Showing posts with label rtbf. Show all posts
Showing posts with label rtbf. Show all posts

2024/04/02

Mission Impossible: The Judge’s Role in Defining the RTBF regarding AI Applications

Author: Fouad Abdelrazek (LLD Candidate)

Research Group: Law, Technology and Design Thinking

Fouad Abdelrazek

Nowadays, the economic growth and prosperity of nations are increasingly linked to the deployment and efficacy of artificial intelligence (AI). The effectiveness of AI is directly proportional to the volume and quality of data available to it. As such, the more personal data that is fed into an AI system, the greater its accuracy and efficiency.[1]

Thus, the deletion of such data could significantly impact the efficiency and effectiveness of AI models. Accordingly, it could have severe implications for the economy in the long run.[2]

On the other hand, the issue of protecting personal data is a matter of utmost importance, as it is considered a fundamental human right.[3] Hence, the regulation of technology is a crucial aspect to ensure the protection of individuals. Nevertheless, it is important to guarantee that such regulations do not become an obstacle to development but rather support it.

Achieving the balance between these two interests is a complex matter that requires careful consideration and implementation of appropriate policies and regulations.

In my opinion, it also relies on the role of judges in interpreting the text of regulations. This ensures that regulations can be effectively applied to emerging technologies while also providing a level of flexibility necessary to promote innovation and development.

This significant role clearly appears in interpreting the right to be forgotten (RTBF), especially regarding AI applications. The RTBF is one of the most powerful rights that the General Data Protection Regulation (GDPR) has given under the name of the right to erasure (Article 17). This right gives EU and EEA residents the power to control their personal data.[4]

However, the concept of the RTBF presents a significant challenge in terms of its definition and implementation in relation to AI applications. This is because the requirement for data deletion, which is a fundamental aspect of the RTBF, is not easily applicable to AI systems. Unlike humans, AI systems and applications do not “forget” data in the same way, and the data deletion process in AI contexts is far more complex.[5] As a result, various conflicts and debates have emerged concerning the interpretation of the RTBF in the context of AI, making it a topic of significant academic interest.

There is an ongoing debate about interpreting “erasing” data differently, each with varying levels of difficulty to implement. A strict interpretation would demand erasing all copies of the data and removing them from any derived or aggregated representations to the extent that it is impossible to recover the data by any known technical means. This may not be feasible with some technologies. A more nuanced and pragmatic interpretation could permit encrypted data copies to persist as long as they remain indecipherable to unauthorized parties. A gentler and even more pragmatic interpretation could permit unencrypted data copies to last as long as they are no longer publicly visible in indices, database queries, or search engine results.[6]

Here, the judges have an essential role in interpreting the definition of the RTBF and directing the organization about how it should execute the verdict. This interpretation will directly impact AI.[7]

Roughly speaking, there are two methods of interpreting a legal text: the first is textualism, and the second is purposivism. Textualism is to stick to the statute's text in interpretation, whereas purposivism (or intentionalism) considers text-external purposes and legislator intentions.[8]

In this context, can judges’ emotional bias affect their interpretation of the RTBF to either decrease or increase the deletion of personal data to improve the economy?

People might unconsciously favour evidence that aligns with their existing viewpoints while disregarding or devaluing evidence that contradicts them.[9] From a classical legal realist perspective, the judge's decision can be biased without the judge knowing.[10] Despite judges' claims that their emotions do not impact their decisions,[11] it's unlikely that emotions cease to exist when they act in court. Emotions are a significant source of intuition, and their impact on decision-making is robust and valuable.[12] One judge has expressively stated, "Judges, being flesh and blood, are subject to the same emotions and human frailties as affect other members of the species."[13]

Hence, the issue of how judges interpret the RTBF in the context of AI is a complex and multifaceted one. The judgment of the European Court of Justice’s (ECJ) Google Spain case (C‑131/12) suggests that each case of the RTBF should be interpreted in its own context (judgement addressing Question 3, para. 99). This provides judges with much interpretive leeway in determining the meaning of the RTBF in the context of every case. However, this leeway may lead to different interpretations in similar cases.

Judges have to emphasize either of the two methods of interpreting a legal text to define the RTBF. However, interpretations of these two methods will raise different challenges for implementing the RTBF regarding AI.

On the one hand, under textualism, where the judge must adhere strictly to the statute's text, the text unequivocally calls for the erasure of the individual’s personal data. This may seem to have a harmful impact on the economy. It may lead to the erasure of a massive amount of data, which AI depends on in its efficiency, which will significantly impact the economy. However, are such verdicts technically executable in the first place? In some cases, it is very difficult to ensure that the personal data is erased from the model.[14] However, naturally, such an interpretation will increase trust in the judicial system, encouraging individuals, in turn, to give their personal data to these organizations.

On the other hand, a purposive interpretation might lead to a very broad interpretation of the text, which may negatively impact the trust between individuals and the judicial system. Through the lens of purposive interpretation, the RTBF may be interpreted such that data is not necessarily physically destroyed or overwritten; rather, it is merely made inaccessible or not readily retrievable through normal means. This could imply that, in practical terms, data marked for deletion in databases may still exist in some form and is merely concealed, awaiting potential overwriting in the future.[15] This will not lead to the actual erasure of personal data. Consequently, this will make individuals more reluctant to give their personal data to these organizations, which will affect the efficiency and accuracy of AI and also negatively impact the economy.

In conclusion, implementing the RTBF in the context of AI requires a nuanced and balanced approach. Considering this challenge, it would be useful if the Court of Justice of the European Union (CJEU) established clearer guiding criteria for judges to follow when interpreting the RTBF and its implementation, aiming to reach a balance between people's interests and the economy, especially in the context of AI. Although the ECJ presented its opinion, in practice, it is still debatable whether it was right or not. From this perspective, the lack of clear criteria for the RTBF, coupled with the rising number of cases and varying circuits that handle them, will result in a significant difference in interpretations of the RTBF in similar cases.

The existence of clear criteria would ensure that judgments are unified and consistent, ensuring trust and fairness, and avoiding conflicts and negative economic impacts.



[1] Mangini, V., Tal, I., & Moldovan, A. N. (2020, August). An empirical study on the impact of GDPR and right to be forgotten  organisations and users perspective. In Proceedings of the 15th international conference on availability, reliability and security (pp. 1–9).

[2] Salami, E. (2023). Artificial Intelligence: The end of Legal Protection of Personal Data and Intellectual Property?: Research on the countering effects of data protection and IPR on the regulation of Artificial Intelligence systems.

[3] Rodotà, S. (2009). Data protection as a fundamental right. In Reinventing data protection? (pp. 77–82). Dordrecht: Springer Netherlands.

[4] Post, R. C. (2017). Data privacy and dignitary privacy: Google Spain, the right to be forgotten, and the construction of the public sphere. Duke LJ, 67, 981.

[5] Villaronga, E. F., Kieseberg, P., & Li, T. (2018). Humans forget, machines remember: Artificial intelligence and the right to be forgotten. Computer Law & Security Review, 34(2), 304–313.

[6] Sandra, I. A. The enforcement of right to be forgotten at the EU level by using search engines.

[7]Aghion, P., Jones, B. F., & Jones, C. I. (2018). Artificial intelligence and economic growth. In The economics of artificial intelligence: An agenda (pp. 237282). University of Chicago Press. It is stated on the business Bank of America site that “AI will contribute more than $15 trillion to the global economy by 2030” https://business.bofa.com/en-us/content/economic-impact-of-ai.html#

[8] Aalto-Heinilä, M. (2016). Fairness in statutory interpretation: Text, purpose or intention?. International Journal of Legal Discourse, 1(1), 193–211.

[9] Nickerson, R. S. (1998). Confirmation bias: A ubiquitous phenomenon in many guises. Review of general psychology, 2(2), 175–220.

[11] Maroney, T. A. (2011). Emotional regulation and judicial behavior. Calif. L. Rev., 99, 1485.

[12] Wistrich, A. J., & Rachlinski, J. J. (2017). Implicit bias in judicial decision making how it affects judgment and what judges can do about it. Chapter, 5, pp. 17–16

[13] Maroney, T. (2016). The emotionally intelligent judge: A new (and realistic) ideal. Revista Forumul Judecatorilor, 61.

[14] Graves, L., Nagisetty, V., & Ganesh, V. (2020). Does AI Remember? Neural Networks and the Right to be Forgotten.

[15] Villaronga, E. F., Kieseberg, P., & Li, T. (2018). Humans forget, machines remember: Artificial intelligence and the right to be forgotten. Computer Law & Security Review, 34(2), 304-313.


2022/10/11

“To use or not to use, that is the question” – Mobile applications and the right to be forgotten

Author: Fouad Abdelrazek (LLD Candidate)

Research Group: Law, Technology and Design Thinking

Fouad Abdelrazek

We are living in a rapidly digitalizing world. Due to the increase in computing power of mobile phones, and the exponential growth of smart mobile applications for various purposes,[1] people from all norms of life depend on mobile applications to assist them in daily tasks. Moreover, the easy download and installation of mobile applications and their flexibility to be used anywhere, at any time, has engaged people in their use.[2]

Albeit being generally handy, mobile applications cause a set of privacy and security concerns. Mobile applications can collect large quantities of personal information from their many sensors, including location, biometrics, and other sensitive data. This information, processed together with the records of users’ interaction with the web service, could also be used to build users’ profiles and pose risks to their fundamental rights.[3]

In a mobile application ecosystem, when data is collected about, or from, a mobile device, the personal nature of mobile device usage implies that such data has to be considered personal data in the context of the General Data Protection Regulations (GDPR).[4] Nevertheless, does that mean such data is automatically protected in practice, and there is no need to heed caution?

Our culture of convenience often leads us to think that all we need to do to delete our data from the application is to delete the application itself from the device. However, while the active elements may be uninstalled, that doesn’t always mean that the personal data we’ve uploaded using the application has been deleted. Even if a message appears to warn us that deleting the application will also delete the data, this usually only means that the data will be deleted from the device itself, but it still exists on the developer’s server.[5]

If the user decided to delete his personal data, he has to use his right to be forgotten (RTBF) which is stated in Article 17 of the GDPR. However, it is also important to note that the RTBF is not an absolute right, and it only applies in certain circumstances.[6] As a result, the mobile application user will face many obstacles regarding this right. It is important to highlight that individuals cannot have their personal data deleted when they need to use the application if the application requires the use of the individual’s personal data for its intended purpose. In other words, the user cannot use the mobile application without providing it access to the necessary personal data. Also, users cannot simply withdraw their consent to provide necessary personal data as long as they need to use this application. This is due to the fact that the application will not function unless the user accepts and gives permission to the application provider to gather their personal data.

So, in order to truly protect our data, we are left with the question, “to use, or not to use?”, and a controversial decision of whether to take it or leave it. Either you give permission to various service providers, and possibly third parties, to use your “necessary” personal data, or you do not use the application that you may require for an educational purpose, for transportation, or even as your only means of connection to friends and family in various countries.

Despite service providers receiving legitimate consent from the users and even if they are being transparent about the use of data, users are still not fully in control of their data or aware of the privacy issues they may face. And although users must be given the option to change their wishes and revoke their decision at any time [7], they usually will not if their need for using the application wins over their privacy concerns. Hence, the available privacy protection privileges will not deny the truth that the provider of the mobile application is using and processing the user’s personal data to make him able to use the application. Consequently, it is important to know whether the use of mobile applications controls us or whether we are in control of our own use of mobile applications

We will find that most of the people that are using mobile applications generally need more than one application in their routine lives. This need forces people to give consent to the mobile application provider to access and process their personal data to function, even if they have concerns or would otherwise be cautious to do so. Accordingly, the need to use mobile applications is the controller of this relationship. Thus, not necessarily the technology itself, but the need for the technology that controls our usage and provision of data.

Accordingly, this will impact the effectiveness of implementing the RTBF on the used mobile applications. Since the erasure of identified, or identifiable, personal data from the mobile application could lead to the inability to use this application, users may no longer want to do so. This will lead to inefficiency in the usage of an important right that was given to the users, especially since it gives them the power to control their data. Not only that, but it could make the RTBF regarding mobile applications out of service.

As a result, it is important to raise awareness of how precious our personal data is and how to protect it to push toward the development of more transparent mobile applications. Such applications should allow for their usage with minimal data collection, provide more precise and simplified information on the usage of personal data, and allow opting out of unnecessary data collection, thus giving more control to individuals and their rights.  

References:

[1] Islam, R., Islam, R., & Mazumder, T. (2010). Mobile application and its global impact. International Journal of Engineering & Technology (IJEST), 10(6), 72-78.

[2] Nathan, S. S., Hussain, A., & Hashim, N. L. (2016). Studies on deaf mobile application: Need for functionalities and requirements. Journal of Telecommunication, Electronic and Computer Engineering, 8(8), 47-50.

[3] European Data Protection Supervisor (2016) “Guidelines on the protection of personal data processed by mobile applications provided by European Union institutions”.

[4] Castelluccia, C., Guerses, S., Hansen, M., Hoepman, J. H., van Hoboken, J., & Vieira, B. (2017). Privacy and data protection in mobile applications: A study on the app development ecosystem and the technical implementation of GDPR.

[5] Peters, B. What Happens to Your Personal Data after Deleting an App. https://techspective.net/2020/12/01/what-happens-to-your-personal-data-after-deleting-an-app/

[6] Information Commissioner’s Office (2018). Guide to the general data protection regulation (GDPR). Right to erasure. Retrieved from: https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/

[7] European Data Protection Supervisor (2016) “Guidelines on the protection of personal data processed by mobile applications provided by European Union institutions”.