Data Protection and Privacy 2025

BELGIUM Trends and Developments Contributed by: Benjamin Docquir and Margo Cornette, Osborne Clarke

ations that might pose risks to health, safety or fundamental rights, as well as the establishment and proper documentation of a post-market monitoring system. This also allows for the eval - uation of continuous compliance of AI systems with the AIA’s requirements. Pursuant to Article 26, Section 6 of the AIA, deployers of high-risk AI systems must retain logs under their control for at least six months, considering the AI system’s intended purpose. When logs are managed by healthcare professionals, it is crucial to ensure that they can be stored long term and that data governance policies are in place to regulate the retention period. Transparency Transparency and explainability are key to foster trust in AI. It is therefore not surprising that the AIA emphasises the importance of these princi - ples several times and imposes various trans - parency obligations. In the context of remote patient monitoring, the following transparency obligations merit consideration by healthcare professionals: • deployers of the high-risk AI systems referred to in Annex III, which make decisions or assist in making decisions related to natural per - sons, must inform the natural persons that they are subject to the use of a high-risk AI system (Article 26, Section 11 of the AIA); and • when using an emotion recognition system or a biometric categorisation system, the deployer must inform the natural persons exposed thereto about the operation of the system (Article 50 of the AIA). Data protection impact assessment and co-operation These obligations are straightforward: deploy - ers must co-operate with the relevant competent authorities in any actions they take concerning

a high-risk AI system to implement the AIA. This co-operation may include providing any request - ed information about the AI system used. In addition, they must comply with their obligation to carry out a data protection impact assess - ment under Article 35 of the GDPR, for which they can use the instructions for use. Fundamental rights impact assessment for high-risk AI systems Article 27 of the AIA provides that, prior to deploying a high-risk AI system as defined in Article 6(2), deployers who are public bodies or private entities providing public services, and those deploying AI systems specified in points 5(b) and (c) of Annex III, must carry out an assessment of the system’s impact on fun - damental rights. The term “public services” is used broadly in the AIA, without clear criteria or further guidance on how to identify such services. This could result in a wider range of organisations being subject to this obligation than expected at first sight. Recital 96 provides some context by listing examples of public services, such as healthcare. As a result, healthcare professionals may find themselves subject to this obligation. Where applicable, healthcare professionals must thus ensure that a fundamental rights impact assessment is carried out prior to the first use of a high-risk AI system, consisting of the fol - lowing elements: • a description of the deployer’s procedures in which the high-risk AI system will be used, in accordance with its intended purpose; • a description of the time period and frequen - cy of the AI system’s intended use; • the categories of natural persons and groups who could be affected by its use;

33

CHAMBERS.COM

Powered by