Posted on

Risk mitigation strategies

The risk-based approach of data protection law in the UK and the EU requires all organisations processing personal information to implement appropriate measures in according to the particular circumstances – the nature, scope, context and purposes of the processing undertaken, and the risks posed to individuals’ rights and freedoms.

Under the General Data Protection Regulations (GDPR) organisations are required to identify the risks to people’s data protection rights associated with their processing activities. This will determine the measures needed to ensure that processing complies with the data protection obligations. Compliance therefore, involves assessing the risks to the rights and freedoms of individuals and judging what is appropriate in those circumstances.

Automated processing is generally regarded as higher risk than processing involving direct human oversight

This applies to the use of AI just as to other technologies that process personal data. In the context of AI, the specific nature of the risks posed, and the circumstances of processing will require an appropriate balance between competing interests to ensure data protection compliance. This may, in turn, impact the outcome of the processing. It is unrealistic to adopt a ‘zero tolerance’ approach to risks to rights and freedoms, and indeed, the law does not require this. It is about ensuring that these risks are identified, managed and mitigated.

To manage the risks to individuals that arise from processing personal data in AI systems, it is important to develop a mature understanding of fundamental rights, risks, and how to balance these and other interests. Ultimately, it is necessary to:

  • assess the risks to individual rights that the use of AI poses;
  • determine how these will be addressed; and
  • establish the impact this has on the use of AI.

The primary tool for data protection risk assessment is the data protection impact assessment:

How confident are you that your organisation has robust data protection risk assessments that will cover the use of personal information by AI-based tools for HRM purposes? Why?
Record your thoughts in your learning diary before you move on….