Prof. Dr. Larry AdamsAcademic, Author & Researcher

Chapter 18: THE FUTURE OF DATA PROTECTION

Technological advances that are changing the relationship between people, organisations, governments and information will drive the future of data protection. The amount of data generated and the ways in which it can be analysed are also transforming with the introduction of artificial intelligence, generative AI, quantum computing, autonomous systems, biometric technology, digital identity, Internet of Things devices, immersive environments and advanced cloud infrastructures.

The traditional idea of data protection was mostly about the prevention of the collection, use and disclosure of personal data without consent. Things are much more complex in the future. Organisations now have access to more and more ways to deduce who people are, to foresee their actions, to tailor services to them, and to make decisions using automated systems. Therefore, in the future, data protection should not only have to deal with what information is collected, but also what can be derived from it, how automated decisions can be made, who is responsible for the decisions and how decisions can be challenged.

The United Nations Global Digital Compact (United Nations, 2024) echoes this broader approach by urging for interoperable data-governance systems, greater collaboration across borders, and robust international governance of AI that safeguards human rights and fosters technological progress.

18.1 Emerging Technologies

New technologies will in many ways define the new Data-Protection landscape. The most important development is undoubtedly artificial intelligence, which can analyze vast amounts of data and look for patterns that may be hard for humans to see. Machine learning systems can look at patterns of behaviour, location, buying habits, social interactions and other data to make predictions about people.

The extra edge that Generative AI brings is that it creates new content in various forms – text, images, audio, video and software – based on patterns detected from vast amounts of data. This raises significant issues of training data source, copyright, personal data, synthetic identities and misinformation. It also poses problems with respect to data subjects in whose personal data may have been included in datasets without their meaningful knowledge or control.

Another significant development is biometric technologies. Face recognition, voice recognition, behavioural biometrics and other identification technologies have the potential of delivering significant value in security and public-service delivery. But biometric information poses unique privacy dangers as individuals can't easily change their biological features if they are breached.

The Internet of Things will increase data collection even further, adding to the variety and volume of data collected. In the age of smartness, vehicles, sensors in the physical world and connected medical devices are all constantly producing data on the physical context and on human activities. The distinction between digital data and everyday life is therefore becoming more and more elusive.

Individuals, organisations, physical infrastructure and environments may have detailed digital representations thanks to digital twins and advanced simulation technologies. These systems could enable healthcare, manufacturing and urban planning, but could also cause new risks if digital representations are inaccurate or manipulated, or if they are used beyond their intended purpose.

The answer might be part of privacy-enhancing technologies. It is possible to carry out data analysis without unnecessary exposure of identifiable information, using techniques like federated learning, differential privacy and secure computation. Restriction of technology is likely to be the first step in future data protection, while the embedding of privacy protection within technology will be the second.

18.2 Quantum Computing Challenges

One of the biggest challenges in the foreseeable future for cyber security and data protection is quantum computing. Many digital services, such as secure communications, online banking, digital signatures and protected data transfer, rely on conventional public-key cryptographic systems. Some widely used cryptographic techniques could be compromised in the future by large-scale quantum computers.

The danger is especially great because information encrypted now can be collected by an attacker and kept for later use in decrypting the information. Sometimes this is referred to as a harvest now decrypt later risk. This means that organisations do not have to wait for the day of the powerful quantum computers to get ready for it.

The answer is the shift to post-quantum cryptography (PQC): cryptographic algorithms that are resistant to quantum computer attacks. The U.S. National Institute of Standards and Technology (NIST) released three major post-quantum cryptographic standards (FIPS 203, FIPS 204 and FIPS 205) in 2024. As it may take time to replace cryptographic infrastructure, NIST has urged organisations to start their migration efforts (NIST, 2024).

It's not a matter of just swapping one algorithm for another. Organisations must find out where cryptography is being applied in the hardware, software, cloud, databases, communications and third-party applications. They need to be aware of vulnerabilities in particular algorithms in systems and they need to come up with migration strategies.

Cryptographic agility will thus be a growing tenet of practice. It is important to design systems such that the cryptographic algorithms can be changed without having to rebuild the infrastructure. This is especially significant as organisations can be expected to switch algorithms in the future as technology progresses.

There could also be good news in cyber security when it comes to quantum computing. Quantum technologies are being investigated to develop new methods of secure communications and enhanced security features. However, the rise of quantum technology should not only be seen as a threat, it is also a risk and an opportunity for innovation in the field of cyber security (Liu & Moody, 2024).

Data protection authorities have a new regulatory role to play in the quantum transition. Organisations with information that is very sensitive and has a long-time frame for confidentiality purposes should start to evaluate quantum risks well before quantum computers can become capable of cracking today's encryption.

18.3 AI Regulation

It is expected that AI regulation will be one of the most significant areas of data governance in the future, over the next few decades. The big debate isn't about regulating AI; it's about what kinds of regulations can do that without being overly onerous and stifling of beneficial innovation.

A technological-centric regulatory approach is probably not going to work due to the constant evolution of AI technologies. Risk-based governance is a more robust solution. In such an approach, the more likely an AI system may have a negative impact, the more regulatory requirements are imposed.

There may be limited obligations for low-risk applications, or systems which have the potential to have a significant impact on employment, education, healthcare, access to financial services, public services or fundamental rights may require extensive assessment and oversight.

One example of such an approach is set forth in the European Union's AI Act. It classifies AI systems into different risk tiers and provides detailed guidelines for high-risk AI systems, such as those requiring a risk management plan, data governance controls, logging and human oversight. Some AI applications have transparency requirements.

The OECD's AI Principles also highlight aspects related to human rights, fairness, privacy, transparency, robustness, security, safety and accountability throughout the AI lifecycle (OECD, 2024). UNESCO's Recommendation on the Ethics of Artificial Intelligence also focuses on the human dimension of responsible AI governance, with human dignity, human rights, inclusion, transparency and human oversight at its core (UNESCO, 2021).

So, there are a few basic principles that should form part of the foundation of future AI regulation. First, transparency should help people to know when they are talking to AI, and under certain circumstances know what is going on behind the scenes if the decision turned out to be consequential. Second, where automated decisions would have a substantial impact on the individual, there should be human oversight. Thirdly, it needs to define who or what is accountable for harm caused by an AI system. Fourth, Fairness/Non-Discrimination be reflected in the design, testing and monitoring of systems. Fifth, it's essential to ensure security and robustness across the entire AI lifecycle.

Importantly, regulation needs to be broader than just developers. Risks can arise in organisations when AI systems are misconfigured, poorly trained, wrong data is used or overreliance is placed on outputs produced by the AI. Accountability needs to be spread throughout the AI value chain, therefore.

Continuous AI governance is likely to be more of a way of life in the future than it is a one-off certification process. AI systems may adapt to new data or evolving models, or to changing operational conditions. Ongoing monitoring, auditing and reassessment of the risk, therefore, should be a part of regulatory oversight.

18.4 Digital Human Rights

Human rights are inextricably linked to protecting data. With the growing digitalisation of societies, rights that are normally observed in a physical space need to be observed in the digital world too.

One such right is privacy, but there are broader issues about freedom of expression, equality, autonomy, access to information, non-discrimination, due process and human dignity. Digital technologies impact human rights in civil, political, economic, social and cultural aspects (OHCHR, 2024).

AI poses specific human-rights issues as the systems can perpetuate or magnify the discrimination embedded in past data. A disparity between the outcomes of an algorithm for recruitment, lending, insurance, education, or public-sector decision-making can arise without any discriminatory intent.

The complexity of this issue is better visualised with the digital identity systems. While digital identity can enhance access to public services and ease transactions, poorly designed systems could leave out people who don't have the right documentation, technological access and biometric features. The question is, however, how to expand inclusion when going digital, without generating new forms of exclusion.

The right to human autonomy is also becoming increasingly important. Personalisation algorithms can influence what people see, buy, read and believe. Even when users don't understand how, recommendation systems can influence their behaviour. Protecting meaningful human choice may thus need to be taken into account in future digital-rights frameworks.

Special attention must be given to children and those at special risk. Younger users can be exposed to profiling, behavioural advertising, manipulation and inappropriate content in the digital world. Data-protection principles should therefore be subject to enhanced safeguards when those involved in data-processing may have restricted ability to understand or exercise control over data-processing activities.

This principle must therefore be the basis of digital human rights in the future: technological advances should be secondary to human dignity. The UN Global Digital Compact also emphasizes the need for an inclusive, open, safe and secure digital space that respects, protects and promotes human rights (United Nations, 2024).

18.5 The Future Regulatory Landscape:

The future regulatory environment will be more international, interrelated, and technology agnostic. While national regulation will continue to be relevant, national solutions are becoming less feasible in the case of multinationals digital services.

Data often flows across borders on cloud platforms, over international payment systems, global tech giants, and global tech supply chains. As a result, regulatory fragmentation can raise compliance issues and lead to uncertainty over which regulations apply.

In the future it is likely that this will translate into tighter alignment of the application of general regulatory principles instead of the same country-by-country legislation. They may be based on: privacy, accountability, cyber security, transparency, human oversight, proportionality and respect for fundamental rights.

Regional frameworks have the potential to be important tools in this development. Even though the national legal systems vary, it is not impossible for ASEAN to cooperate in the field of personal-data protection, digital-data governance, data-management and cross-border data flows, as has been done already in the region.

The complexity of the regulatory system is likely to grow as well, with regulators becoming more specialised. It may require traditional data-protection principals to work with cybersecurity, competition, telecommunications, financial and AI regulators. Institutional coordination will thus be needed rather than institutional regulatory silos in the future regulatory environment.

There also needs to be more adaptive regulation. Rather than using detailed rules which are likely to change rapidly, governments can mix legislation with regulatory standards, technical guidance, regulatory sandboxes, codes of practice and industry standards.

For new technologies, a regulatory sandbox can be very helpful. They enable organisations to experiment with new technologies in a safe yet supervised environment and give regulators the chance to gain experience with a new technology before rules are established.

The future regulator will thus not only be an enforcement body but also a technology assessor, a risk manager, a standards participant, an educator and a responsible technology facilitator of innovation.

The importance of international cooperation will grow as well. The global digital compact prioritizes interoperability of national data-governance frameworks, reflecting a trend toward recognizing that no single national approach to digital governance is enough for international digital governance (United Nations, 2024).

18.6 Final Reflections

Legislation will not be the only means of defining the future of data protection. It will be influenced by the relationship of technology, institutions, markets, citizens and human rights. With the advent of AI, quantum computing, biometric systems, connected devices, and ever-more sophisticated data analysis there must be a new way of thinking about privacy and security.

In fact, one of the most critical lessons to be learned is that data protection must evolve from reactive to proactive. Risks should be addressed long before a breach, discrimination or technological failure occurs. Systems should be designed to include privacy, security and accountability from its inception.

The second lesson is that technological innovation and regulation are not in opposition. Trust can be built through effective regulation and trust is key to sustainable digital economies. People are more inclined to engage with online services if they feel their data is managed responsibly.

The third lesson is that human rights must be at the core of digital transformation. Data is a good thing but people are not just statistics. Every data set represents a human being and their dignity, autonomy, privacy and rights need to be respected.

The fourth lesson is on cooperation across the borders. Cyber threats, cloud services, AI systems and data flows span across nations. Nobody can solve all of the problems of the future data governance, all on their own. It will therefore be increasingly important for governments, international organisations, regulators, technology companies, researchers and civil society to cooperate with each other.

Last but by no means least, future data governance needs to embrace the fact that the world of technology is a dynamic landscape. It is inevitable that the regulatory infrastructure that is created today will face technologies which are not currently available. The goal should thus not be to anticipate all of the future technology, but rather to set up principles of resilient governance that can be adapted to the changing technological landscape.

It should therefore be viewed as a journey, not a destination, for data protection in the future. As technology progresses, privacy and security should evolve as well, and in tandem with human rights, which should prioritize accountability, transparency and privacy. It is the most successful societies that will not necessarily be the ones that collect the most data and deploy technology the fastest. They will be those who can help build trusted digital spaces that are able to coexist with innovation and human dignity.

There is now a need for a shift from traditional data protection to a more comprehensive approach to responsible digital governance in the future. Such governance acknowledges that the problems of data protection and cyber security are not only linked but also part of one policy environment, as well as the issues of AI ethics, human rights, digital inclusion and technological innovation.

Another way to look at it is that the future of data protection is the future of technology and society. Digital transformation can help shape economic growth, scientific advancement, and public-service effectiveness and social inclusion, if technological progress is managed responsibly. However, when governance is not moving in tandem with technology, then the same systems can exacerbate inequality, surveillance, discrimination, insecurity and loss of individual autonomy.

The guiding principle for the future should, therefore, be simple: technology must serve humanity and data governance must make sure that technological progress is trustworthy, secure, inclusive and respectful to human dignity.