Reykjavík University
An algorithm must be seen to be believed : right to an explanation of automated decision-making in the GDPR
Abstract
dc:description.abstractRapid technological developments in the world of artificial intelligence and automated decision-making have brought new challenges for the protection of personal data. Just like their human counterparts, algorithmic decision-makers can be biased and discriminatory which can have serious consequences data subjects. News of automated decision-makers making crucial errors due to these biases are being reported regularly. Errors like systematically classifying some ethnicities as gorillas or charging higher interest rates to minorities compared to non-minorities. To counter these biases and errors, scholars and researchers have stressed the importance of increased transparency and explainability of artificial intelligence. To this end, the General Data Protection Regulation includes a right to an explanation, which grants the data subject a right to an explanation for decisions made by artificial intelligent systems. This thesis analyses the scope and the extent of this right. More specifically, it addresses in what situations data controllers are required to provide explanations, as well as requirements to the content, form and timing of the information. Further this thesis discusses how data controllers can comply with this obligation. In summary, data controllers are required to provide an explanation whenever a decision is based solely on automated processing and produces legal effects concerning the data subject or similarly significantly affects the data subject. The explanation must be provided in ameaningful and understandable way. Therefore, the explanation must include a simple (yet comprehensive) and generic (yet complete) overview of the relevant factors of the underlying system’s functionality that are of importance. In conclusion, data controllers shall provide an ex ante explanation of the system functionality. Lastly, the thesis introduces two methods, subject-centric explanations and counterfactual explanations, which data controllers can utilize to comply with the requirements of the GDPR.
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Friðbert Þór Ólafsson 1994-
- Contributors dc:contributor
-
- Háskólinn í Reykjavík
Subjects
dc:subject × 8Rights
- Language dc:language.iso
- en
Identifiers
dc:identifier.*- Handle dc:identifier.uri
- http://hdl.handle.net/1946/33145
- OAI identifier oai:identifier
- oai:skemman.is:1946/33145