2. Artificial Intelligence Ethics and Data Protection
The ethical use of AI is a subject that is not limited to “academic” concepts and theories, but also concerns the daily use of AI in any context, from recruitment and employment, to creativity and productivity, to decision-making. This has necessitated the development and implementation of a comprehensive legal framework and enforceable standards. On a global scale, the most significant step in the direction of AI regulation, was the approach adopted by the European Union in 2024.
As a global leader in AI Ethics and Data Management and Protection, the European Union now addresses AI and data protection concerns systemically, with a commitment to safeguard all citizens against associated risks while ensuring that innovation remains uncompromised.
2. a. AI Act of the European Union
In 2024, the EU introduced the AI ACT (EC 2024), the world’s first comprehensive AI law. The EU AI Act establishes harmonised rules for how AI systems are developed, deployed, and used across all EU member states. The main goal of the Act is to ensure that AI use is safe, transparent, and respects fundamental rights while still encouraging innovation and economic growth. The law applies to companies based in the EU and to any organisation worldwide whose AI systems affect people within the EU itself.
The 2024 EU AI Act is risk-based regulation; this means that the level of oversight depends on how much an AI system can impact people’s lives (EU AI ACT 2024). The table below summarises the risk-based classification of AI systems:
| Risk-based AI Classification | |
|---|---|
| Unacceptable Risk AI (Banned) | These systems are considered a threat to fundamental rights and are prohibited. Examples include:
|
| High-Risk AI | High-Risk AI systems are allowed but are strictly regulated and must adhere to standards regarding the use of accurate and consistent data collection, systemic implementation of documentation and transparency measures, human oversight and strong cybersecurity measures. Examples include AI used in:
|
| Limited Risk AI | Chatbots and Content Recommendation Algorithms are considered “limited risk” AI systems. They must meet clear transparency obligations, such as:
|
| Minimal Risk AI | This AI category refers to everyday applications like spam filters or video game AI, which are unlikely to negatively affect people’s lives. face minimal regulation. Minimal risk AI is deliberately left unregulated by the EU to avoid obstacles to experimentation and technological development. |
The AI Act requires organisations that develop or use AI to assess and classify their AI systems by risk, implement transparency by informing users about AI use/features, and maintain human oversight and risk management procedures. Companies that do not adhere to the AI Act regulations may face severe fines of potentially up to €35 million or 7% of their turnover.
Finally, the EU AI Act is implemented and works alongside the EU Accessibility Act. Especially in cases of development and deployment of AI-powered recruitment and performance appraisal software that are categorised as “High Risk” systems, the EU AI Act dictates that all new AI technologies and services should ensure “full and equal access for everyone, including persons with disabilities, in a way that takes full account of their inherent dignity and diversity” (EU AI ACT 2024). This can be achieved through active engagement and testing with vulnerable stakeholder groups during development, and the implementation of digital accessibility features in software as a mandatory requirement.
2. b. Artificial Intelligence: Ethics Related to Day-to-Day Use
In essence, the ethical use of artificial intelligence in everyday work environments is reflected in the decisions and actions of employees, where most interactions with AI occur at a routine level through tools used for communication, data processing/analysis/reporting, content creation, and decision support. Therefore, the ethical use of AI becomes a practical responsibility, and it concerns all professionals regardless of their role, position or level of technical expertise.
As AI systems often use and rely on large amounts of data, including personal and sensitive information, their use is closely linked to data protection principles (see GDPR section 2. c., pp. 9 - 10). Additionally, a key aspect of day-to-day AI ethics is accountability. Accountability refers to taking responsibility for how AI tools are used in our work, reviewing outputs, verifying and applying them accordingly; AI systems should not be treated as fully autonomous decision-makers.
Similarly, transparency regarding the use of AI plays an important role in maintaining trust both internally and externally. This means that job applicants, colleagues and clients should be aware when AI is being used, particularly in situations where communication and decisions are influenced by it. One example of such use of AI is the integration of chatbots into companies’ websites that automatically respond to client inquiries. In such cases, the clients must be explicitly informed that they are interacting with a chatbot.
By understanding the ethical implications of routine interactions with AI technologies, professionals can help prevent risks associated with them. The following short scenarios illustrate how common workplace practices can give rise to ethical challenges in the use of AI:
Scenario 1: The social media manager of an NGO for Families of People with Disabilities uses features of the NOTION AI writing toolkit to generate text for social media posts and articles. As time is of the essence and considering that the followers of the NGO on social media are not likely to fact-check and cross-reference the content of the posts, the manager becomes accustomed to copy-pasting the texts without quality checks. Over time, they realise that the engagement of followers with the posts of the social media page is considerably lower. This scenario demonstrates that generic content generated by AI may fail to capture the attention of readers in the long-term. Indeed, AI can help generate content faster, but users must be aware that the “raw” AI-generated content is not unique to a particular user and often is quite “stale” and generic.
Scenario 2: A young recruiter relies entirely on the AI-powered CV screening system of LinkedIn to shortlist candidates, without understanding how the system evaluates applicants. As a result, qualified candidates are excluded due to data bias. This scenario demonstrates a “classic” case of AI algorithm bias, where hundreds, if not thousands, of candidates apply for the same position via LinkedIn. Many qualified candidates are automatically rejected due to a lack of “AI-proofing” in their CVs and Cover Letters. “AI-proofing” involves optimising CVs and Cover Letters with relevant keywords, formatting and phrasing so they perform well in automated applicant tracking systems and AI screening tools.
Scenario 3: A member of an internal HR team uploads employee performance data into a public, freely available AI platform to generate performance summaries and reviews. The privacy statement on the website hosting the platform explicitly states that the information entered by the users is processed externally, which means that the data is potentially exposed to third parties with unknown motives. This scenario represents a breach of data confidentiality and improper handling, as sensitive information should not be shared with unsecured AI platforms.
Scenario 4: A digital marketing assistant uses Bing AI to generate images and content for a promotional campaign of an online store without reading the Terms of Service, and is therefore unaware that even though it is legal to sell the images, the client does not acquire copyrighted materials. This means that other companies and even competitors can use the same images for their own campaigns.
Scenario 5: A 60-year-old manager of a small family-owned electronics store recently came across ChatGPT and casually spends time interacting with it. He is now accustomed to entering qualitative employee information and asks ChatGPT to assess their performance. The manager just dismissed the recently promoted assistant manager, who has been working in the shop for the past 10 years, based solely on the achievement of individual sales targets. The fact that the new assistant manager has been dedicating their time to training and mentoring new employees has not been considered. As unlikely as it looks, in 2025, a survey with over 1300 employers across various sectors in the USA (GCND 2025) indicated that over 60% of them use AI to determine lay-offs, with approximately 6% of them stating that they implement AI decisions without an intervention by a human expert. Unfortunately, there is no data to represent the EU in this regard.
As seen above, ethical issues in AI often arise from how the technology is used, rather than the technology itself. Some general AI ethics guidelines that apply to everyday professionals include:
Consistent review and verification of AI-generated outputs before using or applying them in actual work
AI should not be relied on for important decisions, especially decisions affecting people’s careers and livelihoods
Uploading confidential information and personal data into unsecured AI platforms should be avoided
Awareness of potential biases in AI algorithms, and systematic verification of the results
Transparency must be upheld when using AI, by disclosing AI-generated content when necessary
Finally, all professionals should familiarise themselves with internal organisational policies regarding the use of AI and relevant ethics. Many companies have introduced AI governance frameworks that outline acceptable use, risk management and accountability structures with the aim to promote responsible use of this new technology.
AI is first and foremost more “Artificial” than “Intelligent”.
AI-generated content contains errors, biases, and incomplete information. Making decisions based on AI-generated results without critical evaluation can lead to poor decisions and often, unintended consequences.
2. c. General Data Protection Regulation (GDPR)
Enforced since 2018, the General Data Protection Regulation (GDPR) is the cornerstone of data protection and privacy law within the European Union. GDPR was designed to standardise data protection laws across EU member states, while strengthening the rights of citizens by giving them greater control over their personal data. GDPR applies to organisations established within the EU, as well as organisations outside the EU that process the personal data of EU residents (EC 2026). A significant aspect of GDPR is its focus on accountability and governance. People and organisations who collect and process personal data must not only comply with the regulation but also be able to demonstrate compliance. This includes measures such as maintaining detailed records of processing activities and conducting Data Protection Impact Assessments. To ensure the implementation of GDPR, many organisations appoint a Data Protection Officer to oversee compliance.
GDPR is closely linked to the EU AI ACT due to the fact that AI systems rely solely on data entered by users to be “trained”, and to generate results. GDPR is built upon seven fundamental principles which guide all data processing activities and ensure that personal data is handled responsibly. Specifically:
- 1. Lawfulness, Fairness, and Transparency: whenever someone processes personal data, they should have a good reason for doing so. According to GDPR, valid reasons for personal data processing may be the drafting of contracts, fulfilling legal obligations and protection of vital interests of a person. People and organisations that process personal data must secure explicit consent before doing so.
- 2. Purpose Limitation: The purposes for processing data must be clearly established and communicated to people through a privacy notice. The processing of personal data must be limited to the set purposes only.
- 3. Data Minimisation: only the data necessary for a given purpose should be collected, reducing the risk of leaks and misuse. In general, data such as phone numbers and home addresses should never be collected unless it is deemed necessary.
- 4. Data Accuracy: organisations and people who collect and process personal data should implement measures to correct and erase incorrect data, and have regular audits by GDPR experts.
- 5. Storage Limitation: The length of time for storing personal data must be clearly defined and justified. People and organisations who store and process personal data should establish mechanisms for deleting and/or anonymising data after set periods of time.
- 6. Integrity and Confidentiality: personal data must be kept secure from internal or external threats such as unauthorised or unlawful processing and accidental loss, destruction, or damage.
- 7. Accountability: appropriate measures and records must be in place as proof of compliance with the data processing principles, and supervisory authorities can ask for this evidence at any time.
GDPR is enforced by national supervisory authorities within each EU member state, coordinated by the European Data Protection Board. These national authorities have the power to investigate complaints, conduct audits, and impose administrative fines. As is the case with the AI Act of 2024, companies that breach GDPR face significant penalties of potentially up to €20 million or 4% of their annual turnover.
2. d. GDPR Awareness: A General Responsibility
It is important to remember that, regardless of their position and responsibilities, every professional can potentially act as a safeguard or weak link in the data security chain. Therefore, the implementation of GDPR is not the sole responsibility of IT experts and IT departments. Everyone should be aware of common security threats and how to avoid them. Data breaches do not only refer to organised hacking attacks against large companies, but also small, everyday incidents that may seem insignificant to the average employee. For example:
- 1. Scenario: An office administrator working in a small insurance company receives what appears to be a legitimate internal email asking them to verify the records of a new client. Believing that the request is authentic, they click the link and enter their CMS login credentials, giving the attacker access to a database containing personal client information, including names, addresses, and insurance policy details. This is a classic example of a “phishing” attack.
- 2. Scenario: A project manager at an international marketing firm prints a list of client contacts in preparation for a meeting. After the meeting, the documents are left overnight on a desk in the conference room, where unauthorised staff members can access them. This scenario describes a breach of Confidentiality, as personal data was exposed due to insufficient handling and storage practices.
- 3. Scenario: An intern psychologist working at a local hospital transfers patient data from the hospital system to a personal USB drive to prepare some reports at home. The drive is not encrypted and is subsequently lost during transportation. This scenario describes a violation of data processing security and a breach of confidentiality. Personal data must not be transferred to unsecured devices under any circumstances.
- 4. Scenario: The general director and senior lawyer of a small, family-owned law firm sends a case file containing personal client data to a colleague via email, but accidentally types the wrong email address. The email goes to an external recipient who has no connection to the firm. In this case, the firm must immediately notify the supervisory authority and the affected client/clients.
- 5. Scenario: A receptionist at a financial consulting institution throws away printed forms containing clients’ personal details without shredding them. The rubbish bin was picked up by the external cleaning contractor and removed from the premises. Failure to securely destroy sensitive documents constitutes a severe breach of GDPR. The firm must immediately notify the supervisory authority and the affected client/clients.
As the scenarios above show, GDPR breaches are significant, no matter how big or small they are perceived to be. Most data breach incidents are caused by human error, regardless of someone’s position in the organisational hierarchy pyramid. Some general GDPR-related tips that apply to everyone are the following:
Use of strong, unique passwords which should never be shared with others
Establishment of two-factor authentication when available, and all devices and apps must be kept up-to-date
Only permitted information should be shared
Confidential information should not be shared on public sites, and clients or co-workers should not be discussed in open events and communal areas
Email containing personal data should be flagged and deleted once the data is no longer needed
All electronic devices should be screen-locked even when not in use for brief periods of time
Issues or suspicions of fraudulent messages that may not be genuine should not be opened under any circumstances, and IT departments should be informed.
Portable storage like USB drives should be encrypted and never be used to transport sensitive data unless it is absolutely necessary
Members of staff should ask their employer or supervisor about available training resources and opportunities on GDPR and AI Ethics
In addition to the aforementioned tips, all professionals should familiarise themselves with internal company policies. Internal security and data protection policies usually describe data classifications, data storage and sharing procedures, reporting measures/protocols and appointment of internal contact people responsible for GDPR-related matters. GDPR requires companies to report data breaches to the authorities within 72 hours of identifying an incident. In cases of incidents caused by human error, employers should adhere to “no-blame” policies; if employees are hesitant to report incidents for fear of the consequences, the short and long-term impact of unreported data breach incidents can be extremely costly.