The Vanishing Record: Artificial Intelligence, Anonymisation, and the Unexamined Premises of Data Protection Law
Keywords:
Artificial intelligence; data protection; anonymisation; right to erasure; proportionality; differential privacy; General Data Protection RegulationAbstract
Data protection law sits on foundations that it has never seriously examined: that it is possible to locate and destroy a record on request; that it is possible to make a record anonymous without identifiers by performing some steps; that a controller which takes a recognised safeguard thereby discharges its obligations. Each premise was created during a time of registers and released tables. None resists the influence of artificial intelligence: a trained model keeps some traces of the individuals from whom it was trained but keeps no record of them in any place where they can be found. This article is a call for the courts and regulators to recognise that the resulting gap does not need to be filled by an engineering solution, but rather is a doctrinal shortcoming, and that the published scientific record provides the evidence that they require to fill the gap. Building on that record, and six episodes of enforcement and adjudication in four jurisdictions, it suggests that proportionality review must shift from a documentary to an evidentiary discipline and that de-identification safe harbours in the statute should be reconsidered when the data is intended to be used to train a model.





