1 of 11

SSH and ELSI Aspects

Luca Schirru (KUL), Sabrina Brizioli (CNR) and Valentina Colcelli (CNR)

2 of 11

Origin

Type

Data

Personal

Human-generated

Machine-generated

Non-Personal

Human-generated

Machine-generated

Why it’s important?

3 of 11

Data

GDPR

ODD

IPRs

DGA

FFNPD

DSA

DMA

AIA

DA

IPRs (EU)

Trade Secrets

InfoSoc

Database

CDSM

Term

Software

Orphan Works

EU Legal Framework on Data

(main Directives, Regulations and Proposals)

Author: Luca Schirru

EU Law

National Laws

International Treaties

IPRs (Intl’ Treaties)

Berne

Convention

Rome

Convention

Paris

Convention

Marrakesh

Treaty

WCT

WPPT

TRIPs

4 of 11

Are all data subject to IPRs?

< name & contact - other presentation info>

Data x Works x Databases

What is covered by IPRs?

Are all uses covered by IPRs?

5 of 11

“Creative Commons licenses give everyone from individual creators to large institutions a standardized way to grant the public permission to use their creative work under copyright law”

From “all rights reserved” to “some rights reserved”

6 of 11

Relationship with the national Law

< name & contact - other presentation info>

Types of data

Licenses compatibility

7 of 11

Scope of the GDPR

(material and territorial scopes)

GDPR applies to personal data:

Processed by a controller or processor in the EU

Of data subject in the EU for specified activities and the controller and processor are not established in the EU

In the context of the activities of an establishment of a controller or a processor in the EU, even if the processing is not in the EU

Which form part of a filing system or are intended to

Wholly or partly processed by automated means

Arts 2 and 3, GDPR

8 of 11

Data subject

Personal data

Data controller

Data processor(s)

Data protection authority

Lawfulness, fairness and transparency

Purpose Limitation

Data minimisation

Accuracy

Storage limitation

Integrity and Confidentiality

Accountability

Personal data shall be ‘processed lawfully, fairly and in a transparent manner in relation to the data subject’

Personal data shall be ‘collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes’

Personal data shall be ‘adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed’

Personal data shall be ‘accurate and, where necessary, kept up to date’

Personal data shall be ‘kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed’

Personal data shall be ‘processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures’

‘The controller shall be responsible for, and be able to demonstrate compliance with’ the previous items

Principles

9 of 11

Consent

    • ‘the data subject has given consent to the processing of his or her personal data for one or more specific purposes’

Performance of a contract

    • ‘processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract’

Compliance with a legal obligation

    • ‘processing is necessary for compliance with a legal obligation to which the controller is subject’

Protection of vital interests

    • ‘processing is necessary in order to protect the vital interests of the data subject or of another natural person’

Public interest

    • ‘processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller’

Legitimate interest

    • ‘processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.’

‘Processing shall be lawful only if and to the extent that at least one of the following applies’ (art 6(1)):

Legal Bases

10 of 11

< name & contact - other presentation info>

What are your ELSI concerns?

11 of 11

< name & contact - other presentation info>

«Some questions of interest would be what to think of if training data for AI and ML contain data that is protected by intellectual property rights and GDPR. That applies to both creating and sharing such data sets. Related to this questions is risk assessment for proper use of of AI and ML-models in research to avoid bias. That may require knowledge of the training data.»

  • Personal Data: Art. 35 (1) GDPR: “Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data”
  • Copyrights: TDM exceptions (CDSM, arts. 3 and 4)

An example: