What should be the role of DPAs in enforcing the EU AI Act?

DPAs of EU Member States are well-suited to overseeing high-risk AI systems, and most of them have experience of enforcing data protection rules in cases concerning ADM. By Joanna Mazur of University of Warsaw.

The importance of the interplay between data protection and artificial intelligence (AI) regulation is evident: AI systems are often trained using datasets that include personal data, and their use involves processing personal data. Furthermore, their functions are similar to those of other digital systems, particularly with regard to automated decision-making (ADM).

The research(1) on which this report is based focused on analysing this issue from the perspective of enforcement. While recognising the importance of substantive norms concerning data processing for AI use, we posed research questions regarding the involvement of the authorities responsible for enforcing data protection law – the data protection authorities (DPAs) – in the AI Act’s enforcement model.(2) Our study – and consequently the following report – addresses three research questions. Firstly, we examine the regulatory framework governing the involvement of DPAs in the enforcement model under the AI Act. Secondly, we provide empirical insight into the activity level of the DPAs with regard to AI. Thirdly, we propose solutions concerning the DPAs’ involvement in enforcing the AI Act, inspired by our study.(3)

Continue Reading

International Report subscribers, please login to access the full article

LOGIN

If you wish to subscribe, please see our subscription information.

Subscribe