Almost seven decades after Alan Turing conceived of ‘intelligent machines’, there has recently been a surge of interest in machine learning and algorithmic decision-making. The popular imagination has been stirred by high-profile events such as the victory of IBM’s supercomputer, Watson, in the US quiz show Jeopardy, and Google Deepmind’s deep learning program AlphaGo’s victory in the ancient Chinese game Go. Meanwhile, machine learning processes are being deployed in contexts as varied as fraud prevention, medical diagnostics, and the development of autonomous vehicles. The underlying technologies are increasingly accessible to data controllers, with major cloud computing providers including Amazon, IBM, Google, and Microsoft offering low-cost, scalable, cloud-supported machine learning services and tools, with a particular focus on data mining and other types of predictive analytics. Regulation of ‘automated individual decisions’ is not new to data protection law and was addressed explicitly in the 1995 Data Protection Directive (DPD).1 The 2016 General Data Protection Regulation (GDPR) extends the protection against decisions made solely on the basis of automated processing to cover not only profiling of data subjects but also any other form of automated processing.2 All of the data protection principles apply to such processing, but perhaps most significant are the requirements of the first principle, which stipulates that processing of personal data must be lawful, fair, and transparent. Although that may appear straightforward, the practical application to machine learning of each element of this principle is likely to be challenging.
No takes yet. Share an insight, caveat, or question.
Kuner et al. (2017) studied this question.