ICO launches new AI and data protection guidance
The Information Commissioner’s Office (ICO) has launched new guidance on how to ensure data protection compliance when deploying artificial intelligence (AI).
Following an open consultation earlier this year, which techUK responded to, the ICO has released new guidance on AI and data protection. This is the culmination of two years of research and part of the ICO’s commitment to enable good data protection practice in AI.
The guidance is intended to “mitigate the risks specifically arising from a data protection perspective, explaining how data protection principles apply to AI projects without losing sight of the benefits such projects can deliver”. The guidance includes recommendations on best practice and technical measures that organisations can use to mitigate risks but is not intended as a guide to the ethical or design principles of the use of AI.
This guidance is primarily aimed at two audiences, those with a compliance focus (including the ICO's own auditors) and technology specialists. We believe from the guidance published that a “toolkit designed to provide further practical support to organisations auditing the compliance of their own AI systems” is also forthcoming.
It is worth noting that this guidance is not a statutory code. There is no penalty if you fail to adopt good practice recommendations, as long as you find another way to comply with the law. The ICO have used the terms ‘must’ and ‘should’ to mark the distinction between compliance with data protection law and general good practice.
The structure of guidance relates to key data protection principles- accountability and governance, fairness and transparency, data minimisation and security and individual rights.
The guidance states that when it comes to trade-offs, the “right balance depends on the specific sectoral and social context you operate in, and the impact the processing may have on individuals”. Significant emphasis is placed on the importance of Data Protection Impact Assessments (DPIA’s) for AI systems using personal data.
The guidance also points to the need to take care to identify and understand the relationship between the data controller/data processor. The guidance states that Government will explore this issue in more detail when they come to reviewing the Cloud Computing Guidance in 2021.
The ICO has said that it will continue to adapt the guidelines to keep pace with the “fast moving innovation and evolution” of AI. The ICO would like to continue to consult with those using the guidance to understand how it works in practice and are open to ideas on the tools they could create to support implementation of the guidance. To provide feedback, please provide your details at the bottom of this page here.
Finally, if you’d like to discuss any aspect of this guidance or better understand what it means for your organisation, please get in touch.
Latest News from
Defence and Security SME Forum Survey Results24/09/2021 16:25:00
Over the summer, techUK’s Defence and Security SME Forum asked the SME community within techUK's membership to take part in a survey examining engagement with the UK Ministry of Defence (MOD).
UK National AI Strategy24/09/2021 11:25:00
Summary of major announcements from the UK Government's National AI Strategy.
Inclusive Economy Partnership (IEP) and Dell Technologies launch the Digital Inclusion Impact Group23/09/2021 15:15:00
techUK is a part of a group of industry, government, and civil society leaders to tackle digital exclusion in the UK.
Tackling greenwashing: CMA published new guidance on green claims21/09/2021 14:15:00
Companies have until the New Year to address potentially misleading claims
techUK industry briefing with the Greater Manchester Combined Authority21/09/2021 12:05:00
Insights from the GMCA Digital team
MHRA announce consultation on the future regulation of medical devices20/09/2021 16:20:00
The Medicines and Healthcare products Regulatory Agency (MHRA) is inviting members of the public to provide their views on possible changes to the regulatory framework for medical devices in the UK, aiming to develop a new regime for medical devices.
Tech Industry Gold accreditation extended to training programmes to help tackle digital skills shortages20/09/2021 15:20:00
TechSkills announces FDM as first to achieve Tech Industry Gold accreditation for training programmes.
Over a third of tech firms join Race to Zero campaign20/09/2021 13:15:00
Over a third of tech firms join Race to Zero campaign