One of the more notable aspects of the UK’s DP&DI (No. 2) Bill (the “Bill”) is its explicit recognition that the concept of “scientific research” includes “any research that can reasonably be described as scientific”, even when carried out for a “commercial activity” (see clause 2 of the Bill, amending Article 4 of the UK GDPR). It adds that this research can include “technological development”.
This matters because personal data processing for “scientific research” receives special treatment under the GDPR (e.g. “scientific research” can provide a lawful ground for processing special category data and – under certain conditions – benefits from derogations from transparency and data subject rights). Because of this, you can expect strong interest from private sector entities to explore whether their product-oriented research and development activities can be characterised as “scientific research” under the Bill.
Is this really a change or just a clarification?
Some will argue the UK proposal is simply a clarification of the GDPR’s existing intent. For example, GDPR Recital 159 already acknowledges that the concept of scientific research “should be interpreted in a broad manner including for example technological development and demonstration, fundamental research, applied research and privately funded research” (emphasis added) – giving a clear nod towards, without unambiguously endorsing (since this language exists in recitals, not within operative statutory provisions), commercially-funded research.
Whether or not the concept of “scientific research” under the GDPR actually extends to commercial research has, however, long been a topic for debate. The EDPS, for example, has previously weighed in to express the view that the GDPR’s “scientific research” regime applies only where “the research is carried out with the aim of growing society’s collective knowledge and wellbeing, as opposed to serving primarily one or several private interests”.
If the UK Bill is adopted as proposed, it seems this point will now be settled favourably for the private sector – under UK law, at least.
The potential impact to private sector AI development
It’s worth considering, though, what this could mean in the context of future AI development. ChatGPT is unquestionably the topic du jour in privacy circles (and beyond) at present. The “technological development” necessary to realise generative AI models, like ChatGPT, requires “scientific research” in the field of computer science, and many tech businesses are currently scurrying to research and develop new AI tools as part of their “commercial activity” (Microsoft Bing and Google Bard are just the tip of a very, very large iceberg).
But should research into commercially-funded AI tools like these fall within the scope of the (UK) GDPR’s “scientific research” regime?
You might argue that, yes, it should. After all, Art 89 of the (UK + EU) GDPR requires that data processed for “scientific research” must be subject to “appropriate safeguards”, including “respect for the principle of data minimisation” and, where possible, pseudonymisation and even anonymisation. Proponents could argue this enhances protection for data processed for “scientific research” purposes (and note here that the Bill will add further “appropriate safeguards”, previously addressed in s.19 of the Data Protection Act 2018, in a new Article 84C to the UK GDPR – including that processing for “scientific research” must not cause substantial damage or distress, or be used for making decisions about a data subject to whom the data relates).
Conversely, opponents might argue these are measures that controllers should be taking anyway to comply with data protection principles, and consider even the remote possibility that personal data processed for AI development could benefit from GDPR “scientific research” derogations so unpalatable as to be a door that ought to be shut, firmly, now, so as to leave no room for future debate (or commercially-exploitative misuse) – especially given that the GDPR’s rules on lawfulness, intervention, and explainability, all relevant to AI, might conflict with these derogations.
Is this intended or not?
It’s unclear to what degree the explicit extension of the UK GDPR’s “scientific research” regime to “commercial activity” and its application to AI has already been considered by the UK government as part of its National AI Strategy – but, given the AI gold rush currently underway, this is a clearly point that merits closer examination and careful policy consideration moving forward.
Special thanks go to my friend Eleonor Duhs for her informed peer review (aka marking of my homework) prior to publication.