A/78/310
of the regulations on personal data processing right from the product design stage.
The recommendations are as follows:
• Comply with local regulations on the processing of personal data;
• Conduct privacy impact assessments;
• Embed privacy, ethics and security by design and by default;
• Implement the principle of accountability;
• Design appropriate governance schemes on the processing of personal data in
organizations that develop artificial intelligence products;
• Adopt measures to ensure the implementation of the principles on the processing
of personal data in artificial intelligence projects;
• Respect the rights of data owners and implement effective mechanisms for the
exercise of such rights;
• Ensure the quality of personal data;
• Use anonymization tools;
• Increase trust and transparency with personal data owners.
14. For details on the implementation of some of these recommendations, the
Ibero-American Data Protection Network has prepared additional and more detailed
guidelines, contained in the document entitled “Specific Guidelines for Compliance
with the Principles and Rights that Govern the Protection of Personal Data in
Artificial Intelligence Projects”. 15 The principle of transparency, which will be
referred to later, is discussed in more detail in the present report.
III. Risks inherent to artificial intelligence
15. Society and its digital transformation are being shaped by artificial intelligence,
which is present in several aspects of daily life, the economy, science, education,
health and many other sectors and activities.
16. Though artificial intelligence offers society undeniable benefits and
opportunities, it might also come with intrinsic challenges, risks and t hreats, which
could include its unethical development or use and the making of biased,
non-transparent or incorrect decisions about human beings.
17.
The risk levels depend on each specific situation.
The European Commission is of the opinion that a given [artificial intelligence]
application should generally be considered high-risk in light of what is at stake,
considering whether both the sector and the intended use involve significant
risks, in particular from the viewpoint of protection of safety, con sumer rights
and fundamental rights. More specifically, an [artificial intelligence] application
should be considered high-risk when it meets the following two cumulative
criteria:
(a) First, the [artificial intelligence] application is employed in a sec tor
where, given the characteristics of the activities typically undertaken,
__________________
15
6/20
Ibero-American Data Protection Network, “Specific Guidelines for Compliance with the
Principles and Rights that Govern the Protection of Personal Data in Artificial Intelligence
Projects”, (2019). Available at: https://www.redipd.org/sites/default/files/2020-02/guide-specificguidelines-ai-projects.pdf.
23-15851