SlideShare a Scribd company logo
On GDPR compliance, the Right to be
Forgotten and AI
Cristina Rosu, DPO XWiki SAS
by
Human mind and the paradox of
forgetting
• Ars memoriae vs. Ars oblivionalis - Cicero, Themistocles &
Umberto Eco
• The psychological memory: short term vs. long term
AI “mind”
*humans control it
1. Data input
2. The storage
3. The deletion - no forgetting paradox
What is AI?
(really long story short)
...Glimpses of the real
story, still short
Reinforcement
learning
Neural Networks
/ “Deep Learning”
backpropagation algorithm:
passing an input through
forwards the neural network,
comparing the result to the
“model” result. After, all the
nodes from output (front) to
input (back) are updated.
A right to be forgotten - definition
= The right of the individual to obtain the deletion of
personal information posted online by the data owner
himself or a third party, even if it was legally posted.
The European perspective on the Right
to be forgotten
• Directive 95/46/EC on the protection of individuals with
regard to the processing of personal data and on the free
movement of such data
• C-131/12 - Google Spain SL and Google Inc. v Agencia
Española de Protección de Datos (AEPD) and Mario Costeja
González
• Article 17 EU GDPR "Right to erasure ('right to be forgotten')"
On the Google Spain v AEPD and Mario Costeja González case at
the Court of Justice of the European Union, in 2012
• Deleting two pages of La Vanguardia, with a notice for a
real-estate auction
• The Directive 95/46/EC is directly applicable to Google Inc.
• The search engine qualifies as a “data controller”
• “...a right to address himself to a search engine service
provider in order to prevent indexing of the information
relating to him personally, published legally on third parties’
web pages...”
Some statistics on deletion for GDPR compliance
If your company receives a request based on the right to be forgotten, what is the method
you would use to delete the content?
France USA UK Germany Spain
Basic deletion 34% 28% 24% 23% 26%
Free data wiping
solution (without
proof)
21% 25% 33% 27% 35%
Secure data
erasure solution
(with proof)
46% 43% 38% 44% 38%
I don’t know 0% 4% 6% 6% 1%
Other 0% 0,4% 0% 0% 0%
By October 2016, Google received 347,533 separate
requests to remove aprox. 1.2 million websites.
58% of the requests were denied.
EU country Total removal
requests
% of URL’s
removed
% of URL’s
removed
France 247,832 48.4% 51.6%
Germany 222,319 48.2% 51.8%
U.K. 163,205 38% 62%
Spain 104,240 37.2% 62.8%
Italy 86,002 29.7% 70.3%
Austria 23,274 47,7% 52,3%
Belgium 37,472 45.7% 54.3%
Criteria for evaluating delisting requests
1. Data subject’s role in public life
2. Nature of information
• Bias toward an individual’s strong privacy interest (personal
financial information; related to an individual’s intimate and sex
life; private information about minors; private contact or
identification information etc.)
• Bias toward a public interest (related to criminal activity;
relevant to political discourse and governance; relates to public
health etc.)
3. Source
4. Time
A right to delisting vs. social forgetting
• The “boomerang” effect and the paradox of
forgetting
• Collecting links of delisted items
When a record is deleted using the SQL interface in relevant
databases, it is only marked as deleted and gets removed from the
search indexes.
Deletion in MySQL:
Viviane Reding, the
European Commission’s
vice-president (2010 -
2014)
‘‘It is clear that the
right to be
forgotten cannot
amount to a right
of the total
erasure of
history.’’
Numbers related to the information that is
collected from users
• As of the third quarter of 2017, Facebook had 2.07
billion monthly active users.
• Google announced over 2 billion monthly active
devices on Android in May 2017.
• Google Drive now has 800 million users and Google
Photos has more than 500 million monthly users in
2017.
AI has no reasoning, will, desire, ethics beside our own.
Image from "Explaining and Harnessing Adversarial Examples" by Ian J. Goodfellow,
Jonathon Shlens, Christian Szegedy
Apple’s “most advanced” face ID tech that can detect if someone is
trying to get into your phone with a probability of 1 in 1 million
Can’t tell these 2 women co-workers apart
Forgetting in algorithmic memory
“obfuscation” = to produce misleading,
false or ambiguous information parallel
to the relevant one
The right to be forgotten impacts
machine learning algorithms
• Erasure of one data
• Making data less sensitive
• Functional encryption algorithms
• Pseudonymization
• Data anonymization
Possible approaches
• Data minimization
• Interdisciplinary research addressing
innovative technological solutions and
dedicated legal norms for the AI model
Possible approaches
• Take control over your data
• Use ethical products that respect your privacy as a
user
Examples of open source projects:
- Mastodon - decentralized social network
- Matrix - encrypted end-to-end chat
- Cryptpad - zero knowledge collaborative editor
Feel free to contact me!
E-mail: cristina.rosu@xwiki.com
@cristina.r:matrix.org
@redchrision@mastodon.social
Thank you!

More Related Content

PPTX
Facebook data breach
PDF
Cambridge Analytica as a Prime Example of the Manipulation of Democratic Deci...
PPTX
Cambridge Analytica
PPTX
Facebook and cambridge analytica scandal
PDF
Mining Big Data to Predicting Future
PPTX
Data-Driven Government: Explore the Four Pillars of Value
PPTX
The mechanics of trust online practice: Avoiding lies, bullshit and fake news
PPTX
EduTECH Presentation Nick Barter
Facebook data breach
Cambridge Analytica as a Prime Example of the Manipulation of Democratic Deci...
Cambridge Analytica
Facebook and cambridge analytica scandal
Mining Big Data to Predicting Future
Data-Driven Government: Explore the Four Pillars of Value
The mechanics of trust online practice: Avoiding lies, bullshit and fake news
EduTECH Presentation Nick Barter

Similar to On GDPR compliance, the Right to be forgotten and Artificial Intelligence, OW2con'18, June 7-8, 2018, Paris (20)

PPTX
To share or not to share? machine generated data for science
PPT
16190734.ppt
PDF
Data ethics for developers
PDF
10 Key Challenges for AI within the EU Data Protection Framework.pdf
PPTX
Can ChatGPT be compatible with the GDPR? Discuss.
PPTX
S0-Stephen.pptx
PPT
Week 5: Dataveillance
PPTX
The death of data protection
PPTX
The death of data protection sans obama
PPT
Getting the social side of pervasive computing right
PDF
The advent of artificial super intelligence and its impacts
PDF
An Elementary Introduction to Artificial Intelligence, Data Science and Machi...
PPTX
The Need for Deep Learning Transparency
PDF
Cognitive Computing: Challenges and opportunities in Building an Artificial I...
PPTX
Artificial Intelligence.
PDF
The Ethics of Artificial Intelligence in Digital Ecosystems
PDF
Fontys Eric van Tol
PPTX
Future of Information Ethics.pptx
PPTX
My Privacy at Risk, is it Safe?
PDF
Odoo Experience 2018 - GDPR: How Odoo Can Help You with Complieance
To share or not to share? machine generated data for science
16190734.ppt
Data ethics for developers
10 Key Challenges for AI within the EU Data Protection Framework.pdf
Can ChatGPT be compatible with the GDPR? Discuss.
S0-Stephen.pptx
Week 5: Dataveillance
The death of data protection
The death of data protection sans obama
Getting the social side of pervasive computing right
The advent of artificial super intelligence and its impacts
An Elementary Introduction to Artificial Intelligence, Data Science and Machi...
The Need for Deep Learning Transparency
Cognitive Computing: Challenges and opportunities in Building an Artificial I...
Artificial Intelligence.
The Ethics of Artificial Intelligence in Digital Ecosystems
Fontys Eric van Tol
Future of Information Ethics.pptx
My Privacy at Risk, is it Safe?
Odoo Experience 2018 - GDPR: How Odoo Can Help You with Complieance
Ad

More from OW2 (20)

PDF
OW2 and RIOS teaming up to boost the open source impact, Nov. 2022 in Roma
 
PDF
The Open Source Good Governance Initiative presented at RIOS OS Week, Nov. 20...
 
PDF
GLPi v.10, les fonctionnalités principales et l'offre cloud
 
PDF
Centreon: superviser le Cloud et le Legacy à partir d'une même plateforme, po...
 
PDF
FusionIAM : la gestion des identités et des accés open source
 
PDF
OW2 Association Européenne aux racines grenobloises, transformer l'industrie ...
 
PDF
SFScon'20 Bringing the User into the Equation
 
PDF
Towards a sustainable solution to open source sustainability, OW2online20, Ju...
 
PDF
Advanced proactive and polymorphing cloud application adaptation with MORPHEM...
 
PDF
Open Source governance and the Eclipse Foundation, OW2online, June 2020
 
PDF
Open source contribution policies, OW2online, June 2020
 
PDF
Software development at scale, pandemic lockdown and oss ecosystems, OW2onlin...
 
PDF
Overview of the OpenChain Reference Tooling Work Group, OW2online20, June 2020
 
PDF
Open Source Compliance at Orange, OW2online, June 2020
 
PDF
Ideas, methods and tools for OSS Compliance assessment, OW2online, June 2020
 
PDF
Intelligent package management with FASTEN, OW2online, June 2020
 
PDF
DECODER, a Smarter Environment for DevOps Teams , OW2online, June 2020
 
PDF
Enabling DevOps for IoT software development, powered by Open Source, OW2onli...
 
PDF
Upcoming Challenges in Artificial Intelligence Research and Development, OW2o...
 
PDF
Cacti and Big Data at Orange France, OW2online, June 2020
 
OW2 and RIOS teaming up to boost the open source impact, Nov. 2022 in Roma
 
The Open Source Good Governance Initiative presented at RIOS OS Week, Nov. 20...
 
GLPi v.10, les fonctionnalités principales et l'offre cloud
 
Centreon: superviser le Cloud et le Legacy à partir d'une même plateforme, po...
 
FusionIAM : la gestion des identités et des accés open source
 
OW2 Association Européenne aux racines grenobloises, transformer l'industrie ...
 
SFScon'20 Bringing the User into the Equation
 
Towards a sustainable solution to open source sustainability, OW2online20, Ju...
 
Advanced proactive and polymorphing cloud application adaptation with MORPHEM...
 
Open Source governance and the Eclipse Foundation, OW2online, June 2020
 
Open source contribution policies, OW2online, June 2020
 
Software development at scale, pandemic lockdown and oss ecosystems, OW2onlin...
 
Overview of the OpenChain Reference Tooling Work Group, OW2online20, June 2020
 
Open Source Compliance at Orange, OW2online, June 2020
 
Ideas, methods and tools for OSS Compliance assessment, OW2online, June 2020
 
Intelligent package management with FASTEN, OW2online, June 2020
 
DECODER, a Smarter Environment for DevOps Teams , OW2online, June 2020
 
Enabling DevOps for IoT software development, powered by Open Source, OW2onli...
 
Upcoming Challenges in Artificial Intelligence Research and Development, OW2o...
 
Cacti and Big Data at Orange France, OW2online, June 2020
 
Ad

Recently uploaded (20)

PDF
AI And Its Effect On The Evolving IT Sector In Australia - Elevate
PDF
GamePlan Trading System Review: Professional Trader's Honest Take
PDF
[발표본] 너의 과제는 클라우드에 있어_KTDS_김동현_20250524.pdf
PDF
Modernizing your data center with Dell and AMD
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
REPORT: Heating appliances market in Poland 2024
PPTX
CroxyProxy Instagram Access id login.pptx
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PDF
CIFDAQ's Teaching Thursday: Moving Averages Made Simple
PDF
Event Presentation Google Cloud Next Extended 2025
PPTX
Cloud computing and distributed systems.
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Reimagining Insurance: Connected Data for Confident Decisions.pdf
PDF
Electronic commerce courselecture one. Pdf
PDF
Omni-Path Integration Expertise Offered by Nor-Tech
PPTX
Telecom Fraud Prevention Guide | Hyperlink InfoSystem
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
Smarter Business Operations Powered by IoT Remote Monitoring
PPTX
Big Data Technologies - Introduction.pptx
PDF
SAP855240_ALP - Defining the Global Template PUBLIC.pdf
AI And Its Effect On The Evolving IT Sector In Australia - Elevate
GamePlan Trading System Review: Professional Trader's Honest Take
[발표본] 너의 과제는 클라우드에 있어_KTDS_김동현_20250524.pdf
Modernizing your data center with Dell and AMD
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
REPORT: Heating appliances market in Poland 2024
CroxyProxy Instagram Access id login.pptx
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
CIFDAQ's Teaching Thursday: Moving Averages Made Simple
Event Presentation Google Cloud Next Extended 2025
Cloud computing and distributed systems.
“AI and Expert System Decision Support & Business Intelligence Systems”
Reimagining Insurance: Connected Data for Confident Decisions.pdf
Electronic commerce courselecture one. Pdf
Omni-Path Integration Expertise Offered by Nor-Tech
Telecom Fraud Prevention Guide | Hyperlink InfoSystem
NewMind AI Weekly Chronicles - August'25 Week I
Smarter Business Operations Powered by IoT Remote Monitoring
Big Data Technologies - Introduction.pptx
SAP855240_ALP - Defining the Global Template PUBLIC.pdf

On GDPR compliance, the Right to be forgotten and Artificial Intelligence, OW2con'18, June 7-8, 2018, Paris

  • 1. On GDPR compliance, the Right to be Forgotten and AI Cristina Rosu, DPO XWiki SAS by
  • 2. Human mind and the paradox of forgetting • Ars memoriae vs. Ars oblivionalis - Cicero, Themistocles & Umberto Eco • The psychological memory: short term vs. long term
  • 3. AI “mind” *humans control it 1. Data input 2. The storage 3. The deletion - no forgetting paradox
  • 4. What is AI? (really long story short)
  • 5. ...Glimpses of the real story, still short Reinforcement learning Neural Networks / “Deep Learning” backpropagation algorithm: passing an input through forwards the neural network, comparing the result to the “model” result. After, all the nodes from output (front) to input (back) are updated.
  • 6. A right to be forgotten - definition = The right of the individual to obtain the deletion of personal information posted online by the data owner himself or a third party, even if it was legally posted.
  • 7. The European perspective on the Right to be forgotten • Directive 95/46/EC on the protection of individuals with regard to the processing of personal data and on the free movement of such data • C-131/12 - Google Spain SL and Google Inc. v Agencia Española de Protección de Datos (AEPD) and Mario Costeja González • Article 17 EU GDPR "Right to erasure ('right to be forgotten')"
  • 8. On the Google Spain v AEPD and Mario Costeja González case at the Court of Justice of the European Union, in 2012 • Deleting two pages of La Vanguardia, with a notice for a real-estate auction • The Directive 95/46/EC is directly applicable to Google Inc. • The search engine qualifies as a “data controller” • “...a right to address himself to a search engine service provider in order to prevent indexing of the information relating to him personally, published legally on third parties’ web pages...”
  • 9. Some statistics on deletion for GDPR compliance If your company receives a request based on the right to be forgotten, what is the method you would use to delete the content? France USA UK Germany Spain Basic deletion 34% 28% 24% 23% 26% Free data wiping solution (without proof) 21% 25% 33% 27% 35% Secure data erasure solution (with proof) 46% 43% 38% 44% 38% I don’t know 0% 4% 6% 6% 1% Other 0% 0,4% 0% 0% 0%
  • 10. By October 2016, Google received 347,533 separate requests to remove aprox. 1.2 million websites. 58% of the requests were denied. EU country Total removal requests % of URL’s removed % of URL’s removed France 247,832 48.4% 51.6% Germany 222,319 48.2% 51.8% U.K. 163,205 38% 62% Spain 104,240 37.2% 62.8% Italy 86,002 29.7% 70.3% Austria 23,274 47,7% 52,3% Belgium 37,472 45.7% 54.3%
  • 11. Criteria for evaluating delisting requests 1. Data subject’s role in public life 2. Nature of information • Bias toward an individual’s strong privacy interest (personal financial information; related to an individual’s intimate and sex life; private information about minors; private contact or identification information etc.) • Bias toward a public interest (related to criminal activity; relevant to political discourse and governance; relates to public health etc.) 3. Source 4. Time
  • 12. A right to delisting vs. social forgetting • The “boomerang” effect and the paradox of forgetting • Collecting links of delisted items
  • 13. When a record is deleted using the SQL interface in relevant databases, it is only marked as deleted and gets removed from the search indexes. Deletion in MySQL:
  • 14. Viviane Reding, the European Commission’s vice-president (2010 - 2014) ‘‘It is clear that the right to be forgotten cannot amount to a right of the total erasure of history.’’
  • 15. Numbers related to the information that is collected from users • As of the third quarter of 2017, Facebook had 2.07 billion monthly active users. • Google announced over 2 billion monthly active devices on Android in May 2017. • Google Drive now has 800 million users and Google Photos has more than 500 million monthly users in 2017.
  • 16. AI has no reasoning, will, desire, ethics beside our own. Image from "Explaining and Harnessing Adversarial Examples" by Ian J. Goodfellow, Jonathon Shlens, Christian Szegedy
  • 17. Apple’s “most advanced” face ID tech that can detect if someone is trying to get into your phone with a probability of 1 in 1 million Can’t tell these 2 women co-workers apart
  • 18. Forgetting in algorithmic memory “obfuscation” = to produce misleading, false or ambiguous information parallel to the relevant one
  • 19. The right to be forgotten impacts machine learning algorithms • Erasure of one data • Making data less sensitive • Functional encryption algorithms • Pseudonymization • Data anonymization
  • 20. Possible approaches • Data minimization • Interdisciplinary research addressing innovative technological solutions and dedicated legal norms for the AI model
  • 21. Possible approaches • Take control over your data • Use ethical products that respect your privacy as a user Examples of open source projects: - Mastodon - decentralized social network - Matrix - encrypted end-to-end chat - Cryptpad - zero knowledge collaborative editor
  • 22. Feel free to contact me! E-mail: [email protected] @cristina.r:matrix.org @[email protected]