Device Manufacturers as Controllers: Expanding the Concept of ‘Controllership’ in the GDPR
Publikation: Bidrag til tidsskrift › Tidsskriftartikel › Forskning › fagfællebedømt
Dokumenter
- Device Manufacturers
Indsendt manuskript, 808 KB, PDF-dokument
In the past, AI-devices offloaded their processing to the cloud, clearly implicating the provider of the cloud as either a controller or a processor under the General Data Protection Regulation (GDPR). Increasingly, however, AI-driven processing is moving away from the cloud. Dedicated AI chipsets embedded in mobile clients and various edge devices now provide on-device predictions. A smart phone can screen for skin melanomas without sending any data to the cloud or app developer, and a bedside patient monitoring system can process locally in the hospital without sending any personal data to the device manufacturer. Such localised processing reveals underlying problems of how responsibility within data protection is allocated. For example, device manufacturers are typically deemed to fall outside the scope of the GDPR. This paper argues that the current understanding of the controller/processor framework is too narrow in scope and calls for a revised understanding of the framework. This is demonstrated through various processing scenarios and a teleological interpretation of the GDPR and CJEU decisions.
Originalsprog | Engelsk |
---|---|
Artikelnummer | 105762 |
Tidsskrift | Computer Law and Security Review |
Vol/bind | 47 |
Antal sider | 36 |
ISSN | 0267-3649 |
DOI | |
Status | Udgivet - 2022 |
Antal downloads er baseret på statistik fra Google Scholar og www.ku.dk
Ingen data tilgængelig
ID: 287694036