[论文解读] Using sensitive data to prevent discrimination by artificial intelligence: Does the GDPR need a new exception?
本文主张,GDPR对处理特殊类别个人数据(如种族、宗教和性取向)的严格禁令,阻碍了组织对人工智能系统进行反歧视审计的能力。为此,本文提出在GDPR中增设一项新的法律例外,允许为反歧视审计目的使用敏感数据,从而在人工智能治理中实现隐私保护与非歧视目标之间的平衡。
Organisations can use artificial intelligence to make decisions about people for a variety of reasons, for instance, to select the best candidates from many job applications. However, AI systems can have discriminatory effects when used for decision-making. To illustrate, an AI system could reject applications of people with a certain ethnicity, while the organisation did not plan such ethnicity discrimination. But in Europe, an organisation runs into a problem when it wants to assess whether its AI system accidentally discriminates based on ethnicity: the organisation may not know the applicants' ethnicity. In principle, the GDPR bans the use of certain 'special categories of data' (sometimes called 'sensitive data'), which include data on ethnicity, religion, and sexual preference. The proposal for an AI Act of the European Commission includes a provision that would enable organisations to use special categories of data for auditing their AI systems. This paper asks whether the GDPR's rules on special categories of personal data hinder the prevention of AI-driven discrimination. We argue that the GDPR does prohibit such use of special category data in many circumstances. We also map out the arguments for and against creating an exception to the GDPR's ban on using special categories of personal data, to enable preventing discrimination by AI systems. The paper discusses European law, but the paper can be relevant outside Europe too, as many policymakers in the world grapple with the tension between privacy and non-discrimination policy.
研究动机与目标
- 调查GDPR对处理特殊类别个人数据的禁止规定是否妨碍对人工智能系统进行有效的反歧视审计。
- 评估在人工智能决策中检测偏见时使用敏感数据(如种族或宗教)的法律与政策影响。
- 评估是否有必要在GDPR中增设新例外,以使组织能够主动预防人工智能驱动的歧视。
- 分析在欧盟《人工智能法案》背景下,隐私保护与非歧视之间在人工智能监管中的张力。
- 提供一个法律与政策框架,以实现人工智能审计中敏感数据的负责任使用,同时不损害数据保护原则。
提出的方法
- 对GDPR中关于特殊类别个人数据的条款及其在人工智能审计中的适用性进行比较法律分析。
- 梳理GDPR中现有的法律例外(例如明示同意、法定义务等),以评估其在反歧视审计中的适用性。
- 评估拟议的《人工智能法案》中允许为审计目的使用特殊类别数据的规定,并评估其与GDPR的兼容性。
- 分析判例法和监管指南,以识别当前法律框架在人工智能公平性评估方面的漏洞。
- 构建一项规范性法律论证,主张为GDPR增设一项新的、有针对性的例外,仅允许为检测和预防人工智能歧视而使用敏感数据。
- 评估此类例外在欧盟基本权利法下的可行性与合法性,包括数据保护和非歧视原则。
实验结果
研究问题
- RQ1GDPR当前对处理特殊类别个人数据的禁令在多大程度上阻碍了组织对人工智能系统进行反歧视审计的能力?
- RQ2GDPR中目前存在哪些法律依据可允许在人工智能反歧视审计中使用敏感数据?
- RQ3是否存在法律与政策上的正当理由,以引入一项新的GDPR例外,明确允许为审计人工智能系统而使用敏感数据?
- RQ4如何设计此类例外,以确保其范围严格限定、比例适当,并符合基本权利要求?
- RQ5此类新例外对数据保护与人工智能治理中非歧视之间的平衡会产生何种影响?
主要发现
- GDPR目前在大多数情况下禁止使用特殊类别个人数据(如种族、宗教和性取向)来审计人工智能系统。
- 现有的GDPR例外(如明示同意或法定义务)在系统性反歧视审计中不充分或不切实际。
- 拟议的《人工智能法案》中允许使用敏感数据用于审计的规定虽为进步,但除非在GDPR中增设新例外,否则仍与GDPR不兼容。
- 从法律和规范角度看,为GDPR增设一项新的、有针对性的例外是正当的,可使组织能够检测和预防由人工智能引发的歧视。
- 此类例外必须范围严格限定,须配备保护措施,并仅限于公平与非歧视审计之目的。
- 本文结论认为,若无新例外,GDPR可能无意中削弱确保人工智能系统公平与非歧视的努力。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。