<p>Synthetic data generation (SDG) plays an increasingly important role as a research and innovation accelerator. While SDG can enable privacy-preserving data sharing, it also raises privacy concerns compounded by uncertainty how privacy law applies to SDG and the generated data itself. Such uncertainty can hinder positive applications of SDG and put individual privacy rights at risk. This study aims to understand how SDG and synthetic data are treated under Canadian federal privacy law, identifying regulatory gaps that extend beyond the Canadian context and proposing recommendations to address them. Our analysis shows that SDG is not explicitly addressed by the statute. While SDG arguably qualifies as a use of personal information, it is unclear whether consent is required for SDG. Further Fair Information Practices with respective obligations apply to SDG just as they do to any use of personal information. The generated data itself could fall outside the law’s scope since it is more likely to qualify as non-personal than traditionally de-identified data but the concept of identifiability under the statute remains ambiguous, particularly regarding inferences. An unclear definition of identifiability represents a relevant gap in privacy law that can harm the individual directly, through the exposure of personal information, or indirectly, by hindering the adoption of SDG and other beneficial privacy-enhancing technologies. A Code of Practice, anchored in legislation, could address such privacy concerns and ensure the proper application of SDG.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

An assessment of synthetic data generation, use and disclosure under Canadian privacy regulations

  • Lisa Pilgram,
  • Anita Fineberg,
  • Elizabeth Jonker,
  • Khaled El Emam

摘要

Synthetic data generation (SDG) plays an increasingly important role as a research and innovation accelerator. While SDG can enable privacy-preserving data sharing, it also raises privacy concerns compounded by uncertainty how privacy law applies to SDG and the generated data itself. Such uncertainty can hinder positive applications of SDG and put individual privacy rights at risk. This study aims to understand how SDG and synthetic data are treated under Canadian federal privacy law, identifying regulatory gaps that extend beyond the Canadian context and proposing recommendations to address them. Our analysis shows that SDG is not explicitly addressed by the statute. While SDG arguably qualifies as a use of personal information, it is unclear whether consent is required for SDG. Further Fair Information Practices with respective obligations apply to SDG just as they do to any use of personal information. The generated data itself could fall outside the law’s scope since it is more likely to qualify as non-personal than traditionally de-identified data but the concept of identifiability under the statute remains ambiguous, particularly regarding inferences. An unclear definition of identifiability represents a relevant gap in privacy law that can harm the individual directly, through the exposure of personal information, or indirectly, by hindering the adoption of SDG and other beneficial privacy-enhancing technologies. A Code of Practice, anchored in legislation, could address such privacy concerns and ensure the proper application of SDG.