In this discussion paper, CIPL considers the following key privacy and data protection concepts and explores how they can be effectively applied to the development and deployment of genAI models and systems:
- Fairness;
- Collection limitation;
- Purpose specification;
- Use limitation;
- Individual rights;
- Transparency;
- Organizational accountability; and
- Cross-border data transfers.
The analysis in this paper builds on our previous work on the intersection of data protection, artificial intelligence, and organizational accountability and synthesizes it for the context of genAI models and systems. Our work has included convening global regulators, academia, and industry to discuss the emerging tensions between AI technologies and data protection principles and develop potential solutions that resolve or mitigate these tensions.