• The fact that data obtained in a particular context and/or through a particular processing activity can be processed for a wide variety of purposes that were unknown at the outset, and that, owing to the unpredictability of artificial intelligence, it is not possible to prevent the purposes of the processing from being reconfigured or the data from being processed for far too many purposes in a manner contrary to the principle of purpose limitation,

• The ever greater use of automated decision-making mechanisms.

C. Data Processing by Means of Artificial Intelligence under Personal Data Protection Law

In the data processing operations which they contain and in which they are involved, artificial intelligence technologies must respect the rights and freedoms of individuals, must protect, in the context of our subject, the right to the protection of personal data, and must comply with the law on the protection of personal data. Since artificial intelligence technologies do not (yet) have personality, the obligations and responsibilities will at this point arise for the natural or legal persons who develop, sell and use artificial intelligence technologies.

In determining the principles and rules to be observed by the developers, sellers and users of artificial intelligence in the context of data processing by artificial intelligence technologies under personal data protection law, the guidelines on the subject issued by the Consultative Committee of the Council of Europe Convention No. 108 for the Protection of Individuals with regard to Automatic Processing of Personal Data provide guidance. According to these guidelines15:

• In the development and use of artificial intelligence technologies that may have effects on individuals and society, fundamental human rights and in particular the right to the protection of personal data are to be taken as the basis. In this context, situations in which artificial intelligence is used in decision-making processes are of particular importance.

• The fundamental principles of data protection law must be observed in the development of artificial intelligence technologies that are concerned with the processing of personal data.

• Responsible investments must be made in the field of artificial intelligence, and avoiding and eliminating the risks relating to the processing of personal data must be the basic approach.

• The assessment of risk (impact assessment) in data processing must be carried out with greater care, taking into account the characteristics of artificial intelligence and big data.

• Artificial intelligence technologies must be designed with regard for the rights of data subjects (laid down in Art. 11 of Law No. 6698 on the Protection of Personal Data, KVKK) and in such a way as to enable them to exercise those rights.

• Those who develop, sell and use artificial intelligence must ensure that data subjects are adequately and accurately informed that their personal data will be processed by means of artificial intelligence and that they are able to exercise their right to object where the conditions are met.

• With regard to data processed by means of artificial intelligence, data subjects' control (mastery) over their data and over the outcomes of the process must be ensured.

• Within the scope of the right to object to automated decision-making processes, data subjects must be granted a right to object where data are processed automatically by artificial intelligence and decisions producing effects for individuals are taken.

• Those who develop, sell and use artificial intelligence must take preventive measures against possible risks in the field of the protection of personal data.

• At all stages of processing, including the collection of data, the principle of data protection by design must be observed, and in particular it must be ensured that artificial intelligence does not have biases that may amount to discrimination.

• All developers must assess the type, nature, source and quantity of the personal data to be processed, and unnecessary and excessive processing activities must be prevented. In this context synthetic data (representative data modelling real personal data) may be an effective solution.

• The risks of artificial intelligence going out of context in the processing of data and thereby processing data for purposes other than the intended one must be identified and prevented by the necessary algorithmic formulas.

• Independent advisory boards specific to the subject must be established, and opinions and recommendations must be obtained from existing boards and academic institutions.

• Participatory methods that take into account the comments of potential or existing users must be developed in risk assessment.

• Those who develop, sell and use artificial intelligence must set up an algorithm that is accountable at every stage and in every process of the processing of data by artificial intelligence and must determine to whom the responsibilities will belong (who the controller will be).

Footnotes

  1. Academic / Attorney-at-law. ↑
  2. CNIL, “Comment Permettre À L’homme De Garder La Main? Les enjeux éthiques des algorithmes et de l’intelligence artificielle”, 2017, s. 14. ↑
  3. The Turkish Language Association does not yet have a definition of the concept. The definition given has been translated from the Oxford English Dictionary. https://en.oxforddictionaries.com/definition/artificial_intelligence. ↑
  4. Stuart J. Russell/Peter Norvig, Artificial Intelligence: A Modern Approach (3. ed.), Boston, Prentice Hall, 2010, s. 15, 30. ↑
  5. Lilian Mitrou, “Data Protection, Artificial Intelligence and Cognitive Services: Is The General Data Protection Regulation (GDPR) ‘Artificial Intelligence-Proof’?”, Nisan 2019, s. 10. ↑
  6. Mitrou,s. 11. ↑
  7. Mireille Hildebrandt, “Law as Information in the Era of Data-Driven Agency”, The Modern Law Review, Vol. 79, 2016, s. 2. ↑
  8. Martjn van Otterlo, “A Machine Learning View on Profiling”, Privacy, Due Process and the Computational Turn -Philosophers of Law Meet Philosophers of Technology, Eds: M. Hildebrandt/K. de Vries Abingdon, Routledge, 2013, s. 45. ↑
  9. van Otterlo, s. 46. ↑
  10. Mitrou, s. 13. ↑
  11. CNIL, “Comment Permettre À L’homme De Garder La Main? Les enjeux éthiques des algorithmes et de l’intelligence artificielle”, 2017, s. 18. ↑
  12. Mitrou, s. 19. ↑
  13. Mitrou, s. 19. ↑
  14. Guidelines on Artificial Intelligence and Data Protection, Consultative Committee of The Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, T-PD(2019)01, Strasbourg, 25 January 2019. ↑

Download PDF (in Turkish)

Related publications