میثم کریمی

میثم کریمی

عنوان پایان‌نامه

نهاد های تنظیم گر و نقش آنان در حمایت از داده های شخصی در عرصه هوش مصنوعی با تاکید بر مقررات اروپا ( GDPRو آیین نامه هوش مصنوعی)



    دانشجو میثم کریمی در تاریخ ۳۱ شهریور ۱۴۰۴ ساعت ۲۰:۰۰ ، به راهنمایی رویا معتمدنژاد ، پایان نامه با عنوان "نهاد های تنظیم گر و نقش آنان در حمایت از داده های شخصی در عرصه هوش مصنوعی با تاکید بر مقررات اروپا ( GDPRو آیین نامه هوش مصنوعی)" را دفاع نموده است.


    دانشجو
    میثم کریمی
    استاد راهنما
    رویا معتمدنژاد
    استاد مشاور
    مهریار داشاب
    استاد داور
    وحید آگاه
    رشته تحصیلی
    حقوق ارتباطات
    مقطع تحصیلی
    کارشناسی ارشد
    محل دفاع
    حقوق و علوم سیاسی
    شماره ساختمان محل ارائه
    ۳۸
    نام کلاس محل ارائه
    کلاس ۲۱۰[۲۳۲۱۰]
    شماره کلاس محل ارائه
    ۳۱۰
    تاریخ دفاع
    ۳۱ شهریور ۱۴۰۴
    ساعت دفاع
    ۲۰:۰۰

    چکیده

      

    این پژوهش به بررسی نقش نهادهای تنظیم‌گر در حمایت از داده‌های شخصی در عصر هوش مصنوعی با تمرکز بر چارچوب‌های قانونی اتحادیه اروپا، شامل مقررات عمومی حفاظت از داده‌ها (GDPR) و قانون هوش مصنوعی می‌پردازد. در عصر حاضر، فناوری‌های نوین مانند هوش مصنوعی با قابلیت‌های گسترده در جمع‌آوری، پردازش و تحلیل داده‌های شخصی، چالش‌های جدی در زمینه حریم خصوصی و حفاظت از داده‌ها ایجاد کرده‌اند. در این راستا، نهادهای تنظیم‌گر به عنوان ارکان کلیدی در نظارت، اجرا و تضمین رعایت قوانین، نقش حیاتی ایفا می‌کنند.

    در فصل اول، مبانی نظری شامل مفاهیم داده و داده‌های شخصی، انواع آن‌ها، اهمیت حمایت از داده‌های شخصی و همچنین تعریف، پیشینه، شاخه‌ها و تأثیرات هوش مصنوعی بر داده‌های شخصی مورد بررسی قرار گرفته است. داده‌های شخصی به عنوان سوخت اصلی سیستم‌های هوش مصنوعی، در معرض خطرات و چالش‌هایی از جمله نقض حریم خصوصی، تبعیض و سوءاستفاده قرار دارند. همچنین، مفهوم نهادهای تنظیم‌گر، انواع آن‌ها در اتحادیه اروپا و نقش آن‌ها در حفاظت از داده‌ها تبیین شده است.

    در فصل دوم به تحلیل مقررات حفاظت از داده‌های شخصی اتحادیه اروپا (GDPR) و قانون هوش مصنوعی اختصاص دارد. در بخش GDPR، اهداف کلیدی، اصول مهم (مانند قانونمندی، شفافیت، حداقل سازی و پاسخگویی)، حقوق افراد موضوع داده (از جمله حق دسترسی، اصلاح، حذف و انتقال داده) و نقش نهادهای تنظیم‌گر در اجرای این مقررات بررسی شده است. نهادهایی همچون کمیسیون اروپا، هیئت اروپایی حفاظت از داده‌ها (EDPB)، ناظر حفاظت از داده‌های اروپا (EDPS) و نهادهای ملی مانند CNIL در فرانسه، وظایف گسترده‌ای در نظارت، آموزش، رسیدگی به شکایات و اعمال جریمه‌ها بر عهده دارند. در بخش قانون هوش مصنوعی، تاریخچه تصویب، اهداف (از جمله ترویج هوش مصنوعی انسان‌محور و قابل اعتماد)، دامنه شمول و طبقه‌بندی سیستم‌های هوش مصنوعی بر اساس سطح ریسک (بی‌خطر، متوسط، پرخطر و ممنوعه) مورد تحلیل قرار گرفته است. این قانون با رویکردی مبتنی بر ریسک، الزامات خاصی را برای سیستم‌های پرخطر وضع کرده و نقش نهادهای تنظیم‌گر در نظارت بر پیاده‌سازی این الزامات و تعامل با نهادهای بین‌المللی را برجسته می‌کند.

    در فصل سوم، تحلیل مقایسه‌ای بین GDPR و آیین‌نامه هوش مصنوعی ارائه شده است. شباهت‌ها و تفاوت‌های این دو چارچوب از نظر اهداف، اصول و رویکردهای نظارتی بررسی شده و تأثیرات متقابل آن‌ها بر یکدیگر تحلیل گردیده است. همچنین، نقش نهادهای تنظیم‌گر در هر دو چارچوب مقایسه شده و کارایی، نقاط قوت و ضعف آن‌ها در اجرای قوانین مورد ارزیابی قرار گرفته است.

      

    آنچه در پایان از این پژوهش استنباط می شود این است که نهادهای تنظیم‌گر در اتحادیه اروپا با ایجاد چارچوب‌های قانونی جامع و هماهنگ، نقش اساسی در حمایت از داده‌های شخصی و مقابله با چالش‌های ناشی از هوش مصنوعی ایفا می‌کنند. با این حال، پیچیدگی فناوری‌های نوین و توسعه سریع هوش مصنوعی، نیازمند تقویت همکاری‌های بین‌المللی، به‌روزرسانی مستمر قوانین و افزایش منابع نهادهای نظارتی است. این پژوهش بر اهمیت تلفیق مقررات حفاظت از داده‌ها و هوش مصنوعی برای دستیابی به تعادل بین نوآوری و حمایت از حقوق افراد تأکید دارد.

    Abstract

      This research examines the role of regulatory bodies in protecting personal data in the age of artificial intelligence, focusing on the European Union's legal frameworks, including the General Data Protection Regulation (GDPR) and the AI Act. In the current era, novel technologies such as AI, with their extensive capabilities for collecting, processing, and analyzing personal data, have created significant challenges for privacy and data protection. In this context, regulatory bodies play a vital role as key pillars in supervising, enforcing, and ensuring compliance with the law. The first chapter covers the theoretical foundations, including the concepts of data and personal data, their types, the importance of personal data protection, as well as the definition, background, branches, and impacts of artificial intelligence on personal data. Personal data, as the primary fuel for AI systems, faces risks and challenges including privacy violations, discrimination, and misuse. Furthermore, the concept of regulatory bodies, their types within the EU, and their role in data protection are explained. The second chapter is dedicated to analyzing the EU's personal data protection regulation (GDPR) and the AI Act. The GDPR section examines its key objectives, important principles (such as lawfulness, tra  arency, minimization, and accountability), the rights of data subjects (including the right of access, rectification, erasure, and data portability), and the role of regulatory bodies in implementing these regulations. Bodies such as the European Commission, the European Data Protection Board (EDPB), the European Data Protection Supervisor (EDPS), and national authorities like the CNIL in France, have extensive duties in supervision, education, handling complaints, and imposing fines. The AI Act section analyzes its legislative history, objectives (including promoting human-centric and trustworthy AI), scope, and the classification of AI systems based on risk level (unacceptable, high, limited, and minimal). This law, with its risk-based approach, establishes specific requirements for high-risk systems and highlights the role of regulatory bodies in monitoring the implementation of these requirements and engaging with international institutions. The third chapter provides a comparative analysis between the GDPR and the AI Act. The similarities and differences between these two frameworks regarding their objectives, principles, and regulatory approaches are examined, and their mutual influences are analyzed. Furthermore, the role of regulatory bodies in both frameworks is compared, and their efficiency, strengths, and weaknesses in law enforcement are evaluated. The conclusion drawn from this research is that regulatory bodies in the European Union play a fundamental role in protecting personal data and addressing challenges posed by artificial intelligence by establishing comprehensive and harmonized legal frameworks. However, the complexity of novel technologies and the rapid development of AI necessitate strengthened international cooperation, continuous updates to laws, and increased resources for regulatory bodies. This research emphasizes the importance of integrating data protection and AI regulations to achieve a balance between innovation and the protection of individuals' rights.