AI AND DATA PROTECTION LAW

Filiberto Brozzetti, Stefano Pietropaoli

Obiettivi formativi

The course aims to provide students in the Global Law, Business & Tech Major with advanced knowledge of the legal, regulatory, and institutional frameworks governing data protection, data governance, and artificial intelligence, with particular focus on the European Union regulatory model and its interaction with global legal, economic, technological, and geopolitical developments. The course seeks to broaden the professional outlook of students by illustrating how legal expertise in data protection and AI regulation may be applied not only to the interpretation and enforcement of rules, but also to the design of compliance strategies, the assessment of technological risks, the governance of data-driven business models, and the evaluation of the legal implications of emerging AI systems. Particular attention is devoted to the GDPR, EU data regulations, platform regulation, the AI Act, and comparative approaches to data and AI governance in the United States, China, and international organisations. From this perspective, students are trained to understand the interaction between technological innovation, fundamental rights, market dynamics, organisational compliance, and public regulation in a transnational legal environment. Lectures provide the theoretical, legal, and institutional framework for the main topics covered in the course, including EU digital and data strategies, the GDPR, data sharing and data governance instruments, platform regulation, AI definitions and regulatory models, the AI Act, synthetic data, agentic AI, AI supply chains, and the use of data and AI in armed conflicts and military contexts. Seminars, case studies, group work, compliance-oriented exercises, and project presentations enable students to apply the knowledge acquired to concrete legal and organisational problems, while developing analytical, comparative, argumentative, risk-assessment, project-design, communication, and collaborative skills consistent with the interdisciplinary profile of the Global Law, Business & Tech Major of the Bachelor’s Degree in Global Law.

Prerequisiti

None.

Risultati di apprendimento attesi

Knowledge and understanding: By the end of the course, students will understand the legal, institutional and comparative foundations of data protection, data governance and AI regulation, with particular reference to the EU framework and its global implications. They will be familiar with the principles and main mechanisms of the GDPR; international data transfers; the Data Act; the Data Governance Act; the Database and Open Data Directives; the Digital Services Act; the Digital Markets Act; and the AI Act. They will also understand their relationship with fundamental rights, market and platform regulation, organisational compliance, digital sovereignty, and developments including synthetic data, foundation models, agentic AI and AI infrastructures. Applying knowledge and understanding: Students will be able to analyse issues arising from the processing, sharing and use of data and the development, deployment and governance of AI systems. They will identify the applicable framework, roles and responsibilities, obligations and risks, and interactions among data protection, data governance, platform regulation and AI regulation. Through seminars, cases, exercises and group work, they will apply legal reasoning to GDPR compliance, international transfers, data sharing, big-data analytics, automated decision-making, AI Act compliance, synthetic data, agentic AI, AI supply chains, and military uses of data and AI. Making judgements: Through interactive lectures, seminars, case discussions and group work, students will develop critical judgements on the legal, economic, technological, ethical and geopolitical implications of data and AI regulation. They will assess the strengths, limits, practical effects and enforcement challenges of the GDPR, the EU Data Strategy and the AI Act, as well as tensions between innovation and regulation, fundamental rights and market interests, accountability and technological development, and digital sovereignty and global interoperability. They will also evaluate risks relating to profiling, algorithmic bias, opacity, autonomous systems, AI infrastructures and armed conflict. Communication skills: Students will communicate clearly, rigorously and persuasively on data protection, data governance and AI regulation. They will present complex legal issues, explain regulatory implications for institutions, companies and technology providers, justify legal and compliance assessments, and use specialist EU digital-regulation terminology appropriately. They will prepare concise, well-structured analyses, reports and group-project outputs for academic, institutional, professional and multidisciplinary audiences. Learning skills: Students will independently navigate legislation, case law, institutional and policy documents, comparative frameworks, case studies and specialist literature on data protection, data governance and AI. They will update their knowledge in response to legal, institutional and technological developments, pursue further research, and integrate legal, technological, comparative and policy perspectives in addressing complex problems. Transferable skills: The course develops legal, analytical, digital and comparative competences for governing data-driven and AI-based technologies in global legal and business environments. Practical cases, seminars, group work and presentations strengthen risk assessment, problem-solving, project design, collaboration, argumentation, communication and ethical reasoning. Students will learn to work across legal, technological and organisational domains, assess the implications of innovation for rights, markets, institutions and society, and contribute to responsible digital governance in professional, institutional and international settings.

Contenuti Del Corso

1. EU data protection and data governance framework: The course examines the evolution of EU digital, data and AI strategies, with specific focus on the GDPR, data protection principles, data subject rights, governance of personal data processing, international data transfers, and the role of compliance tools such as DPIAs, accountability mechanisms, and data protection by design and by default. 2. Regulation of data sharing, platforms and digital markets: The course analyses the main EU regulatory instruments concerning data access, re-use and sharing, including the Data Act, the Data Governance Act, the Database Directive and the Open Data Directive. It also addresses the Digital Services Act and the Digital Markets Act, highlighting the intersections between data protection, platform governance, competition law and digital market regulation. 3. AI regulation, compliance and emerging technological developments: The course explores the legal definition and governance of AI, the EU AI Strategy and the structure of the AI Act, including risk classification, obligations for high-risk AI systems, compliance mechanisms and critical issues. It also covers the interplay between AI and data, synthetic data, agentic AI, foundation models, AI infrastructures, gigafactories and supply chains. 4. Comparative, geopolitical and security dimensions of data and AI: The course adopts a global and comparative perspective on data and AI regulation, comparing EU, US, Chinese and international approaches. It also addresses the use of data and AI in armed conflicts and military contexts, with attention to international humanitarian law, surveillance, targeting, autonomous weapons systems, accountability and strategic dependencies.

Testi Di Riferimento

The main study materials for the course consist of the lectures, the slides, and the additional materials shared by the Professors on the MyLuiss platform. These materials constitute the primary basis for the preparation of the exam for attending students. The following reference texts are recommended for all students and are compulsory for non-attending students: European Union Agency for Fundamental Rights and Council of Europe, Handbook on European Data Protection Law, Luxembourg: Publications Office of the European Union, 2018, available at: https://fra.europa.eu/sites/default/files/fra_uploads/fra-coe-edps-2018-handbook-data-protection_en.pdf Nathalie A. Smuha, ed., The Cambridge Handbook of the Law, Ethics and Policy of Artificial Intelligence, Cambridge: Cambridge University Press, 2025.

Metodologie Didattiche

Learning: lectures Practice: expert guests, case studies and simulations Discussion: seminars and in-class group discussions Collaboration: small-group work, discussion of others’ findings and development of shared outcomes Production: reports and presentations

Modalità di verifica dell'apprendimento

Achievement of the intended learning outcomes set out in the course objectives will be assessed and verified as follows: 75% of the final grade will be based on participation in, and contribution to, group work. The group project will consist of the development of an AI Agent specialised in the management of legal issues relating to AI and data, on the basis of the specific legislation, case law and regulatory framework of a non-EU jurisdiction. The procedures for carrying out, developing and presenting the group work will be explained and supervised during the course, with the contribution of industry professionals. 25% of the final grade will be based on the discussion, during the oral examination, of an individual thematic in-depth study chosen by the student on one of the topics covered in class. This discussion will assess the student’s ability to analyse a specific legal or regulatory issue, use appropriate sources, develop a coherent argument and communicate the results clearly and rigorously. Non-attending students will be examined orally on the teaching materials and the reference textbooks indicated in the syllabus.

Criteri per l’assegnazione dell’elaborato finale

Interest in the subject matter and individual appreciation of the Chairs.

Settimana 1

1.1 Course introduction: rules of engagement (RoE) and disruptive uses of data and AI technologies Presentation of the course methodology, sources, and assessment criteria. Analysis of the disruptive impact of data-driven and AI-based technologies on traditional legal, economic and social categories. 1.2 Introduction to the GDPR (Prof. Brozzetti) Legal nature, structure, and scope of Regulation (EU) 2016/679. Transition from Directive 95/46/EC and the rationale of the risk-based approach. Territorial scope and extraterritorial application.

Settimana 2

2.1 Evolution of EU strategies on digital, data, and AI (Prof. Pietropaoli) Reconstruction of the EU policy framework from the Digital Single Market Strategy to the European Data Strategy and AI Strategy. Focus on the emergence of “digital sovereignty” as a regulatory paradigm and on the relationship between innovation, competition, and fundamental rights. 2.2 Definitions, principles, lawfulness of processing, and data subject rights (Prof. Brozzetti) Systematic analysis of key definitions (Art. 4 GDPR) and general principles (Art. 5 GDPR). Legal bases for processing (Art. 6 GDPR) and special categories of data (Art. 9 GDPR). Data subject rights as instruments of individual control and their limits in practice.

Settimana 3

3.1 Governance of personal data processing: roles and compliance mechanisms (Prof. Pietropaoli) Allocation of responsibilities among controllers, processors, and data protection officers. The principle of accountability and related compliance tools (DPIA, records of processing, internal policies). Data protection by design and by default as regulatory standards. 3.2 International data transfers and EU–U.S. disputes (Prof. Pietropaoli) Legal regimes governing transfers to third countries (Chapter V GDPR). Analysis of adequacy decisions, SCCs, and BCRs. Case law of the Court of Justice (Schrems I, II and III) and the evolving EU–US data transfer framework.

Settimana 4

4.1 Global comparison of data regulation frameworks (Prof. Pietropaoli) Comparative analysis of EU, US, and Chinese approaches to data governance. Divergences in legal traditions, regulatory objectives, and enforcement mechanisms. 4.2 Use of data in armed conflicts (Prof. Pietropaoli) Applicability of data protection law in situations of armed conflict. Interaction with international humanitarian law (IHL). Legal issues related to surveillance, intelligence gathering, and data-driven targeting.

Settimana 5

5.1 The Data Act (Prof. Brozzetti) Legal structure and objectives of the Data Act within the EU Data Strategy. Access to and sharing of non-personal and industrial data, contractual fairness, and interoperability obligations. Interplay with data protection law. 5.2 Data Governance Act, Database Directive, Open Data Directive (Prof. Brozzetti) Legal frameworks for data re-use and sharing. The role of data intermediaries and data altruism under the Data Governance Act. Protection of databases and the legal regime of public sector information.

Settimana 6

6.1 Digital Services Act (DSA) and Digital Markets Act (DMA) (Prof. Brozzetti) Regulatory architecture for digital platforms. Obligations of online intermediaries and “gatekeepers”. Intersections between platform regulation, competition law, and data protection. 6.2 Seminar: Implementation of data regulations in organizations (Prof. Brozzetti) Case-based discussion on corporate compliance models. Mapping of data flows, risk assessment, and internal governance structures in light of overlapping regulatory regimes.

Settimana 7

Mid-Term Break

Settimana 8

8.1 Definitions of AI and the EU AI Strategy (Prof. Pietropaoli) Technical and legal definitions of artificial intelligence. The EU’s risk-based regulatory approach and its underlying normative assumptions. 8.2 Introduction to the AI Act: principles and structure (Prof. Brozzetti) Scope and architecture of the AI Act. Classification of AI systems according to risk levels. Regulatory techniques (prohibitions, obligations, conformity assessments).

Settimana 9

9.1 Weaknesses and critical issues of the AI Act (Prof. Pietropaoli) Doctrinal and practical critiques of the AI Act. Problems of definition, enforcement, and technological neutrality. Tensions between innovation and regulation. 9.2 Interplay between AI and data (Prof. Pietropaoli) Structural relationship between data governance and AI systems. Issues of training data, data quality, explainability, and accountability. Legal qualification of algorithmic outputs.

Settimana 10

10.1 Seminar: Agentic AI (Prof. Pietropaoli) Legal implications of autonomous and goal-oriented AI systems. Questions of liability, control, and attribution of decisions. 10.2 Seminar: AI gigafactories and supply chains (Prof. Pietropaoli) Legal and geopolitical dimensions of AI production, including access to computational resources, chips, and strategic dependencies.

Settimana 11

11.1 Global comparison of AI regulation (Prof. Pietropaoli) Comparative overview of emerging AI regulatory models (EU, US, China, international organizations). Soft law instruments and global governance initiatives. 11.2 Soft law tools for AI and Data Law Compliance (Prof. Pietropaoli)

Settimana 12

12.1 Mega trends in AI development (Prof. Brozzetti) Analysis of technological and industrial trends (foundation models, generative AI, large-scale infrastructures). Implications for regulation and market structure. 12.2 Seminar: Synthetic data (Prof. Brozzetti) Legal and technical aspects of synthetic data. Assessment of its compatibility with GDPR principles and its role in mitigating privacy risks.