Data protection in the AI era: benchmarking EU GDPR and AIA, to reform Saudi Data Protection law
Jawahitha Sarabdeen — Cogent Social Sciences
Jawahitha Sarabdeen — Cogent Social Sciences
How it connects
Related across sources
Full text
AI systems, especially large language models (LLMs), use huge amounts of data. This raises concerns for many, as it could lead to violations of data privacy. The Saudi Data Protection Law (PDPL) 2021 was passed to address potential privacy violations. However, the requirements on data processing, storage, data minimization, and automation pose challenges for AI system developers. The law may be violated due to the use of personal data in training data, the memorization of training data in small datasets, and inversion attacks. The article aims to identify a doctrinal gap and propose reforms to the Saudi PDPL to enable the law to effectively regulate AI systems. To propose reform, the EU General Data Protection Regulation (GDPR) 2018 and the Artificial Intelligence Act (AIA) have been benchmarked. The article employed legal content analysis and comparative methods. The finding showed that the use of personal data without consent or exception violates various data principles. The article suggested ways to prevent violations and improve existing legal provisions. The suggestions can help AI developers, users, and consumers to benefit from AI without sacrificing their right to privacy.