Artificial Intelligence and Data Protection: Seeking Sustainable Development
摘要
Personal data are now commonly perceived as an external manifestation of the individual’s personality. This distinctive identity also influences the GDPR, whose strength lies precisely in having provided transversal principles that regulate personal data processing, regardless of the wider scenario wherein data processing occurs. This is exactly why these principles pose challenges for artificial intelligence, which needs free, secure, robust and quality data, including personal ones, in order to be competitive in the market. Undoubtedly, since the free market requires circulation and sharing of data, even before artificial intelligence emerged, conflicts between principles were evident and demand a broader contextualisation. Understanding how to balance the free flow and broad accessibility of such data, which AI systems need in order to be trained, with the security and confidentiality criteria that must be guaranteed during personal data processing becomes a general challenge shared in the digital market. Assuming that the circulation of data is encouraged by their negotiability, a manifestation of the peculiar patrimonial character that characterises them, it is necessary to point out that the principles of lawfulness, purpose limitation and minimisation, cornerstones of data protection, are essential even in AI-driven operations. Inspired by the purpose of balancing individuals’ self-determination with demanding development needs, this paper aims to reflect on the legal “infrastructures” used by current AI systems (such as ChatGPT) to process personal data. In this context, it should also take into account the perspectives offered by current contracts for the provision of digital goods and services (referred to in Directive No. 770/2019).