将GDPR的DPIA流程改造为AI法案FRIA自动化工具的基础
Towards An Automated AI Act FRIA Tool That Can Reuse GDPR's DPIA
- 分析DPIA与FRIA的信息流程,找出可复用环节
- 提出FRIA五步流程,明确各阶段自动化支持点
- 为欧盟AI法案要求的自动化工具提供实现框架
AI法案要求开展基本权利影响评估(FRIA),并允许复用数据保护影响评估(DPIA),同时要求欧盟委员会开发自动化工具以支持FRIA流程。本文首次将DPIA与FRIA视为信息处理过程,系统分析两者涉及的信息内容,明确DPIA可在FRIA中复用的具体环节。在此基础上,提出FRIA的五步流程,并讨论每个步骤中自动化工具的作用。研究为FRIA的信息构建与管理提供了基础,支持欧盟委员会落实AI法案对自动化工具的要求。
原文摘要 · Abstract (English)
The AI Act introduces the obligation to conduct a Fundamental Rights Impact Assessment (FRIA), with the possibility to reuse a Data Protection Impact Assessment (DPIA), and requires the EU Commission to create of an automated tool to support the FRIA process. In this article, we provide our novel exploration of the DPIA and FRIA as information processes to enable the creation of automated tools. We first investigate the information involved in DPIA and FRIA, and then use this to align the two to state where a DPIA can be reused in a FRIA. We then present the FRIA as a 5-step process and discuss the role of an automated tool for each step. Our work provides the necessary foundation for creating and managing information for FRIA and supporting it through an automated tool as required by the AI Act.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。