5 Data and data transfers

AI systems rely on vast amounts of data, much of which includes personal and sensitive information (and which is subject to specific legal protections under data protection law in the UK, including the General Data Protection Regulation 2018). This presents significant legal and ethical challenges.

Organisations must ensure that personal data is processed lawfully, fairly, and transparently. This includes honouring principles such as purpose limitation and data minimisation. Under the Data Protection Act 2018 in the UK, organisations are required to process personal data lawfully, fairly, and transparently.

However, many GenAI models are trained on internet-scraped data without clear user consent, raising concerns about the legal basis for processing and potential violations of privacy. Furthermore, inferential capabilities of AI can generate sensitive information about individuals from seemingly harmless inputs, escalating privacy risks.

For instance, training LLMs using data scraped from the internet raises substantive concerns over non-compliance with data protection obligations. Care should be taken when using or training GenAI or LLMs given these issues.

Described image
Image generated with AI using the prompt: Generate an image of cross border data transfers.

Cross-border data transfers complicate compliance further. When data is sent to countries without adequate protections, organisations must use safeguards like Standard Contractual Clauses (SCCs). Yet these are often insufficient given global enforcement asymmetries.

Experts increasingly recommend collective governance strategies (Lynskey, 2021) – such as public registers of training datasets – to improve transparency and accountability in AI data practices.

Activity icon Reflection

Timing: Allow 10 minutes

Think about the first three risks posed by GenAI. Are any of the first three concerns addressed in your organisation’s use of GenAI? Which, if any of these require strengthening to ensure that your organisation is mitigating the risks of GenAI?

Make a note below of any potential mitigations your organisation could adopt.

To use this interactive functionality a free OU account is required. Sign in or register.
Interactive feature not available in single page view (see it in standard view).