Goto

Collaborating Authors

 administrative fine


A Personal data Value at Risk Approach

Enriquez, Luis

arXiv.org Artificial Intelligence

What if the main data protection vulnerability is risk management? Data Protection merges three disciplines: data protection law, information security, and risk management. Nonetheless, very little research has been made on the field of data protection risk management, where subjectivity and superficiality are the dominant state of the art. Since the GDPR tells you what to do, but not how to do it, the solution for approaching GDPR compliance is still a gray zone, where the trend is using the rule of thumb. Considering that the most important goal of risk management is to reduce uncertainty in order to take informed decisions, risk management for the protection of the rights and freedoms of the data subjects cannot be disconnected from the impact materialization that data controllers and processors need to assess. This paper proposes a quantitative approach to data protection risk-based compliance from a data controllers perspective, with the aim of proposing a mindset change, where data protection impact assessments can be improved by using data protection analytics, quantitative risk analysis, and calibrating expert opinions.


AI Act: Leadings MEPs want to expand Commission's revision powers

#artificialintelligence

The European Parliament's co-rapporteurs of the AI Act have proposed expanding the European Commission's revision powers to extend the list of high-risk systems and prohibited practices at a later stage. The eighth batch of compromise amendments on the proposed Artificial Intelligence regulation was shared by leading lawmakers Dragoș Tudorache and Brando Benifei with the representatives of the other political groups last Friday (21 October). The AI Act is a flagship legislative proposal to regulate the development, deployment and use of artificial intelligence. The co-rapporteurs are currently trying to reach a common position with the other political groups, pitching several significant changes to the original wording. The most relevant amendment would significantly extend the Commission's revision powers after the legislation becomes effective.