Legal, Ethical, Privacy and Societal Adherence

 

Report on the human fundamental rights impact assessment, ethics by design and ethics by use, data privacy impact assessment and assessment list for trustworthy AI.

Executive Summary

This Deliverable reports on the Project’s Fundamental Rights Impact Assessment (FRIA), the Data Protection Impact Assessment (DPIA), the Assessment List for Trustworthy Artificial Intelligence (ALTAI) for self-assessment1 and the Ethical Artificial Intelligence (AI) risk assessment.

More precisely, it analyses in detail how fundamental rights and freedoms and relevant societal values may be affected within PopEye’s framework. Moreover, it evaluates certain socio-cultural considerations that must be integrated to respect diverse cultural norms and mitigate potential resistance to accepting PopEye’s framework by some communities or regions in the European Union (EU). It also recommends technical, organisational and other measures to be taken to address all identified risks.

Overall, this Deliverable conducts a comprehensive impact assessment, covering all relevant privacy, ethical, social and legal issues of PopEye. It thus contributes to: identifying ethical, legal, social and privacy-related concerns inherent to the PopEye technologies; delineating data flows within the PopEye tools, stakeholders and services; recognising significant risks associated with these data flows (mostly biometric data); facilitating interactive workshops and/or conducting interviews with pertinent Project/external stakeholders; and collaborating with all partners to propose potential technical or operational solutions and mitigation measures, prioritising aspects of privacy, social impact, security, lawful basis and elements related to traveller
recognition in the EU Schengen Area.

The remainder of this Deliverable is structured as follows:

Section 1 specifies the purpose of this Deliverable and analyses its methodology. Section 2 scrutinises some key legal instruments, like the Charter of Fundamental Rights of the EU (CFR), the European Convention on Human Rights (ECHR), the General Data Protection Regulation (GDPR), the Law Enforcement Directive (LED), the Artificial Intelligence Act (AI Act), but also other applicable legal tools (including soft law). It also assesses further socio-cultural aspects of PopEye, in particular relating to: profiling; accountability and transparency; the way in which end-users and individuals subjected to the use of the PopEye’s technology will be informed on the functioning of the technology, its limits and potential risks; measures to avoid and/or minimise
discrimination and stigmatisation; and other relevant socio-cultural aspects, namely, the risk of surveillance and over-control, as well as complexities in data processing via AI. Section 3 conducts a comprehensive impact assessment involving the Project’s interim DPIA+ and FRIA, including the ALTAI and the ethical AI risk assessment. This includes: a scrutiny of the Project’s data processing operations (also covering the processing via AI) and their purposes; an assessment of possible interferences with fundamental rights and freedoms; the Legality-, Legitimacy- and Necessity-test (LLN-test), known from settled case law of the European Courts; and a principles-based approach, relying upon the ALTAI and the ethical AI risk assessment. Section 4 summarises and draws conclusions.

 

DOWNLOAD