The European Bureau of Consumer Unions (BEUC) and researchers from the European University Institute (EUI) in Florence unveiled research on Thursday 5 July on artificial intelligence’s potential in terms of implementing the general directive on protection of personal data (GDPR).
For this, the researchers analysed privacy protection policies in the month of June 2018 at 14 private companies: Google, Facebook, Amazon, Apple, Microsoft, WhatsApp, Twitter, Uber, AirBnB, Booking, Skyscanner, Netflix, Steam and Epic Games.
They used this analysis to develop a machine learning tool, ‘Claudette,’ formed with the aid of a series of examples, to automatically identify clauses in data protection policies that seem to be defective.
The study’s main conclusion is that a month after the regulation came into force, there was still plenty of room for improvement. Not one of the analysed privacy protection policies fully met its requirements.
The result is presented in the form of notes with a colour code where all clauses of the policies in question are categorised. The examined policies have a total of 3,659 sentences an the overall results show that 401 sentences (11%) were classified as containing ‘unclear language’ and 1,240 (33.9%) sentences were considered ‘potentially problematic’ or providing ‘insufficient information.’
What does 'Claudette' say about Facebook’s practices?
Facebook was not spared. The report concludes that its policy ‘gives the impression of the company using the legal terms and buzzwords and catch-phrases, than attempting at constructing a truly user-centric, GDPR complain policy.’
Facebook’s privacy statement is ‘almost copy and pasted from the regulation’ but does not say how and to what purpose data is processed. It says: ‘With Facebook it is particularly unclear where personal data end up and which third parties get access to it.’
Of the 204 sentences analysed from Facebook’s privacy policy by ‘Claudette,’ 79 contain ‘insufficient information,’ 5 ‘unclear language’ and 56 are ‘problematic’ from the viewpoint of data processing, while only 19 contain ‘full information.’
Artificial intelligence in service of data protection
The study’s other major conclusion is that analysis of the content of privacy protection policies can largely be carried out by computers using artificial intelligence if sufficiently large group of data is created.
In practice, this means, however, that many other privacy protection policies have to be analysed manually before analysis can be fully carried out by machines alone.
BEUC and EUI are planning to go further, aiming to turn this into a long-term project for developing automised assessment tools for surveillance authorities, consumer organisations and for users themselves, who face a tsunami of policy updates and new requests for consent.
While at the moment this technology only aims to analyse policies, the researchers say that the day when artificial intelligence-based tools could automatically verify activity related to data processing automatically exercise a right of opposition or to automatically inform the inspection authorities of possible violations is ‘not so distant.’
To discover ‘Claudette,’ go to: https://bit.ly/2IW3bTL and for the study, go to: https://bit.ly/2uakGdN . (Original version in English by Marion Fontana)