Ailance Alt TM Logo

GDPR

« Back to Glossary Index

GDPR (General Data Protection Regulation)

Definition

The General Data Protection Regulation (GDPR) is a European law that has been directly applicable in all member states since May 25, 2018. Its aim is to protect the fundamental rights of natural persons when handling personal data and at the same time to enable the free movement of data within the Union. It defines comprehensive requirements for lawfulness, Transparency, Earmarking, data economy, accuracy, storage limitation, Integrity, Confidentiality and accountability. The regulation affects all organizations - including those outside the EU - that process the data of EU citizens. For AI governance, the GDPR of central importance, as it provides the legal framework within which AI systems personal data may use. Violations may result in substantial fines.

Basic principles

  • Legality, fairness, Transparency: Data may only be processed on a legitimate basis, and Affected parties need to know how their data is being used.
  • Earmarking and minimization: Only data that is necessary for a specific purpose may be collected, and that purpose may not be changed retroactively.
  • Correctness and memory limitation: Data must be accurate and will be stored only as long as necessary.
  • Integrity and Confidentiality: They are Technical and organizational measures to protect data from unauthorized access.
  • Accountability: Responsible persons must be able to demonstrate that they adhere to these principles.

Practical example

An online store needs a customer's address in order to deliver an order. This Processing is necessary for the performance of the contract and is therefore permissible. If the store wishes to use the e-mail address later for advertising messages, the GDPR a clear Consent. A double opt-in procedure ensures that only registered recipients are contacted.

Implications for AI

  • AI systems that personal data ...must have a legal basis and the Rights of data subjects true.
  • Privacy by Design and Privacy by Default apply during the development and use of AI applications.
  • If the risk is high, a Data Protection Impact Assessment (DPIA) must be conducted and documented.

Steps towards compliance

  • Data inventory and Legal basis: Record all data processing activities and document the purposes and legal basis.
  • Transparent communication: Update data protection notices and enable the Revocation of consents.
  • Rights of data subjects implement: Create processes for information, Correction, Deletion and data portability.
  • Security: Implement technical measures such as Encryption, access restrictions, and regular updates.
  • Continuous monitoring: Conduct regular reviews, document processes, and update measures.
« Back to Glossary Index
administrator