Abstract
The paper discusses some aspects of the legal regulation of personal data profiling in various jurisdictions. It focuses on derived personal data, also known as inferences, which are the outputs of digital profiling and automated decision-making. Although the extraction of new knowledge about individuals based on the processing of personal data has become common practice in both the commercial and public sectors, there have been only a few attempts to establish specific legal frameworks for derived personal data. These include the European Union, California (USA), and Singapore. Using a comparative legal approach, the author analyzes the characteristics of derived personal data and how the rights of individuals are protected in relation to derived personal information in these jurisdictions and in Russia as well. After examining the relevant laws and regulations, the author concludes that these attempts to regulate derived personal data are an effort to adapt traditional legal frameworks to the challenges posed by Big data. At the same time, the protection of personal data when using Big data technologies and artificial intelligence requires advanced regulatory approaches. Today, data extraction processes are often hidden from data subjects and not under their control. The author believes that the automated processing of personal information, including digital profiling and the extraction of new personal data, should be made more transparent and allow users to opt out.
Author supplied keywords
Cite
CITATION STYLE
Mochalov, A. N. (2024). Digital Profiling and the Legal Regime of Derived Personal Data. Kutafin Law Review, 11(3), 491–513. https://doi.org/10.17803/2713-0533.2024.3.29.491-513
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.