Data Protection: Personal Information, GDPR, APPI
Putting personal information into AI can become subject to the personal-information protection law (APPI) or GDPR. Design is needed together with legal.
Points to Pin Down
- Cross-border transfer: sending personal data to an AI on overseas servers = a cross-border-transfer issue
- Purpose of use: is it within the purpose stated at collection?
- Third-party provision: does provision to an AI vendor apply?
- Training use: input used for training can become uncontrollable
Practical Principles
- In principle don't input personal info (anonymize/pseudonymize first)
- When necessary, block training use via contract (DPA, etc.) and settings
- Confirm storage country, retention period, deletion means
- Take processing you're unsure about to legal/experts
Caution
This article is general organization and not legal advice. Regulations change by country/amendment, so always confirm the latest primary sources and experts.
Key Point
"Input it because it's convenient" causes incidents. Default to don't input personal info, anonymize, bind by contract, with exceptions on a legal-approval basis.