Advertisement

Experts warn AI-driven data inferencing is outpacing state privacy protections

Data-privacy experts said on a recent panel that while state privacy laws regulate what data brokers can collect and sell, those laws often do not extend to the problematic conclusions those companies can infer.
Listen to this article
0:00
Learn more. This feature uses an automated voice, which may result in occasional errors in pronunciation, tone, or sentiment.
A visually striking blue background showcasing a shield with crack patterns, reflecting concepts of security, protection, and vulnerability in an artistic expression.
(Getty Images)

While many states have enacted data privacy laws, some experts warned this week that those protections are being outpaced by advances in artificial intelligence, which can be used to infer sensitive traits — such as sexual orientation, health conditions or political beliefs — from seemingly unrelated data points.

Those concerns were the topic of a virtual panel hosted Tuesday by LGBT Tech and the Justice Education Project, where privacy experts warned that AI can infer sensitive traits from seemingly ordinary data, including app usage, search history, location data and online activity. Those data points, when combined and analyzed by AI, can reveal information such as a person’s sexual orientation, health status or other sensitive characteristics, even if they never disclosed them. These risks are especially pronounced for LGBTQ+ people, abortion seekers, protesters and other marginalized groups, as this data can exacerbate systems of surveillance and inequality, panelists said.

Because this type of data — and the technology and process by which it is gathered — are relatively new, state privacy laws often fall short in offering protections for it. While laws regulate what data companies and data brokers can collect and sell, those laws often do not extend to what those companies can conclude; inferences often fall outside of legal protections offered through deletion rights or “sensitive data” definitions.

“Privacy law governs what you share and what companies sell. It does not govern what they infer, and that gap is where the harm now lives,” Nicholas Stewart, executive director of the Justice Education Project, a criminal justice reform organization, said during the webinar. “A model doesn’t need you to say anything. It reads where you went, what you searched, who you follow, and it produces the claim on its own.”

Advertisement

While advertising companies, data brokers and social media companies are known for possessing and interacting with these types of data at a large scale, concerns also arise when thinking about how governments and law enforcement agencies can get access to this data. Paige Collings, senior speech and privacy activist at the Electronic Frontier Foundation, pointed to the example, reported by 404 Media last summer, of the Department of Homeland Security obtaining airline data through a data broker in order for its Customs and Border Protection and Immigration and Customs Enforcement agencies to carry out mass deportations.

“We’re in a different era because we’re at the behest of more harms, just due to the greater scope of how we live our lives through the digital space,” Collings said. “But at the same time, it’s the same actors and the same power structures and the same vacuums of institutionalized harm that are able to leverage that, and so I think it’s a much more complex situation that requires individual and community-based approaches to really ascertaining what the harms are that I would have that would be different to you. We will all have different threat models and different security based incidents that we’ll have to reflect on, and how automation will harm us.”

Though state data-privacy policy is more advanced than what’s found at the federal level — an ongoing point of contention in Congress — there are ways those laws could be strengthened.

“Many states use this word ‘reveals,’” said Eric Null, director of the Privacy and Data Project at the Center for Democracy and Technology, a nonprofit advocacy group. “So, for certain categories of sensitive data, like racial and ethnic origin, religious beliefs, health diagnosis, sexuality and citizenship, they say that sensitive data is any personal data that ‘reveals’ this information. My argument would be: The data you use to infer that underlying raw data actually revealed that sensitive data, and therefore the underlying raw data itself is entitled to the additional sensitive protections.”

Though a number of states have this ambiguous language in their privacy laws, panelists said state legislatures often have more room than Congress to create such protections. One thing states could do would be to update the language to explicitly define “personal data” in a way that includes inferences and profiles, not just as “data collected from the consumer.” Null and Stewart suggested that this update would also need to coincide with the ability for consumers to also then delete or contest the inferences themselves, not just the raw data.

Advertisement

Panelists said additional safeguards could be supplied if more states included in their laws data-minimization requirements, a practice advocated for by data privacy experts that involves only collecting the information that is necessary from consumers to achieve a specific objective. Another improvement they suggested was to strengthen the guardrails on government access and use of these types of datasets, addressing the concerns about commercial surveillance feeding enforcement mechanisms. Collings said governments and law enforcement agencies should be required to obtain warrants before purchasing bulk location data, or other mass datasets from brokers.

The panelists also advocated for giving state attorneys general broader enforcement authority over inferred and sensitive data, and allowing for a limited private right-of-action for disclosures that led to serious harms, such as wrongful outings of LGBTQ+ individuals, stalking or discrimination that resulted from access and use of inferred data points.

“On its own, one data point likely isn’t terribly revealing, but that data point, combined with thousands of others and fed into AI, paints a much more revealing, granular and invasive picture,” said Sara Geoghegan, senior counsel and director of the consumer privacy program at the nonprofit research organization Electronic Privacy Information Center. “So think of a single GPS coordinate. This piece of data could mean anything. It could mean your car broke down there, or you were dropping someone off at that location — but if you frequent that location and that coordinate belongs to a dialysis center, and you go there three times a week for three hours, there is a much stronger inference that you might have kidney disease.”

Latest Podcasts