← Back to posts
Post 60

Popia And Gdpr

Go deeperRead the long-form companion article: Popia And Gdpr

The right to be forgotten does not really apply to an AI model that has learned from you.

Major privacy laws, the European GDPR and South Africa's POPIA and their counterparts around the world, are built around a model of personal data that is, essentially, a file. Your name, your address, your records. If you want that file corrected, deleted, or moved, the law gives you the right to ask, and organisations have to comply. For most of what companies do with information, this works reasonably well. The file exists in a database, and the database can be searched, edited, exported, or wiped. The legal model and the technical reality match up.

AI has quietly broken this match. When a model is trained on data that included yours, your information no longer sits in a file that can be neatly deleted. It has been smeared across millions of parameters in a statistical object that nobody, not even the engineers who built it, could point to and say here is the part that came from you. You can ask for the file to be deleted, and the file will indeed be deleted. The model, however, will keep behaving as if it learned from you, because it did. The regulation written for the file world is being applied to the model world, and the mismatch is awkward for everyone, especially the regulators, who are mostly pretending this problem does not exist yet. When you exercised your right to have data deleted somewhere, did you ever wonder whether the deletion actually removed the traces, or just the file?

Last week we looked at the laws of paper-record privacy. This week we look at the right to be forgotten and at why an AI model cannot really forget you the way a database can.

#POPIA#GDPR#DataPrivacy#AIEthics