vix.ing · top · new · best · stats · spec

Integrating artificial intelligence into health care through data access: can the GDPR act as a beacon for policymakers?

2019/08/17 by Mélanie Bourassa Forcier, Hortense Gallois, Siobhan Mullan +1 · 1 citation
Medicine · Social Sciences · #Artificial Intelligence in Healthcare and Education #Ethics and Social Impacts of AI

paper · pdf · doi:10.1093/jlb/lsz013

openalex publication_date 2019/08/17 · openalex created_date 2025/10/10 · openalex updated_date 2026/08/05

Abstract

The potential of artificial intelligence (AI) to promote better health care has taken the centre stage in modern debates on public health and health policy. Although AI is considered a contemporary innovation, it has been in development for more than a half century. AI research began in the 1950s, when Alan Turing raised the idea that machines could 1 day think as humans.1 Then came, in 1959, the first instance of ‘machine learning’ (ML), where computer scientists created a program capable of solving puzzles on its own.2 Now, AI promises to lead the next major technological revolution, similar in stature to electricity and the internet.3 In the field of health care, AI has already led to improvements, particularly in areas such as precision medicine, diagnosis tools, psychological support, and help for the elderly.4 AI technologies generally require large amounts of both personal and non-personal data to function. In health care specifically, AI technologies rely on personal information, including health-related data extracted from medical files or research participants’ results.5 Promoting AI and capturing its benefits for the health care system yet depend, in large part, on procuring a convenient access to this sensitive data.6 Ensuring that privacy protections are in place appears essential, especially with individuals showing substantial concerns about sharing their data in the medical and clinical context.7 Suggestions to implement public open databases to promote medical research have created some controversy in Europe and in North America. In the UK, citizens rejected the care.data project launched in 2014 due to privacy concerns. Although widely supported by health care professionals, the failure of the project was largely due to a lack of transparency about the envisioned uses of health information and the possibility to opt-out.8 In the United States (US), studies have shown that individuals’ willingness to participate in research involving their genetic data is affected by their concerns about their ability to protect their privacy in such context.9 Paradoxically, this lack of trust is counterbalanced by a growing popularity of direct-to-consumer genetic testing and health monitoring devices. These devices create massive flows of personal and health data, mostly to private companies. This ambivalent attitude of individuals toward data sharing is a major issue for any privacy and data protection regulation. Adequately assuring the right to privacy of citizens while facilitating access to personal data for research is probably one of the biggest challenges policymakers have to face in any country wishing to benefit from many opportunities of AI technologies in health care. Through the adoption of its new General Data Protection Regulation (GDPR),10 the European Union (EU) was the first to attempt to regulate AI through data protection legislation. This regulation paves the way for meaningful reforms in privacy legislation in the US and Canada. The GDPR covers all personal data processed by a data processor or controller established within the Union (art. 3.1, GDPR). It also extends to personal data of any data subject in the EU, no matter the establishment of the processor in two situations: whenever this processing is related the offering of goods or services to data subjects in the Union; and when related to the monitoring of their behavior within the Union (art. 2.2, GDPR). This means that many foreign companies’ activities may fall into the scope of the GDPR. Moreover, the extra-territorial reach of the new regulation puts pressure on Canada and the US to reform their own privacy legislation. Indeed, both systems likely fall short of some of the new requirements set by the EU regulation. If these laws are found to provide insufficient protection, the result could be a decrease in data flow from the EU to North America, due to the need to proceed via the adoption of additional contractual clauses.11 Such decrease would not only negatively affect research and development of AI technologies in both countries but would also interfere with any attempt at cooperation in the field.12 In this context, it appears all the more pressing to consider appropriate measures to consolidate privacy protection and promote stakeholders’ trust. After a brief overview of the contributions and promises of AI to the health sector, we will investigate the challenges to data and privacy protection brought about by developments in this field. This will lead us to identify key avenues for policy reform, in the US and Canada, which we contend could be inspired by the GDPR. There is no single definition for AI. According to the Canadian Standing Senate Committee on Social Affairs, Science and Technology, the expression refers to ‘the reproduction of human cognitive functions such as problem solving, reasoning, understanding, recognition, etc. by artificial means, specifically by computer’.13 In many health care systems, AI has already been successfully deployed, mainly in the form of ML- and deep learning (DL)-based technologies.14 In both ML and DL, a certain amount of data (the input) is provided to the system for processing (through one or several algorithms), in order to provide an output. ML is more specifically used for automatic detection of patterns in large amounts of data, based on logical deduction. The key differences between ML and DL include the and amount of data that be processed by the system and the are DL a more form of ML as artificial In DL, the system amounts of and data, while ML is to a amount of information which to be in a that the is to to as The of DL has it at the of the debates especially in health care. The brought by the from ML to DL is while ML the used in DL to the is by the system The of of the also DL systems is into the system and of it is to this has been to In some the data of the to this lack of transparency in DL as a especially when with sensitive AI research to health care is a growing of AI in health care is generally and These are all areas of in which detection is In clinical care, AI ML and DL systems are already in with and information for diagnosis and The of with has shown potential in the of the or of certain of with than DL systems have also shown potential in the development of precision and and are also showing to the by health care in The of and similar is growing in countries with AI in health care is not to in clinical care or in medical AI systems in the for a clinical The ability of AI systems to based on of data also benefit public AI based on Data has to the development of to help and public health and for and In order to these to health care systems by access to data in both clinical and medical care have The of a care for a health care system which is into the of the of that it is a and of the health care and to in is based on the of research and as a way of facilitating data and by access to medical data in health files for The of the between research and by the to some with and These the that research and clinical care need to be to protect and research The more and which privacy and data protection as are a of of this be as a right to access to personal This to information that a to for or only to with a of such as health data, and The challenges the right to privacy with the development of the and AI was at the modern privacy laws The of the differences between the and European on data protection be found in their for In the US and of Canada, privacy protection is in the protection of especially from The US on privacy is a of and and In Europe and Canada have a more to privacy and data In Europe and in Canada, especially in the of privacy is as an of the right to human the Canadian of privacy is a between the EU and the as concerns about while also deep about private of their personal is established as a right in European It benefits from a similar in the in the US and Canada, privacy is not in the as its protection from these individuals on both of the have shown a attitude toward personal to access to data for health personal data through devices and genetic testing on a This behavior is health data is from personal data provided such as This challenges for privacy protection and was by the of personal data by to the Such in the have the of the public to the of personal data for or also the lack of privacy and to uses of personal data, especially on the uses of data are an issue that the European to when the GDPR. to the medical the GDPR has a the one it at and uses of personal data by the private and public the it at access to personal data, for the development of while of the of that the GDPR for a of the in of and health to in place the the GDPR at data more than their ability to research in the first data, more specifically, are as These data are by a which their processing (art. GDPR). are yet provided in order to access to data while their Although as in systems, the right to data protection is an of the right to where data protection be the of privacy is to In Canada and in the data protection the and the of personal AI is not based on any personal data, that no data protection regulation in these The for is personal non-personal data for the scope of of a data regulation. The EU a regulation for non-personal This regulation at the of non-personal data and facilitating the development of a within the personal data are data that the or through of a data Canadian personal information as about an (art. This definition is similar to that in the GDPR which covers information to an or (art. GDPR). In the are of personal data in the as to and all considered to on is considered personal differences the way privacy is In the new European regulation the of personal non-personal Data genetic data, and data, in are considered are a more by the GDPR than that to of personal data (art. the processing of all sensitive data is the GDPR but with a substantial of to this The first of these where ‘the data subject has to the processing of personal data for one or more (art. GDPR). these are established as The of the that as the GDPR is not as as for the processing the processing of sensitive data is when for in the public or research or (art. provided appropriate are in place (art. GDPR). that the of the GDPR is to some in the of research sensitive or including with to the processing of genetic data, data or data (art. and and requirements with (art. and GDPR). Such in this and has been for its on in the a regulation also covers by as a of The and with for the and the of the of to protect health data and privacy is by its scope of only to data processed by and that data are from its which with large amounts of personal data including health-related are generally not by the Moreover, only information any information is considered that it is not subject to any data protection regulation. be in two by in the from the data set or by a that the of to a data set is have been insufficient to all of data The has been considered particularly in the of and genetic This of data is as as as all personal information related to the is and of scope of This the of genetic information is and the that this of data be In this laws at the (the for or additional the is not considered a way to of data in the of personal The GDPR only data from its scope of are set the GDPR. The of a of specifically to these a is be taken of all the means likely to be such as by the controller or by to identify the or means are likely to be used to identify the be taken of all such as the of and the amount of for into the at the of the processing and technological The of sensitive data as it for the need for additional when with health-related It be to but this also as a for especially the in of sensitive data Such between personal data and sensitive data not in the Canadian regulation on data the data protection is by two the Protection and which to the private sector, and the which covers have their own to health information, considered to be and its to private which or personal data for In that their scope of is more than as any processing of personal data by a (art. the on data protection, was considered to protect personal data by EU is especially to data flows from the EU to Canadian companies. of the GDPR to benefit from this the next The lack of protection including sensitive data, could yet from such personal data is only by Such include when the data subject has of the of an and the (art. GDPR). include when a is for the of a with the data or for of public (art. and Such requirements be especially in where large amounts of data are to a DL for has yet to be to into the of AI on privacy and data protection, especially in of sensitive and health-related In an the of uses by of personal data for the of Canada the in legislation on privacy and for the of In with the by the the Committee on to and of the of a with reform for The Committee on the to legislation in order to with European and a potential on with the the of Canadian that on data regulation is not only in privacy but also access to data for health The the policymakers are with and the growing need for to in Canada, as in is to two at the to access to health and health-related data for research that is in the public on the one and to privacy and of their information when it is used for on the In order to better protect uses of data and research through data both the Canadian and the are with the need for substantial Such in at individuals’ their own The new requirements as as in the GDPR are to individuals to more in the protection of their of for the GDPR also for data which need to be both in the and in the Canadian In order to individuals with their data, the GDPR the requirements for set by is as and (art. GDPR). Although the GDPR not that be it be and on this that or not for the GDPR yet open to by This of is to provide of when the of These new requirements promote the of more meaningful are to the of trust for a more data by individuals’ of their own requirements are more many are set by the GDPR which the processing of both sensitive and be any processing a and is only one of the in for the of The include the processing of personal data is for the of a to which the data subject is or in the public (art. and GDPR). as as any the of the is no by the of a In the of sensitive data, that processing based on be to and any processing of the data that is uses of data are when such processing research (art. GDPR). the of the for several is as not to processing of personal data for in the public or research or is to be when the controller has the to by processing data which not or no the of data provided that appropriate uses of data the of new from data subjects are the but by that may from of the The new requirements of for both the and the Canadian which could help trust data In both the Canadian and the is generally for the and processing of personal in both is not in with the new especially as to the of These differences in requirements between the new European regulation and both North laws could that a data considered may be found European the GDPR to such as for as it is not to data subjects are major for any with personal data by the GDPR is to that is and These new requirements have already led to the of a of the by the privacy the the for requirements which to the of the by This to be the first of several to the between the new GDPR and the North If of requirements are in both to better protect individuals’ privacy and these consider the of in order not to the development of to be in the research context, as it is to the of the data of the GDPR this yet not provide a means to the in the GDPR. The on the Protection of with to the of this in in where may not be could be it would be to the research in the in more may be at as the research The form of to in some as is a based on modern to that subjects are and about the uses of their Although the brought by a be for to implement this on a large could be the of to which means to a for research of certain the need to for any a is In a is not for but a substantial in the would a to the research privacy protection, such include an of research as as of the and the in and health care research could be an especially in where the of and data are requirements be in the and in the Canadian but in and especially in health care, to the and potential AI technologies based on the data The GDPR data subjects with right that at their of the of their This right that will to be subject to a based on including (art. GDPR). AI technologies in health care may be by this new This right for that a DL system created to provide be used as the for which will be to this when provided by or when to into a or when the processing is based on the Data subjects have the in such to a for the an issue when AI and such amount of data that a be The of DL systems a for the of AI in health care. information the GDPR is to be in a used and (art. In all data subjects also have a right to access and the personal data that an has on The GDPR an new right to data This right at individuals to better their data and In health care, data is to have benefits for data as it of for to of data on an and it with their or with a research to personal data which has not been provided by the data subject from its scope of The data from the of the data by a health for is not by this its potential benefit individuals have a right to their information from one health to Data in the US lead to a protection of health data, as personal health information is only when by for health health care and any health care this substantial It public health or personal health for that any by a is no health to a may at fall into the scope of of privacy but could also be by US data data be for research by facilitating data in the US context, it also already scope of In Canada, no data its potential to data in research facilitating data from any to a research project in which a data subject to for the Committee on to and that be provide for a right to data The right to data be as a of any privacy regulation at the of as it individuals to better the of their data by it where it is it only in an and health data protection in order to that sensitive data will not lead to a of this right the GDPR to data subjects is the right to (art. GDPR). The right to or right to be individuals to require of their personal data by private or public It is a GDPR which is from both and This right is to data subjects that any personal information be at their also some to the of the right to as it only when based on one of the These include personal data which is no in to the for which in the first this data be for the processing and no the for could be include when the processing is for of public in the of public health (art. or when it the of (art. GDPR). In where the right to its will be by the to and of personal information, especially when already with In the of one of DL is that the used to an is created based on data that has been This data of the and it to identify and data in order to The to the of its could in of failure to This is of a of the EU to the of data for privacy and to promote the development of to of In the health care the right to that health care may be to medical at their the of the information in a medical could to which affect health care. care are already concerns related to problem when Such result from between two systems, but also from to clinical information at the of care is yet The Canadian and may to this in to implement a right to in their at that such right not for health care to implement by its scope of for The GDPR a than its Canadian and on and (art. GDPR). a toward the protection of privacy and personal data, the GDPR the adoption of means to processing personal data (art. and GDPR). The GDPR also that a data protection be whenever a data likely to result in a to the and of (art. GDPR). Although of such data are provided (art. the of the that this is the to help when a is a processing be considered to result in when it sensitive data, data subjects or when it is based a new or an of an of AI in health care are based on health-related data and technological a is likely to be any processing in the field. a a a of the processing and of an of the need for and of the and the to data subjects from the of the data and a of the measures to and with the GDPR. to the to a be found at which specifically ‘the processing of personal data not be considered to be on a large the processing concerns personal data from or by an health care or In such a data protection not be Although from the is Canadian for public US also a to that are to This from the which is as a and the The in that to the EU regulation. Moreover, the data are to the into the processing in order to the requirements of this regulation and protect the of data (art. GDPR). This as by was in the in Canada by it has not been in the Canadian the Committee of the of in that be to privacy by a and to include the of this The GDPR has also a new by (art. GDPR). This that the means for data be when a Data are to set that only the data for the of be and the of such as privacy by and by the GDPR the adoption of appropriate measures to potential These new for to promote and are with new requirements such as of privacy by and by in privacy would help in the of data in the US and Canada. the from the of and the GDPR are to on and to to individuals of any in health information within In Canada, health privacy laws in and and have also data to that into in include a new data to the some have the of the new only in of of The US has also been the first to privacy with to the US the GDPR has set in of privacy and data the US a data protection and the in privacy and data protection between States and to with the new European the are two of the a data may be to or of the of the (art. GDPR). the a may be to or of the of the (art. GDPR). This system at the of with personal data and to privacy These with the to in of privacy at the to any or In an attempt to for data the GDPR no but to a of their activities (art. GDPR). This at the of privacy with and In Canada, is more with its the of the failure to a data is by of to the of the are the has no to order or in of the some privacy and have such The lack of in on the Canadian the data the to provide with more and may If may be insufficient to from the US legislation not provide a on the to at The opportunities brought by the of AI technologies in the field of health care not be AI developments help through of data to and that machines are better to than such are already in health care and and health research and care. individuals to provide access to their personal data, the would be for the of AI in any health care of trust from the public is the of of personal data such as by the The new to such uses of personal data, especially through the of and some could North The of AI and the brought for privacy protection at in the some and could be for AI as the right to the toward of data be and the adoption of more contend that the and to data privacy with the GDPR also for reform, in order to the Canadian and US legislation more to the privacy challenges raised by AI. as as it only data by and Canada has an that to all and all personal data for that it is to to the of AI and the The and by the GDPR regulation a of and and may negatively affect data sharing for a This not in the EU regulation that would help better the challenges by AI. reform consider these for Canada and US privacy but also in that the scope is yet to be through the potential could be in the reforms to in North America. In Canada, which is its medical devices to be of this It is that any medical with data will be it with a by to the The to the way the is created by the the to we that a to protect personal information that data sharing and data would be to all us also not the benefits we of AI are by the of data such is to and be

Cited by

Related