Artificial Intelligence and LGPD: Reflections on AI Subsidy Collection

Estimated reading time: 2 minutes

Summary

The National Data Protection Authority's (ANPD) public consultation on Artificial Intelligence (AI) and Personal Data Protection aims to gather contributions from different segments of society, including experts, for the development of specific regulations. With my theoretical and practical background in privacy and data protection programs, and a strong interest in AI since my master's and doctoral academic research, I felt personally compelled to participate. Therefore, I began reading the document, intending to learn and participate in the vast array of areas these intersections offer. 

Well, I came across question 13, from block 4, relating to good practices and governance, which is, "How can privacy governance programs be used as a mechanism to promote compliance in the development and use of AI systems with the LGPD (Brazilian General Data Protection Law)? What requirements, specifically related to the development and use of AI systems, should be observed in these cases?" And from this point my honest reflections begin.

It's fair to say that discussions on this topic have been conducted with a timid technological approach. And this point draws my attention, since it highlights the gap between the proposed regulation and the development of systems, and on paper, anything goes. We are witnessing the chicken and the egg hatching simultaneously.

I have a habit of informally talking to an expert or someone involved with the topic at hand. This time, I was told that a certain scope planned for AI application involved "a lot of sensitive data." Unsurprisingly, there wasn't a single item from the LGPD's (Brazilian General Data Protection Law) exhaustive list, nor a single set of data elements that, when combined, would have discriminatory capacity in that context.

I have experienced privacy and security by design firsthand, and questionable situations arose. I have also had the opportunity to experience the opposite, where the principles didn't align. And even when they didn't exist at all. I am neither a lawyer nor an information technology professional, and there is no doubt that a privacy and data protection program has much to contribute precisely because of its interdisciplinary perspective.

It's important to remember that there was a time when business matters were departmentalized. Not anymore. Beyond physically integrated spaces, process risks are evaluated from the different perspectives that underpin the business in which they are embedded. It's inconceivable today to hear statements from IT professionals or similar fields that disregard issues of privacy, image, and other factors.

Regardless of the organization's size or complexity, when it comes to topics that are rapidly developing and impacting the business and its initiatives, alignment between expectations, technical feasibility, and regulatory compliance is essential: gathering functional, non-functional, and information security requirements, ensuring compliance with the LGPD (Brazilian General Data Protection Law), assessing compliance, and analyzing risks to both data subjects and the business are crucial to bringing the AI ​​project to reality.

The specific regulations are under development, but there are closely related rules that guide, support, and impact not only artificial intelligence projects, but also analytics, the Internet of Things, and so on…

About the Author

Meet the author of this article.

Want to see how Privacy Tools can help your company in practice?

Request a personalized demonstration and see how our solutions adapt to your needs.

Related articles section

Read also