Data Security in the Age of Artificial Intelligence

Estimated reading time: 2 minutes

Summary

Brazil's General Data Protection Law (LGPD) and the European Union's General Data Protection Regulation (GDPR) are important milestones in data protection and privacy in a world where information is extremely valuable. However, how do these regulations relate to the increasingly frequent use of generative Artificial Intelligence?

In Brazil

In Brazil, several proposals for the regulation of artificial intelligence have already been presented to the National Congress, the most recent being Bill 2338. The bill has received amendments to the substitute text presented by the ANPD (National Data Protection Authority). Some of these changes include alterations to the definitions of terms, the approach to data subject rights, issues related to biometric systems, the classification of high-risk systems, and the regulation and governance of artificial intelligence.

Other suggestions include changes to the regulatory and standardization process, administrative sanctions, rules for implementing regulatory sandboxes, and the deadline for designating the competent authority. One of the main issues discussed in Brazil is how artificial intelligence should maintain transparency for personal data owners. This is one of the most important points of the LGPD (Brazilian General Data Protection Law) and requires close attention, since artificial intelligence generally collects information from its users.

ChatGPT and the Italian Data Protection Authority

Recently, OpenAI, the company behind ChatGPT, faced problems with the Italian data protection authority. The main reason was a suspected privacy violation, following a months-long investigation. The service was even temporarily banned in the country in 2023, returning after 29 days. Some of the requirements for its return included the disclosure of data processing practices and the implementation of age verification measures. 

Despite OpenAI's swift response, its relationship with the rest of the European Union remains challenging. One of the latest setbacks involved an Austrian data protection NGO, which accused OpenAI of failing to guarantee the accuracy of personal data provided by ChatGPT. Noyb stated that this action violates the GDPR, as Article 5 establishes that personal data must be "accurate and, where necessary, kept up to date".

Today, the European Union is working to regulate AI through the AI ​​Act. This recently approved law is a significant milestone, being one of the first to address the topic of artificial intelligence directly. In addition to establishing parameters on what types of AI are permitted, the law provides for sanctions in case of specific violations.

The Future of Data Protection

The growing presence of artificial intelligence in our daily lives brings significant challenges to data protection and privacy. The interaction between new technologies and regulations such as the LGPD (Brazilian General Data Protection Law) and the GDPR (General Data Protection Regulation) is crucial to ensure that technological innovation does not violate laws and individual rights.

It is essential that laws keep pace with technology and strike a balance between data protection and the potential of artificial intelligence. Ensuring an ethical and secure future will only come with transparency and accountability.

About the Author

Meet the author of this article.

Want to see how Privacy Tools can help your company in practice?

Request a personalized demonstration and see how our solutions adapt to your needs.

Related articles section

Read also