SlideShare a Scribd company logo
GENERATIVE AI AND COMPLIANCE
WITH DATA PROTECTION AND
PRIVACY LAWS: CURRENT
INTERNATIONAL TRENDS & FUTURE
CHALLENGES
Steve Wood, PrivacyX Consulting
Asia Privacy Bridge 12/13 October 2023
10/ 15/2023 St ev e W ood A PB Conf er ence 2023 1
GENERATIVE AI AND FOUNDATION MODELS:
HOW THEY CAN USE PERSONAL DATA
Generative
AI
developers
Generative
AI
deployers
Training data sources (from internet &
licenced data
Includes publicly available personal data
Individual
users
Outputs: text,
code, video,
images (includes
personal data)
Queries
(includes
personal
data)
Inputs into
foundation
model
Learns from
queries
Enterprise Contract
Learns from
queries
Additional training data sources from deployers’
systems
Includes personal data
Inputs into
adapted
model
Outputs: text,
code, video,
images (includes
personal data)
GENERATIVE AI: DATA PROTECTION RISKS
AND CHALLENGES
• Explaining training data
inputs
• Explaining learning from
queries
• Explaining implications of
Generative AI outputs,
including automated
decisions
Transparency
• Controller & processor
roles
• Liability
• Data Governance
• Data Protection by Design
• Impact assessments
Accountabilty
• Right of access
• Right of correction or
deletion
• How do the rights interact
with data in foundation
models?
• Objection to automated
decisions
Data Rights
• Legitimate interests
• Necessity and proportionate
• Consent
• Contract
Lawful basis
• Consent for child users
• Transparency and
awareness
• Impact of outputs
Children
• Bias risk
• Discrimination risk
• Dataset fairness
• Design fairness
• Outcome fairness
• Implementation fairness
Fairness
• Accuracy - hallucinated
output, deepfakes
• Data minimisation – scale of
training data
• Purpose limitation – re-use
of personal data in models
DP principles
• Personal data leakage
• Identification risks
• Model inversion, data
poisoning, prompt injection
• Automation of cyber attacks
Security
MEASURES TAKEN BY
THE GENERATIVE AI
INDUSTRY TO COMPLY
WITH DATA PROTECTION
LAW
1. Rejection or removal of personal data from
training data before model is developed
2. Train models to reject queries for private or
sensitive information about people
3. Allowing website operators can specifically
disallow crawlers or block the crawler’s IP
address
4. Not training and learning from enterprise
deployments of their foundation model and allow
the deployment to control data retention
5. Opt-out for use of chat history data for individual
users
6. Improved privacy notices and information about
data training and classification process
7. New forms and procedures for data rights -
including access and objection
8. Revised contracts and data protection
agreements between developers and deployers
9. Guidance and tools to support safe deployments
10/ 15/2023 St ev e W ood A PB Conf er ence 2023 4
ACTION TAKEN BY DATA PROTECTION
AUTHORITIES
Enforcement orders and fines
• Italy Garante – prohibitionto OpenAI, lifted after one month
• South Korea PIPC – administrative fine of 3.6 million KRW against OpenAI for failure to notify a data breachin relationto its
payment procedure and issued a list of instances of non-compliance
• JapanPIPC - warning issued to OpenAI
Investigations on going into OpenAI
• Canada – Federal OPC, British Columbia, Quebec, and Alberta
• US Federal Trade Commission
• Brazil ANPD
Co-ordinated actions
• European Data ProtectionBoard and Ibero-AmericanNetwork of DPAs
Guidance
• New Zealand PC, UK ICO, Spain AEPD, France CNIL
St ev e W ood A PB Conf er ence 2023
ACTION TAKEN BY
DATA PROTECTION
AUTHORITIES –
AREAS OF NON-
COMPLIANCE
10/ 15/2023 6
Data Protection
by Design
Transparency
Children
Use of
sensitive data
Purpose
limitation,
accuracy &
minimisation
Lawfulness
Consent
Legitimate
Interest
Rights
St ev e W ood A PB Conf er ence 2023
G7 DATA PROTECTION AUTHORITIES
Joint statement on generative AI June 2023
Key areas of concern:
 Legal authority for the processing of personal information
 Risks to children
 Security safeguards
 Mitigation and monitoring measures of generated output
 Transparency measures to promote openness and explainability
 Production of technical documentation across the development lifecycle to assess the compliance
 Technical and organizational measures to ensure individuals can exercise their rights
 Accountabilitymeasures to ensure appropriate levels of responsibility among actors in the AI supplychain
 Limiting collection of personal data to only that which is necessary to fulfil the specified task.
St ev e W ood A PB Conf er ence 2023
WHAT NEXT FOR
GENERATIVE AI
AND DATA
PROTECTION ?
 More detailed DP guidance and regulatory actions
 DP investigations across the AI supply chain, not just
deployers
 DP investigations into specific use cases of generative AI
e.g. in recruitment, banking
 Growth of DP regulatory sandboxes to provide advice on
data protection by design
 Joined up investigations between DP regulators and
other regulators (e.g. competition, financial services)
 Policy makers consider places that DP cannot regulate
and how the gaps should be filled
 Role of the EU AI Act in regulating generative AI (under
negotiation in 2023). Some data protection regulators
may take on AI Act functions when it becomes law
10/ 15/2023 8
St ev e W ood A PB Conf er ence 2023
THANK YOU
Email: steve@privacxconsulting.co.uk
Monthly newsletter: https://privacyx.substack.com
10/ 15/2023 St ev e W ood A PB Conf er ence 2023 9

More Related Content

PDF
Metabolisme protein, karbohidrat, lipid, vitamin dan mineral
Edihard'x Rider
 
PDF
شهود يهوه وهرطقاتهم كتاب لقداسة البابا شنودة الثالث
Ibrahimia Church Ftriends
 
PDF
Data Protection Predictions for 2023.pdf
DarylBallesteros3
 
PDF
AI and Data Privacy in 2025: Global Trends
InData Labs
 
PPTX
Compliance in AI: Policies and Best Practices
Vbout.com
 
PDF
Protecting Data Privacy with AI: Strategies and Solutions
Cognith
 
PDF
Antonio kung impact of ai on privacy sept 10
Privacy Data Protection for Engineering
 
PPTX
Pronti per la legge sulla data protection GDPR? No Panic! - Domenico Maracci,...
Codemotion
 
Metabolisme protein, karbohidrat, lipid, vitamin dan mineral
Edihard'x Rider
 
شهود يهوه وهرطقاتهم كتاب لقداسة البابا شنودة الثالث
Ibrahimia Church Ftriends
 
Data Protection Predictions for 2023.pdf
DarylBallesteros3
 
AI and Data Privacy in 2025: Global Trends
InData Labs
 
Compliance in AI: Policies and Best Practices
Vbout.com
 
Protecting Data Privacy with AI: Strategies and Solutions
Cognith
 
Antonio kung impact of ai on privacy sept 10
Privacy Data Protection for Engineering
 
Pronti per la legge sulla data protection GDPR? No Panic! - Domenico Maracci,...
Codemotion
 

Similar to Steve Wood Generative AI and Data Protection Asia Privacy Bridge October 2023 TO SEND.pdf.pdf (20)

PDF
TrustArc Webinar - Unlocking AI Potential: Leveraging PIA Processes for Compr...
TrustArc
 
PDF
PDT 88 - 4 million seed - Seed - Protecto.pdf
HajeJanKamps
 
PPTX
Data protection with respect to artificial intellignece
anandbba2060
 
PDF
Balancing Data Protection and Artificial Intelligence
Giovanni Maria Riccio
 
PDF
Legal and privacy implications of IoT
Andres Guadamuz
 
PPTX
Privacy issues in data analytics
shekharkanodia
 
PDF
10 Key Challenges for AI within the EU Data Protection Framework.pdf
Priyanka Aash
 
PDF
Jowanna Conboye - Stephens Scown
Agile PR
 
PDF
Toreon adding privacy by design in secure application development oss18 v20...
Sebastien Deleersnyder
 
PPTX
Putting data science into perspective
Sravan Ankaraju
 
PPTX
Pdp4 e privacy engineering toolkit ipen 2019
Privacy Data Protection for Engineering
 
PPTX
My presentation- Ala about privacy and GDPR
zayadeen2003
 
PDF
HARNESSING AI FOR DATA PRIVACY THROUGH A MULTIDIMENSIONAL FRAMEWORK
ijcseit
 
PDF
HARNESSING AI FOR DATA PRIVACY THROUGH A MULTIDIMENSIONAL FRAMEWORK
ijcseit
 
PDF
Harnessing AI for Data Privacy through a Multidimensional Framework
ijcseit
 
PDF
Harnessing AI for Data Privacy through a Multidimensional Framework
ijcseit
 
PDF
AI Roles and Risk for election year 2024
Aurélie Pols
 
PPTX
GDPR and IoT: What do you need to know?
MicheleNati
 
PDF
Dai Davies - GDPR Presentation
Sagittarius
 
TrustArc Webinar - Unlocking AI Potential: Leveraging PIA Processes for Compr...
TrustArc
 
PDT 88 - 4 million seed - Seed - Protecto.pdf
HajeJanKamps
 
Data protection with respect to artificial intellignece
anandbba2060
 
Balancing Data Protection and Artificial Intelligence
Giovanni Maria Riccio
 
Legal and privacy implications of IoT
Andres Guadamuz
 
Privacy issues in data analytics
shekharkanodia
 
10 Key Challenges for AI within the EU Data Protection Framework.pdf
Priyanka Aash
 
Jowanna Conboye - Stephens Scown
Agile PR
 
Toreon adding privacy by design in secure application development oss18 v20...
Sebastien Deleersnyder
 
Putting data science into perspective
Sravan Ankaraju
 
Pdp4 e privacy engineering toolkit ipen 2019
Privacy Data Protection for Engineering
 
My presentation- Ala about privacy and GDPR
zayadeen2003
 
HARNESSING AI FOR DATA PRIVACY THROUGH A MULTIDIMENSIONAL FRAMEWORK
ijcseit
 
HARNESSING AI FOR DATA PRIVACY THROUGH A MULTIDIMENSIONAL FRAMEWORK
ijcseit
 
Harnessing AI for Data Privacy through a Multidimensional Framework
ijcseit
 
Harnessing AI for Data Privacy through a Multidimensional Framework
ijcseit
 
AI Roles and Risk for election year 2024
Aurélie Pols
 
GDPR and IoT: What do you need to know?
MicheleNati
 
Dai Davies - GDPR Presentation
Sagittarius
 
Ad

Recently uploaded (20)

PDF
The Future of Mobile Is Context-Aware—Are You Ready?
iProgrammer Solutions Private Limited
 
PDF
How Open Source Changed My Career by abdelrahman ismail
a0m0rajab1
 
PDF
Oracle AI Vector Search- Getting Started and what's new in 2025- AIOUG Yatra ...
Sandesh Rao
 
PDF
MASTERDECK GRAPHSUMMIT SYDNEY (Public).pdf
Neo4j
 
PDF
NewMind AI Weekly Chronicles - July'25 - Week IV
NewMind AI
 
PDF
The Evolution of KM Roles (Presented at Knowledge Summit Dublin 2025)
Enterprise Knowledge
 
PDF
Economic Impact of Data Centres to the Malaysian Economy
flintglobalapac
 
PDF
Research-Fundamentals-and-Topic-Development.pdf
ayesha butalia
 
PDF
Trying to figure out MCP by actually building an app from scratch with open s...
Julien SIMON
 
PDF
Automating ArcGIS Content Discovery with FME: A Real World Use Case
Safe Software
 
PDF
A Strategic Analysis of the MVNO Wave in Emerging Markets.pdf
IPLOOK Networks
 
PDF
The Future of Artificial Intelligence (AI)
Mukul
 
PDF
Cloud-Migration-Best-Practices-A-Practical-Guide-to-AWS-Azure-and-Google-Clou...
Artjoker Software Development Company
 
PPTX
AI in Daily Life: How Artificial Intelligence Helps Us Every Day
vanshrpatil7
 
PDF
AI Unleashed - Shaping the Future -Starting Today - AIOUG Yatra 2025 - For Co...
Sandesh Rao
 
PDF
Software Development Methodologies in 2025
KodekX
 
PDF
How-Cloud-Computing-Impacts-Businesses-in-2025-and-Beyond.pdf
Artjoker Software Development Company
 
PDF
Brief History of Internet - Early Days of Internet
sutharharshit158
 
PDF
Security features in Dell, HP, and Lenovo PC systems: A research-based compar...
Principled Technologies
 
PDF
Presentation about Hardware and Software in Computer
snehamodhawadiya
 
The Future of Mobile Is Context-Aware—Are You Ready?
iProgrammer Solutions Private Limited
 
How Open Source Changed My Career by abdelrahman ismail
a0m0rajab1
 
Oracle AI Vector Search- Getting Started and what's new in 2025- AIOUG Yatra ...
Sandesh Rao
 
MASTERDECK GRAPHSUMMIT SYDNEY (Public).pdf
Neo4j
 
NewMind AI Weekly Chronicles - July'25 - Week IV
NewMind AI
 
The Evolution of KM Roles (Presented at Knowledge Summit Dublin 2025)
Enterprise Knowledge
 
Economic Impact of Data Centres to the Malaysian Economy
flintglobalapac
 
Research-Fundamentals-and-Topic-Development.pdf
ayesha butalia
 
Trying to figure out MCP by actually building an app from scratch with open s...
Julien SIMON
 
Automating ArcGIS Content Discovery with FME: A Real World Use Case
Safe Software
 
A Strategic Analysis of the MVNO Wave in Emerging Markets.pdf
IPLOOK Networks
 
The Future of Artificial Intelligence (AI)
Mukul
 
Cloud-Migration-Best-Practices-A-Practical-Guide-to-AWS-Azure-and-Google-Clou...
Artjoker Software Development Company
 
AI in Daily Life: How Artificial Intelligence Helps Us Every Day
vanshrpatil7
 
AI Unleashed - Shaping the Future -Starting Today - AIOUG Yatra 2025 - For Co...
Sandesh Rao
 
Software Development Methodologies in 2025
KodekX
 
How-Cloud-Computing-Impacts-Businesses-in-2025-and-Beyond.pdf
Artjoker Software Development Company
 
Brief History of Internet - Early Days of Internet
sutharharshit158
 
Security features in Dell, HP, and Lenovo PC systems: A research-based compar...
Principled Technologies
 
Presentation about Hardware and Software in Computer
snehamodhawadiya
 
Ad

Steve Wood Generative AI and Data Protection Asia Privacy Bridge October 2023 TO SEND.pdf.pdf

  • 1. GENERATIVE AI AND COMPLIANCE WITH DATA PROTECTION AND PRIVACY LAWS: CURRENT INTERNATIONAL TRENDS & FUTURE CHALLENGES Steve Wood, PrivacyX Consulting Asia Privacy Bridge 12/13 October 2023 10/ 15/2023 St ev e W ood A PB Conf er ence 2023 1
  • 2. GENERATIVE AI AND FOUNDATION MODELS: HOW THEY CAN USE PERSONAL DATA Generative AI developers Generative AI deployers Training data sources (from internet & licenced data Includes publicly available personal data Individual users Outputs: text, code, video, images (includes personal data) Queries (includes personal data) Inputs into foundation model Learns from queries Enterprise Contract Learns from queries Additional training data sources from deployers’ systems Includes personal data Inputs into adapted model Outputs: text, code, video, images (includes personal data)
  • 3. GENERATIVE AI: DATA PROTECTION RISKS AND CHALLENGES • Explaining training data inputs • Explaining learning from queries • Explaining implications of Generative AI outputs, including automated decisions Transparency • Controller & processor roles • Liability • Data Governance • Data Protection by Design • Impact assessments Accountabilty • Right of access • Right of correction or deletion • How do the rights interact with data in foundation models? • Objection to automated decisions Data Rights • Legitimate interests • Necessity and proportionate • Consent • Contract Lawful basis • Consent for child users • Transparency and awareness • Impact of outputs Children • Bias risk • Discrimination risk • Dataset fairness • Design fairness • Outcome fairness • Implementation fairness Fairness • Accuracy - hallucinated output, deepfakes • Data minimisation – scale of training data • Purpose limitation – re-use of personal data in models DP principles • Personal data leakage • Identification risks • Model inversion, data poisoning, prompt injection • Automation of cyber attacks Security
  • 4. MEASURES TAKEN BY THE GENERATIVE AI INDUSTRY TO COMPLY WITH DATA PROTECTION LAW 1. Rejection or removal of personal data from training data before model is developed 2. Train models to reject queries for private or sensitive information about people 3. Allowing website operators can specifically disallow crawlers or block the crawler’s IP address 4. Not training and learning from enterprise deployments of their foundation model and allow the deployment to control data retention 5. Opt-out for use of chat history data for individual users 6. Improved privacy notices and information about data training and classification process 7. New forms and procedures for data rights - including access and objection 8. Revised contracts and data protection agreements between developers and deployers 9. Guidance and tools to support safe deployments 10/ 15/2023 St ev e W ood A PB Conf er ence 2023 4
  • 5. ACTION TAKEN BY DATA PROTECTION AUTHORITIES Enforcement orders and fines • Italy Garante – prohibitionto OpenAI, lifted after one month • South Korea PIPC – administrative fine of 3.6 million KRW against OpenAI for failure to notify a data breachin relationto its payment procedure and issued a list of instances of non-compliance • JapanPIPC - warning issued to OpenAI Investigations on going into OpenAI • Canada – Federal OPC, British Columbia, Quebec, and Alberta • US Federal Trade Commission • Brazil ANPD Co-ordinated actions • European Data ProtectionBoard and Ibero-AmericanNetwork of DPAs Guidance • New Zealand PC, UK ICO, Spain AEPD, France CNIL St ev e W ood A PB Conf er ence 2023
  • 6. ACTION TAKEN BY DATA PROTECTION AUTHORITIES – AREAS OF NON- COMPLIANCE 10/ 15/2023 6 Data Protection by Design Transparency Children Use of sensitive data Purpose limitation, accuracy & minimisation Lawfulness Consent Legitimate Interest Rights St ev e W ood A PB Conf er ence 2023
  • 7. G7 DATA PROTECTION AUTHORITIES Joint statement on generative AI June 2023 Key areas of concern:  Legal authority for the processing of personal information  Risks to children  Security safeguards  Mitigation and monitoring measures of generated output  Transparency measures to promote openness and explainability  Production of technical documentation across the development lifecycle to assess the compliance  Technical and organizational measures to ensure individuals can exercise their rights  Accountabilitymeasures to ensure appropriate levels of responsibility among actors in the AI supplychain  Limiting collection of personal data to only that which is necessary to fulfil the specified task. St ev e W ood A PB Conf er ence 2023
  • 8. WHAT NEXT FOR GENERATIVE AI AND DATA PROTECTION ?  More detailed DP guidance and regulatory actions  DP investigations across the AI supply chain, not just deployers  DP investigations into specific use cases of generative AI e.g. in recruitment, banking  Growth of DP regulatory sandboxes to provide advice on data protection by design  Joined up investigations between DP regulators and other regulators (e.g. competition, financial services)  Policy makers consider places that DP cannot regulate and how the gaps should be filled  Role of the EU AI Act in regulating generative AI (under negotiation in 2023). Some data protection regulators may take on AI Act functions when it becomes law 10/ 15/2023 8 St ev e W ood A PB Conf er ence 2023
  • 9. THANK YOU Email: [email protected] Monthly newsletter: https://privacyx.substack.com 10/ 15/2023 St ev e W ood A PB Conf er ence 2023 9