BELGIUM Trends and Developments Contributed by: Benjamin Docquir and Margo Cornette, Osborne Clarke
• the specific risks of harm likely to have an impact on the categories of natural persons or groups of persons, considering the instruc - tions of use given by the provider; • a description of the implementation of human oversight measures according to the instruc - tions for use; and • the measures to be taken if these risks materialise, including internal governance and complaint mechanisms. The AI Office is responsible for developing a template questionnaire to assist deployers in fulfilling their obligations. The Interplay Between the AIA and the GDPR Remote patient monitoring involves the collec - tion and processing of a large amount of person - al (health) data. As a result, remaining compliant with both is a must for healthcare profession - als. An extensive discussion of the interplay between the AIA and the GDPR is beyond the scope of this article, so the following is only a general overview of the similarities between the two regulations. Scope of the GDPR and the AIA The GDPR applies to: • an entity that processes personal data if it is established in the EU, regardless of where the actual data processing takes place; or • an entity that is established outside the EU if it processes personal data in connection with offering goods or services to individuals in the EU or monitoring the behaviour of individuals in the EU. This contrasts with the material scope of the EU AI Act, which is centred on the definition of an AI system. The material scope of the EU AI Act extends to providers, deployers, importers, dis -
tributors and authorised representatives. Unlike the GDPR, the EU AI Act includes a detailed risk categorisation framework that imposes different obligations depending on the risk level of the AI system. Most of the obligations under the EU AI
Act apply to high-risk AI systems. Roles under the GDPR and AIA
Healthcare professionals using AI systems must consider their roles under both the GDPR and the AIA. This is crucial, as different obligations under the GDPR and AIA may apply depending on their qualification. The GDPR makes a distinction between con - trollers and processors, with controllers being responsible for the strictest levels of GDPR com - pliance. The AIA distinguishes between different categories of actors, such as providers, deploy - ers, distributors, importers, etc. The provider and the deployer are the most important roles in practice. Consider a physician in a hospital using an AI system to remotely monitor a patient’s mental health. In this scenario, the physician (or the healthcare organisation employing the physi - cian) is using the AI system in his or her prac - tice, making him or her a deployer under the AIA. The physician is responsible for ensuring that the AI system is used in accordance with the AIA’s requirements. Simultaneously, the physi - cian is collecting, using and managing personal mental health data to provide medical services. This makes him or her a controller under the GDPR, as he or she determines the purposes and means of processing personal data. As a result, he or she must ensure compliance with the obligations under the GDPR.
34
CHAMBERS.COM
Powered by FlippingBook