A Decision-Making Process to Implement the 'Right to Be Forgotten' in Machine Learning

被引:0
作者
Hawkins, Katie [1 ]
Alhuwaish, Nora [1 ]
Belguith, Sana [1 ]
Vranaki, Asma [1 ]
Charlesworth, Andrew [1 ]
机构
[1] Univ Bristol, Bristol, Avon, England
来源
PRIVACY TECHNOLOGIES AND POLICY, APF 2023 | 2024年 / 13888卷
基金
英国工程与自然科学研究理事会;
关键词
Right to be Forgotten; GDPR; Erasure; Machine Learning; Machine Unlearning; Decision-Making;
D O I
10.1007/978-3-031-61089-9_2
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The unprecedented scale at which personal data is used to train machine learning (ML) models is a motivation to examine the ways in which it can be erased when implementing the GDPR's 'right to be forgotten'. The existing literature investigating this right focus on a purely technical or legal approach, lacking the collaboration required for this interdisciplinary space. Recent works has identified there is no one solution to erasure in ML and this must therefore be decided on a case-by-case basis. However, there is an absence of guidance for controllers to follow when personal data must be erased in ML. In this paper we develop a novel, decision-making flow that encompasses the necessary considerations for a controller. Addressing, in particular, the interdisciplinary considerations relevant to the EU GDPR and data protection scholarship, as well as concepts from computer science and its application in industry. This results in several optimal solutions for the controller and data subject, differing with levels of erasure. To validate the proposed decision-making flow a real case study is discussed throughout the paper. The paper highlights the need for a clearer framework when personal data must be erased in ML; empowering the regulator, controller and data subject.
引用
收藏
页码:20 / 38
页数:19
相关论文
共 71 条
[1]  
AI, ensuring GDPR compliance
[2]   Machine Learning from Theory to Algorithms: An Overview [J].
Alzubi, Jafar ;
Nayyar, Anand ;
Kumar, Akshi .
SECOND NATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE (NCCI 2018), 2018, 1142
[3]  
[Anonymous], 2007, CHARTER FUNDAMENTAL
[4]  
[Anonymous], How do we ensure individual rights in our AI systems?
[5]  
[Anonymous], The right to de-listing in questions
[6]  
[Anonymous], Greek DPA imposes 20M euro fine on Clearview AI for unlawful processing of personal data
[7]  
[Anonymous], Right to erasure
[8]  
[Anonymous], Guidelines 5/2019 on the criteria of the Right to be Forgotten in the search engines cases under the GDPR (part 1), V2
[9]  
[Anonymous], 2015, Case C-398/15: Request for a preliminary ruling from the Corte suprema di cassazione (Italy) lodged on 23 July 2015-Camera di Commercio, Industria, Artigianato e Agricoltura di Lecce v Salvatore Manni
[10]  
[Anonymous], FACIAL RECOGNITION T