How will the GDPR impact machine learning?
oreilly.com
oreilly.com
I am extremely proud to be associated with the GDPR (I'm still a European for now). It is an absolute belter of a set of regulations. If you read it, it is actually pretty concise for a legal thingie. It is also very prescriptive which is pretty odd for a legal thingie. It is up there with the "quietly enjoy your own property" basic right that is sort of enshrined in English Law nowadays (IANAL but a search would tell you what I'm on about).
If complying with GDPR is considered a problem then good luck with monetising that weakness.
Also, consider making your site compliant.
Not very long ago there were a bunch of articles posted on HN about how ML and deep neural networks produce knowledge, without humans being able to explain all the steps or any of the steps, and asked the question if this knowledge is still good.
The GDPR answers this question for business decisions regarding humans: No. It's not good enough. Your business is absolutely allowed to use ML for business decisions, but if a person asks how you reached that decision, you can no longer hide behind the machine, you can't treat it as some kind of oracle in a black box that spits out correct answers without any human knowing how the mind of the oracle works.
And I think that's an important foundation to have going forward. It's like how math tests work, you can't just print the correct answer, you have to show your work as well. Because the alternative is a dystopian "the computer is never wrong" future, and that's gonna suck for everyone.
Businesses may be required to state the reason why a decision was made under other regulation but in those cases those are essentially one liners that do not provide any real explanation e.g. credit score does not meet our treshold.
There is however a real problem with GDPR and ML and by real I mean it’s not you’re getting fined out of business but that no one has a good answer for it and that is if I use your information to train a model and you then tell me to stop and delete all your information do I need to retrain my network? (While most would say no it’s not that simple)
Because for example there are other questions like does a trained model constitutes anonymization or not? And again before you say “yes” there are ways to reconstruct the training data from models e.g. http://www.deeplearningbook.org/contents/autoencoders.html
There’s also the issue of using the data for decision making once a request to stop processing has been issued primarily does processing happens only during training or also during inferencing?
You are pretty much just repeating the questions and issues from the original article now. It addresses them better than I can.
But again the fact that a blog post says X isn’t enoguh and while I have no doubt that eventually sense will prevail it still doesn’t fix the current problem and that is that the lack of prescriptive guidance from the 28 DPAs is problematic because it’s not a small risk.
What people don’t seem to understand is that most people who have problems with the GDPR don’t have problems with its principles but rather with the fact that it has been rolled out without almost any clear guidelines and rulings. If you can’t be 100% sure that your business model is compliant with the GDPR it can be a pretty big risk to take on and this ambiguity is much more disruptive than the requirements themselves.
BTW the machine learning problem isn’t unique to GDPR, HIPAA also has this problem most companies elected to classify their trained models as patient data to be on the safe side unless they were only trained with public information.
If you want to do business with the EU then GDPR will probably apply in some way but not for say US to China relations.
However the GDPR is a damn fine set of standards to live up to - bear in mind that you personally are a person. Would you not want your rights as an individual protected in the same way. Go on ... live a little (and be decent).
GDPR may be what everyone needs.
No idea how much that's really an issue, but I'm pretty sure lots of people order from AliBaba in the EU (I have).
If a company uses a Chinese mega surveillance corp API, they still have to disclose it, and they can't just hide behind a "the computer says no" response if they use the results of that API call to make a business decision. The GDPR gives the data subject the right to know why and how the business decision was made, and gives the subject the right to appeal.
If you took someone's picture and ran it through neural style, would that be illegal because you couldn't tell them exactly why it painted their nose blue while imitating Leonardo Da Vinci's artistic style? Is Google auto identification of objects in personal images illegal now because they can't explain how a deep neural net works and classified their friend as something non-human by accident? This has actually happened.
That depends completely on what you are using the value for. Recommending five funny articles - GDPR does not apply. Denying an insurance claim - GDPR most certainly applies, and you have to be able to explain what factors went into the decision. You can't have unaccountable oracle boxes.
Note that a perfectly valid answer could be something like "We've analyzed your posts on social media and we've categorized you as having severe anger issues, which is why we're denying this auto collision insurance claim, because you are most likely at fault given situations like this". The GDPR says you have to be able to explain your decision like that. It doesn't forbid you from making these decisions.
> If you took someone's picture and ran it through neural style, would that be illegal because you couldn't tell them exactly why it painted their nose blue
This is not a business decision, don't be ridiculous.
The Chinese Corp API seems like the same thing. "We looked at you and decided you look like someone who wants to go on a Greek vacation."
EDIT: Also Jacques is not a Lawyer either.
So of course you are being downvoted.
From the article: "...one of the first major distinctions the GDPR makes about ML models is whether they are being deployed autonomously, without a human directly in the decision-making loop. If the answer is yes—as, in practice, will be the case in a huge number of ML models—then that use is likely prohibited by default."
If users explicitly consent to it, then it's permitted under GDPR, but what percentage of users are going to do that? Most will be hitting the "decline" button by default on all websites, even if a given application of ML will be beneficial to them.
This is a showstopper for most ML in the EU. If you have an ML startup in the EU....either close up shop or move.
In practice I wonder if insurance companies (for instance) are actually doing a live ML evaluation on customers, or do they just use ML to develop some 'bandings' that they fit you in to? They could still do this of course, because they can use anonymous data to build a model.
I don't see where the competitive advantage you mention lies? Yes a company in the US could use ML on US citizens, but not EU ones. Presumably a company in France could set up a server in AWS US-West region and do ML on US citizens, but not EU citizens? Surely it is a matter of where the data-subject lives, not where the company is based?
Well, if you can't perform ML on data about the population that is most accessible to you, you are at a competitive disadvantage to those who can. I can't think of many EU companies that control large amounts of data on US citizens. Though I'm sure they exist, there are many more US companies that would have larger volumes of data on US citizens.
Granted, there are some country-specific behaviors that this will not apply to, but then nobody will be finding out what those are in the EU because it's now illegal to do there.
The regulation identifies three areas where the use of autonomous decisions is legal: where the processing is necessary for contractual reasons, where it’s separately authorized by another law, or when the data subject has explicitly consented.
But, again, nobody's going to consent - after encountering countless permission popups on websites each and every day, most will just be hitting "decline" without reading what is being asked.
This doesn't receive nearly enough attention.
Imagine you are a company that makes $500k+/year off of user data. You are not just going to stop doing it because of GDPR, you are going to spend up to $500k on lawyers figuring out how to get around it.