{"id":8849,"date":"2021-07-27T14:02:36","date_gmt":"2021-07-27T14:02:36","guid":{"rendered":"https:\/\/cip2.gmu.edu\/?p=8849"},"modified":"2026-02-03T20:10:40","modified_gmt":"2026-02-03T20:10:40","slug":"privacy-law-considerations-of-ai-and-big-data-in-the-u-s-abroad","status":"publish","type":"post","link":"https:\/\/blogs.uakron.edu\/ualawip\/2021\/07\/27\/privacy-law-considerations-of-ai-and-big-data-in-the-u-s-abroad\/","title":{"rendered":"[Archived Post] Privacy Law Considerations of AI and Big Data \u2013 In the U.S. &amp; Abroad"},"content":{"rendered":"<p><strong>By Kathleen Wills, Esq.<\/strong><a href=\"#_ftn1\" name=\"_ftnref1\">*<\/a><\/p>\n<p><em><a href=\"https:\/\/www.linkedin.com\/in\/kathleenwills\/\" target=\"_blank\" rel=\"noopener\"><span class=\"mark04jha2bev\" data-markjs=\"true\" data-ogac=\"\" data-ogab=\"\" data-ogsc=\"\" data-ogsb=\"\">Kathleen<\/span> Wills<\/a> is a graduate of Antonin Scalia Law School and former C-IP<sup>2<\/sup> RA.<\/em><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-7334 size-full\" src=\"https:\/\/cip2.gmu.edu\/wp-content\/uploads\/sites\/31\/2019\/03\/circuit2_200x200.png\" alt=\"circuit board\" width=\"200\" height=\"200\" srcset=\"https:\/\/blogs.uakron.edu\/ualawip\/wp-content\/uploads\/sites\/1670\/2019\/03\/circuit2_200x200.png 200w, https:\/\/blogs.uakron.edu\/ualawip\/wp-content\/uploads\/sites\/1670\/2019\/03\/circuit2_200x200.png?resize=150,150 150w\" sizes=\"auto, (max-width: 200px) 100vw, 200px\" \/><strong>Artificial Intelligence and Big Data<\/strong><\/p>\n<p>While many of us have come to rely on biometrics data when we open our phones with Apple\u2019s \u201cFace ID,\u201d speak to Amazon\u2019s Alexa, or scan our fingerprints to access something, it\u2019s important to understand some of the legal implications about the big data feeding artificial intelligence (AI) algorithms. While \u201cBig Data\u201d refers to processing large-scale and complex data,<a href=\"#_ftn2\" name=\"_ftnref2\">[1]<\/a> \u201cbiometrics data\u201d refers to the physical characteristics of humans that can be extracted for recognition.<a href=\"#_ftn3\" name=\"_ftnref3\">[2]<\/a> AI and biometrics work together in the dynamics as exemplified above, since AI is a data-driven technology and personal data has become propertised.<a href=\"#_ftn4\" name=\"_ftnref4\">[3]<\/a> The type and sensitivity of the personal data used by AI depend on the application, and not all applications trace details back to a specific person.<a href=\"#_ftn5\" name=\"_ftnref5\">[4]<\/a> The already-active field of Big Data analysis of biometrics working with AI continues to grow, promising to pose challenges and opportunities for consumers, governments, and companies.<\/p>\n<p style=\"padding-left: 40px\"><strong><em>A. How AI Uses Big Data<\/em><\/strong><\/p>\n<p>AI works with Big Data to accomplish several different outcomes. For example, AI can use Big Data to recognize, categorize, and find relationships from the data.<a href=\"#_ftn6\" name=\"_ftnref6\">[5]<\/a> AI can also work with Big Data to adapt to patterns and identify opportunities so that the data can be understood and put into context. For organizations looking to improve efficiency and effectiveness, AI can leverage Big Data to predict the impact of various decisions. In fact, AI can work with algorithms to suggest actions before they have been deployed, assess risk, and provide feedback in real time from the Big Data pools. When AI works with Big Data and biometrics, AI can perform various types of human recognition for applications in every industry.<a href=\"#_ftn7\" name=\"_ftnref7\">[6]<\/a> In other words, the more data AI can process, the more it can learn. Thus, the two rely on each other in order to keep pushing the bounds of technological innovation and machine learning and development.<\/p>\n<p style=\"padding-left: 40px\"><strong><em>B. How AI relates to Privacy Laws<\/em><\/strong><\/p>\n<p>Since AI involves analyzing and understanding Big Data, often the type involving biometrics, or personal information, there are privacy considerations and interests to protect. Further, since businesses want access to consumer data in order to optimize the market, governments are placing limits on the use and retention of such data. For some sectors, the boundary between privacy and AI becomes an ethical one. One can immediately imagine the importance of keeping biometric health data private, calling to mind the purpose of HIPAA, the Health Insurance Portability and Accountability Act,<a href=\"#_ftn8\" name=\"_ftnref8\">[7]<\/a> even though AI can help doctors better understand patterns in their patients\u2019 health, diagnoses, and even surgeries.<\/p>\n<p><strong>I. <\/strong><strong>United States Privacy Law<\/strong><\/p>\n<p style=\"padding-left: 40px\"><strong><em>A. Federal Privacy Law<\/em><\/strong><\/p>\n<p><strong><em>\u00a0<\/em><\/strong>As concerns grow about the privacy and security of data used in AI, there is currently no federal privacy law in the United States. Senators Jeff Merkley and Bernie Sanders proposed the National Biometric Information Privacy Act in 2020, which was not passed into law; it contained provisions such as requiring consent from individuals before collecting information, providing a private right of action for violations, and imposing an obligation to safeguard the identifying information.<a href=\"#_ftn9\" name=\"_ftnref9\">[8]<\/a> The act also required private entities to draft public policies and implement mechanisms for destroying information, limit collection of information to valid business reasons, inform individuals that their information is stored, and obtain written releases before disclosure.<\/p>\n<p style=\"padding-left: 40px\"><strong><em>B. State Privacy Laws<\/em><\/strong><\/p>\n<p>There are a few states that have passed their own privacy laws or amended existing laws to include protections for biometric data, such as Illinois, California, Washington, New York, Arkansas, Louisiana, Oregon, and Colorado. Other states have pending bills or have tried\u2014and currently, failed\u2014to pass biometric protection regulation.<\/p>\n<p>The first, and most comprehensive, biometric regulation was enacted in 2008: the Illinois Biometric Information Privacy Act (BIPA), which governs collecting and storing biometric information.<a href=\"#_ftn10\" name=\"_ftnref10\">[9]<\/a> The biometric law applies to all industries and private entities but exempts the State or any local government agency.<a href=\"#_ftn11\" name=\"_ftnref11\">[10]<\/a> BIPA requires entities to inform individuals in writing that their information is being collected and stored and why, and restricts selling, leasing, trading, or profiting from such information. There is a right of action for \u201cany person aggrieved by a violation\u201d in state circuit court or a supplemental claim in federal district court that can yield $1,000 for negligence, and $5,000 for intentional and reckless violations, as well as attorneys\u2019 fees and equitable relief. In 2018-2019, over 200 lawsuits have been reported under BIPA, usually in class action lawsuits against employers.<a href=\"#_ftn12\" name=\"_ftnref12\">[11]<\/a><\/p>\n<p>Texas\u2019s regulation, Chapter 503: Biometric Identifiers, varies greatly from Illinois\u2019s act.<a href=\"#_ftn13\" name=\"_ftnref13\">[12]<\/a> Under this chapter, a person can\u2019t commercialize another\u2019s biometric identifier unless they inform the person and receive consent; once consent is obtained, one can\u2019t sell, lease, or disclose that identifier to anyone else unless the individual consents to that financial transaction or such disclosure is permitted by a federal or state statute. The chapter suggests a timeframe for destroying identifiers, sets a maximum of $25,000 civil penalty per violation, and is enforced by the state attorney general. Washington\u2019s legislation, Chapter 19.375: Biometric Identifiers, is similar to Texas\u2019s regulation in that the attorney general can enforce it; however, Washington carved out security purposes to the notice and consent procedures usually required before collecting, capturing, or enrolling identifiers.<a href=\"#_ftn14\" name=\"_ftnref14\">[13]<\/a><\/p>\n<p>California enacted the CCPA, or California Consumer Privacy Act of 2018, which provides a broader definition of \u201cbiometric data\u201d and that consumers have the right to know which information is collected and how it\u2019s used, delete that information, and opt-out from the sale of that information.<a href=\"#_ftn15\" name=\"_ftnref15\">[14]<\/a> This law applies to entities that don\u2019t have a physical presence in the state but either (a) have a gross annual revenue of over $25 million, (b) buy, receive, or sell the personal information of 50,000 or more California residents, households, or devices, or (c) derive 50% or more of their annual revenue from selling California residents\u2019 personal information.<a href=\"#_ftn16\" name=\"_ftnref16\">[15]<\/a> This was amended by the CPRA (the California Privacy Rights and Enforcement Act), which will become effective January 1, 2023, and expands the CCPA.<a href=\"#_ftn17\" name=\"_ftnref17\">[16]<\/a> One expansion of the CPRA is a new category of \u201csensitive personal information\u201d which encompasses government identifiers; financial information; geolocation; race; ethnicity; religious or philosophical beliefs; along with genetic, biometric, health information; sexual orientation; nonpublic communications like email and text messages; and union membership. It also adds new consumer privacy rights including the right to restrict sensitive information and creates a new enforcement authority. Thus, the CRPA brings California\u2019s privacy law closer to the European Union\u2019s General Data Protection Regulation.<a href=\"#_ftn18\" name=\"_ftnref18\">[17]<\/a><\/p>\n<p>New York amended its existing data breach notification law to encompass biometric information into the definition of \u201cprivate information.\u201d<a href=\"#_ftn19\" name=\"_ftnref19\">[18]<\/a> Similar to California\u2019s law, the SHIELD Act applies to all companies holding residents\u2019 data; on the other hand, the SHIELD Act outlines various procedures companies should implement for administrative, technical, and physical safeguards. New York also passed a limited biometric legislation for employers, but there is no private right of action.<a href=\"#_ftn20\" name=\"_ftnref20\">[19]<\/a> Similar to New York, Arkansas amended its Personal Information Protection Act so \u201cpersonal information\u201d now includes biometric data. Louisiana also amended its Data Breach Security Notification Law to do the same, as well as added data security and destruction requirements for entities.<a href=\"#_ftn21\" name=\"_ftnref21\">[20]<\/a> Finally, Oregon amended its Information Consumer Protection Act to include protections for biometric data with consumer privacy and data rights.<\/p>\n<p>Most recently, on July 8, 2021, Colorado enacted the Colorado Privacy Act (CPA) after the Governor signed the bill into law.<a href=\"#_ftn22\" name=\"_ftnref22\">[21]<\/a> The state Attorney General explains that the law \u201ccreates personal data privacy rights\u201d and applies to any person, commercial entity, or governmental entity that maintains personal identifying information. Like consumers in California, consumers in Colorado can opt out from certain provisions of the Act\u00ad\u00ad\u2014but not all; residents cannot opt out from the unnecessary and irrelevant collection of information, and controllers must receive a resident\u2019s consent before processing personal information. As for remedies, the CAP provides for a 60-day cure period to fix non-compliance of the Act, or controllers will face civil penalties, but consumers do not have a private right of action under this law.<\/p>\n<p><strong>II. International Privacy Law<\/strong><strong>\u00a0<\/strong><\/p>\n<p>Other countries have pioneered data privacy regulations, as exemplified by the European Union\u2019s (EU\u2019s) regulation: General Data Protection Regulation (GDPR).<a href=\"#_ftn23\" name=\"_ftnref23\">[22]<\/a> Since 2018, this regulation has been enforced against companies that operate within any EU member state in order to protect \u201cnatural persons with regard to the processing of personal data and rules relating to the free movement of personal data.\u201d The GDPR \u201cprotects fundamental rights and freedoms of natural persons,\u201d particularly personal data. The regulation is quite comprehensive, with chapters on rights of data subjects, transfers, remedies, and even provisions for particular processing situations such as freedom of expression and information. There are several carve-outs or \u201cexceptions\u201d to the regulation, such as where a citizen gives consent for a specific purpose or the data are necessary for preventative or occupational medicine. Citizens also have \u201cthe right to be forgotten\u201d or withdraw consent at any time and can lodge a complaint for violations or seek judicial remedy, compensation, or administrative fines.<\/p>\n<p>Since the GDPR protects data of EU citizens and residents, it has an extraterritorial effect. In January of 2021, the European Data Protection Board (EDPB) adopted written opinions for new standard contractual clauses of the GDPR jointly with the European Data Protection Supervisor. One clause will be for the transfer of personal data between processors to third countries outside of the EU.<a href=\"#_ftn24\" name=\"_ftnref24\">[23]<\/a> The transfer of personal data to a third country or international organization may only take place if certain conditions are met, namely following some of the safeguards of European data protection law. However, enforcement of the GDPR is taking time, and Ireland\u2019s data protection commissioner, Helen Dixon, has explained that enforcement goes beyond issuing fines. Interestingly, as Apple, Facebook, Google, LinkedIn, and Twitter are based in Ireland, the country takes the lead in investigating companies.<a href=\"#_ftn25\" name=\"_ftnref25\">[24]<\/a><\/p>\n<p>The GDPR has influenced other countries\u2019 privacy laws. For example, Canada has a federal privacy law, the Personal Information Protection and Electronic Documents Act, and provincial laws that protect personal information in the private sector, which were heavily influenced by the EU\u2019s GDPR.<a href=\"#_ftn26\" name=\"_ftnref26\">[25]<\/a> Argentina has begun the legislative process to update its National Data protection regime, and such resolution was passed in January 2019.<a href=\"#_ftn27\" name=\"_ftnref27\">[26]<\/a> Further, Brazil\u2019s General Data Protection Law replicates portions of the GDPR and includes extraterritoriality provisions, but it also allows for additional flexibility. The GDPR has also affected the Israeli regulatory enforcement, which has been recognized by the European Commission as an adequate jurisdiction for processing personal information. While the list of countries affected by, or taking notes from, the GDPR is quite extensive, it\u2019s important to note that this is a global challenge and opportunity to protect the privacy of consumers when handling biometrics, Big Data, and using them in AI.<\/p>\n<p><strong>III. Why the Legal Considerations for AI Matter<\/strong><\/p>\n<p>AI and the usage of Big Data and biometric information in everyday life effect a multitude of individuals and entities. AI can use a consumer\u2019s personal information and, often, highly sensitive information. Misappropriation or violations of that information are enforced against business entities. Governments all over the globe are working to determine which, if any, regulations to pass to protect AI and what the scope of such rules should be. In the U.S., some states require the Attorney General to enforce state privacy laws, while other state laws provide individuals with a private right of action. Interestingly, given the role AI plays in innovation and technology, venture capitalists (VC) might also play a role as the law develops, since VC firms can work with policy makers and lobbyists to determine potential market failure, risk assessments, and benefits from protecting AI and data.<a href=\"#_ftn28\" name=\"_ftnref28\">[27]<\/a><\/p>\n<p>In addition to the individuals, governments, entities, and industries affected by AI and Big Data biometric analysis, there are also legal implications. While this article discusses, at a high level, the international and national privacy law considerations from AI, there are other constitutional and consumer protection laws implicated as well. AI and other uses of Big Data and biometric information have quickly become ingrained in our everyday lives since the first smartphone was created by IBM in 1992. As laws all over the world continue to be discussed, drafted, killed, adopted, or amended, it\u2019s important to understand the importance of AI and the data it uses.<\/p>\n<hr \/>\n<p><a href=\"#_ftnref1\" name=\"_ftn1\">*<\/a> The information in this article does not, nor is it intended to, constitute legal advice, and has been made available for general information purposes only.<\/p>\n<p><a href=\"#_ftnref2\" name=\"_ftn2\">[1]<\/a> Shafagat Mahmudova, <em>Big Data Challenges in Biometric Technology<\/em>, 5 J. Education and Management Engineering 15-23 (2016).<\/p>\n<p><a href=\"#_ftnref3\" name=\"_ftn3\">[2]<\/a> Ryan N. Phelan, <em>Data Privacy Law and Intellectual Property Considerations for Biometric-Based AI Innovations<\/em>, Security Magazine (June 12, 2020).<\/p>\n<p><a href=\"#_ftnref4\" name=\"_ftn4\">[3]<\/a> Gianclaudio Malgieri, <em>Property and (Intellectual) Ownership of Consumers\u2019 Information: A New Taxonomy for Personal Data<\/em>, 4 Privacy in Germany 133 ff (April 20, 2016).<\/p>\n<p><a href=\"#_ftnref5\" name=\"_ftn5\">[4]<\/a> Jan Grijpink, <em>Privacy Law:<\/em> <em>Biometrics and privacy<\/em>, 17 Computer Law &amp; Security Review 154-160 (May 2001).<\/p>\n<p><a href=\"#_ftnref6\" name=\"_ftn6\">[5]<\/a> Jim Sinur and Ed Peters, <em>AI &amp; Big Data; Better Together<\/em>, Forbes, https:\/\/www.forbes.com\/sites\/cognitiveworld\/2019\/09\/30\/ai-big-data-better-together\/?sh=5c8ed5f360b3 (Sept. 30, 2019).<\/p>\n<p><a href=\"#_ftnref7\" name=\"_ftn7\">[6]<\/a> Joshua Yeung, <em>What is Big Data and What Artificial Intelligence Can Do?<\/em>, Towards Data Science, https:\/\/towardsdatascience.com\/what-is-big-data-and-what-artificial-intelligence-can-do-d3f1d14b84ce (Jan. 29, 2020).<\/p>\n<p><a href=\"#_ftnref8\" name=\"_ftn8\">[7]<\/a> David A. Teich, <em>Artificial Intelligence and Data Privacy \u2013 Turning a Risk into a Benefit<\/em>, Forbes, <a href=\"https:\/\/www.forbes.com\/sites\/davidteich\/2020\/08\/10\/artificial-intelligence-and-data-privacy--turning-a-risk-into-a-benefit\/?sh=5c4959626a95\" target=\"_blank\" rel=\"noopener\">https:\/\/www.forbes.com\/sites\/davidteich\/2020\/08\/10\/artificial-intelligence-and-data-privacy&#8211;turning-a-risk-into-a-benefit\/?sh=5c4959626a95<\/a> (Aug. 10, 2020).<\/p>\n<p><a href=\"#_ftnref9\" name=\"_ftn9\">[8]<\/a> Joseph J. Lazzarotti, <em>National Biometric Information Privacy Act, Proposed by Sens. Jeff Merkley and Bernie Sanders<\/em>, National Law Review, <a href=\"https:\/\/www.natlawreview.com\/article\/national-biometric-information-privacy-act-proposed-sens-jeff-merkley-and-bernie\" target=\"_blank\" rel=\"noopener\">https:\/\/www.natlawreview.com\/article\/national-biometric-information-privacy-act-proposed-sens-jeff-merkley-and-bernie<\/a> (Aug. 5, 2020).<\/p>\n<p><a href=\"#_ftnref10\" name=\"_ftn10\">[9]<\/a> Natalie A. Prescott, <em>The Anatomy of Biometric Laws: What U.S. Companies Need to Know in 2020<\/em>, National Law Review (Jan. 15, 2020).<\/p>\n<p><a href=\"#_ftnref11\" name=\"_ftn11\">[10]<\/a> Biometric Information Privacy Act, 740 ILCS 14 (2008).<\/p>\n<p><a href=\"#_ftnref12\" name=\"_ftn12\">[11]<\/a> <em>Supra<\/em> note 9.<\/p>\n<p><a href=\"#_ftnref13\" name=\"_ftn13\">[12]<\/a> Tex. Bus. &amp; Com. Code \u00a7 503.001 (2009).<\/p>\n<p><a href=\"#_ftnref14\" name=\"_ftn14\">[13]<\/a> Wash. Rev. Code Ann. \u00a7 19.375.020 (2017).<\/p>\n<p><a href=\"#_ftnref15\" name=\"_ftn15\">[14]<\/a> <em>California Consumer Privacy Act<\/em> (CCPA), State of California Department of Justice, <a href=\"https:\/\/oag.ca.gov\/privacy\/ccpa\" target=\"_blank\" rel=\"noopener\">https:\/\/oag.ca.gov\/privacy\/ccpa<\/a> (last accessed May 22, 2021).<\/p>\n<p><a href=\"#_ftnref16\" name=\"_ftn16\">[15]<\/a> Rosenthal et. al., <em>Analyzing the CCPA\u2019s Impact on the Biometric Privacy Landscape<\/em>, <a href=\"https:\/\/www.law.com\/legaltechnews\/2020\/10\/14\/analyzing-the-ccpas-impact-on-the-biometric-privacy-landscape\/\" target=\"_blank\" rel=\"noopener\">https:\/\/www.law.com\/legaltechnews\/2020\/10\/14\/analyzing-the-ccpas-impact-on-the-biometric-privacy-landscape\/<\/a> (Oct. 14, 2020).<\/p>\n<p><a href=\"#_ftnref17\" name=\"_ftn17\">[16]<\/a> Brandon P. Reilly and Scott T. Lashway, <em>Client Alert: The California Privacy Rights Act has Passed<\/em>, Manatt, <a href=\"https:\/\/www.manatt.com\/insights\/newsletters\/client-alert\/the-california-privacy-rights-act-has-passed\" target=\"_blank\" rel=\"noopener\">https:\/\/www.manatt.com\/insights\/newsletters\/client-alert\/the-california-privacy-rights-act-has-passed<\/a> (Nov. 11, 2020).<\/p>\n<p><a href=\"#_ftnref18\" name=\"_ftn18\">[17]<\/a> Peter Banyai et al., <em>California Consumer Privacy Act 2.0 \u2013 What You Need to Know<\/em>, JDSupra, <a href=\"https:\/\/www.jdsupra.com\/legalnews\/california-consumer-privacy-act-2-0-93257\/\" target=\"_blank\" rel=\"noopener\">https:\/\/www.jdsupra.com\/legalnews\/california-consumer-privacy-act-2-0-93257\/<\/a> (Nov. 27, 2020).<\/p>\n<p><a href=\"#_ftnref19\" name=\"_ftn19\">[18]<\/a> Samantha Ettari, <em>New York SHIELD Act: What New Data Security Requirements Mean for Your Business<\/em>, JDSupra, (June 1, 2020).<\/p>\n<p><a href=\"#_ftnref20\" name=\"_ftn20\">[19]<\/a> <em>Supra<\/em> note 9, referring to N.Y. Lab. Law \u00a7201-a.<\/p>\n<p><a href=\"#_ftnref21\" name=\"_ftn21\">[20]<\/a> Kristine Argentine &amp; Paul Yovanic, <em>The Growing Number of Biometric Privacy Laws and the Post-COVID Consumer Class Action Risks for Businesses<\/em>, JDSupra,\u00a0 <a href=\"https:\/\/www.jdsupra.com\/legalnews\/the-growing-number-of-biometric-privacy-2648\/#:~:text=In%202019%2C%20Arkansas%20also%20jumped,of%20an%20individual's%20biological%20characteristics.%E2%80%9D\" target=\"_blank\" rel=\"noopener\">https:\/\/www.jdsupra.com\/legalnews\/the-growing-number-of-biometric-privacy-2648\/#:~:text=In%202019%2C%20Arkansas%20also%20jumped,of%20an%20individual&#8217;s%20biological%20characteristics.%E2%80%9D<\/a> (June 9, 2020).<\/p>\n<p><a href=\"#_ftnref22\" name=\"_ftn22\">[21]<\/a> <em>The Colorado Privacy Act: Explained<\/em>, Beckage, <a href=\"https:\/\/www.beckage.com\/privacy-law\/the-colorado-privacy-act-explained\/\" target=\"_blank\" rel=\"noopener\">https:\/\/www.beckage.com\/privacy-law\/the-colorado-privacy-act-explained\/<\/a> (last accessed July 13, 2021); <em>see also<\/em> Phil Weiser: Colorado Attorney General, <em>Colorado\u2019s Consumer Data Protection Laws: FAQ\u2019s for Business and Government Agencies<\/em>, <a href=\"https:\/\/coag.gov\/resources\/data-protection-laws\/\" target=\"_blank\" rel=\"noopener\">https:\/\/coag.gov\/resources\/data-protection-laws\/<\/a> (last accessed July 13, 2021).<\/p>\n<p><a href=\"#_ftnref23\" name=\"_ftn23\">[22]<\/a> General Data Protection Regulation (GDPR), <a href=\"https:\/\/gdpr-info.eu\/\" target=\"_blank\" rel=\"noopener\">https:\/\/gdpr-info.eu\/<\/a> (last accessed May 22, 2021).<\/p>\n<p><a href=\"#_ftnref24\" name=\"_ftn24\">[23]<\/a> <em>Update on European Data Protection Law<\/em>, National Law Review, <a href=\"https:\/\/www.natlawreview.com\/article\/update-european-data-protection-law\" target=\"_blank\" rel=\"noopener\">https:\/\/www.natlawreview.com\/article\/update-european-data-protection-law<\/a> (Feb. 24, 2021).<\/p>\n<p><a href=\"#_ftnref25\" name=\"_ftn25\">[24]<\/a> Adam Satariano, <em>Europe\u2019s Privacy Law Hasn\u2019t Shown Its Teeth, Frustrating Advocates<\/em>, New York Times, <a href=\"https:\/\/www.nytimes.com\/2020\/04\/27\/technology\/GDPR-privacy-law-europe.html\" target=\"_blank\" rel=\"noopener\">https:\/\/www.nytimes.com\/2020\/04\/27\/technology\/GDPR-privacy-law-europe.html<\/a> (April 28, 2020).<\/p>\n<p><a href=\"#_ftnref26\" name=\"_ftn26\">[25]<\/a> Eduardo Soares et al., <em>Regulation of Artificial Intelligence: The Americas and the Caribbean<\/em>, Library of Congress Legal Reports, https:\/\/www.loc.gov\/law\/help\/artificial-intelligence\/americas.php (Jan. 2019).<\/p>\n<p><a href=\"#_ftnref27\" name=\"_ftn27\">[26]<\/a> Ius Laboris, <em>The Impact of the GDPR Outside the EU<\/em>, Lexology, <a href=\"https:\/\/www.lexology.com\/library\/detail.aspx?g=872b3db5-45d3-4ba3-bda4-3166a075d02f\" target=\"_blank\" rel=\"noopener\">https:\/\/www.lexology.com\/library\/detail.aspx?g=872b3db5-45d3-4ba3-bda4-3166a075d02f<\/a> (Sept. 17, 2019).<\/p>\n<p><a href=\"#_ftnref28\" name=\"_ftn28\">[27]<\/a> Jacob Edler et al., <em>The Intersection of Intellectual Property Rights and Innovation Policy Making \u2013 A Literature Review<\/em>, WIPO (July 2015).<\/p>\n","protected":false},"excerpt":{"rendered":"<p>By Kathleen Wills, Esq.* Kathleen Wills is a graduate of Antonin Scalia Law School and former C-IP2 RA. Artificial Intelligence and Big Data While many of us have come to rely on biometrics data when we open our phones with Apple\u2019s \u201cFace ID,\u201d speak to Amazon\u2019s Alexa, or scan our fingerprints to access something, it\u2019s [&hellip;]<\/p>\n","protected":false},"author":3627,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[97,162,195,202,396,835,1159],"class_list":["post-8849","post","type-post","status-publish","format-standard","hentry","category-high-tech-industry","tag-ai","tag-artificial-intelligence","tag-big-data","tag-biometrics","tag-data","tag-kathleen-wills","tag-privacy-law"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/blogs.uakron.edu\/ualawip\/wp-json\/wp\/v2\/posts\/8849","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.uakron.edu\/ualawip\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.uakron.edu\/ualawip\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.uakron.edu\/ualawip\/wp-json\/wp\/v2\/users\/3627"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.uakron.edu\/ualawip\/wp-json\/wp\/v2\/comments?post=8849"}],"version-history":[{"count":1,"href":"https:\/\/blogs.uakron.edu\/ualawip\/wp-json\/wp\/v2\/posts\/8849\/revisions"}],"predecessor-version":[{"id":15614,"href":"https:\/\/blogs.uakron.edu\/ualawip\/wp-json\/wp\/v2\/posts\/8849\/revisions\/15614"}],"wp:attachment":[{"href":"https:\/\/blogs.uakron.edu\/ualawip\/wp-json\/wp\/v2\/media?parent=8849"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.uakron.edu\/ualawip\/wp-json\/wp\/v2\/categories?post=8849"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.uakron.edu\/ualawip\/wp-json\/wp\/v2\/tags?post=8849"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}