Law & Compliance in AI Security & Data Protection
Law & Compliance in AI Security & Data Protection

Welcome to Law & Compliance in AI Security & Data Protection!
This online textbook is available as a living document, based on the training programme of the same name developed by Dr. Marco Almada under commission by the European Data Protection Board’s Support Pool of Experts at the request of the Hellenic Data Protection Authority (HDPA).
Over approximately 15 hours of self-study, the materials below will present an overview of the various stages of the life cycle of applications powered by AI technologies, from the initial stages of their development to the end of their operation. At each stage, the training materials will identify issues that AI introduces and amplifies, as well as potential responses to them. By studying those materials, professionals will be better positioned to understand whether and how their organizations can use AI in accordance with legal requirements for privacy and data protection.
The textbook as a living document
It is now our pleasure to make the training programme, originally published as a PDF ebook, available in a modifiable community version. This means that learners and experts in the topics will be able to propose changes and add comments to the various chapters of this book. By doing so, we intend to benefit from your insights in order to keep these materials updated as the law and technology both evolve.
The EDPB and the original author will act as facilitators of this community process, hosting the repository, providing the initial materials, and contributing to the maintenance of community standards. We will soon make available the links to the repository and the code of conduct, and we look forward to your contributions!
Disclaimer
This training material is meant to be updated in light of technological and legal changes. It is, nonetheless, a study material that should not be constructed as legal advice.
The views expressed in the deliverables are those of their authors and they do not necessarily reflect the official position of the EDPB. The EDPB does not guarantee the accuracy of the information included in the deliverables. Neither the EDPB nor any person acting on the EDPB’s behalf may be held responsible for any use that may be made of the information contained in the deliverables.
Some excerpts may be redacted or removed from the deliverables as their publication would undermine the protection of legitimate interests, including, inter alia, the privacy and integrity of an individual regarding the protection of personal data in accordance with Regulation (EU) 2018/1725 and/or the commercial interests of a natural or legal person.
License
The contents of this book are made available under a CC BY-SA 4.0 licence. A summary of your right and obligation can be found at https://creativecommons.org/licenses/by-sa/4.0/