← Back to list

AI & Privacy, how to protect data?

Data protection has been at the heart of the digital sphere for years. If the GDPR has made it possible to regulate personal data, collect…

Craft AI Team in Craft AI · 2026-04-27 09:12 · 0 claps · 3.8 min read
#ai #data-privacy #data
Open on Medium ↗
Wiki topics: AI · AI · General 🔒 · Cybersecurity

AI & Privacy, how to protect data?

Data protection has been at the heart of the digital sphere for years. If the GDPR has made it possible to regulate personal data, collect it, and secure its storage, the arrival of AI is redistributing the cards. This technology increases the “attack surface” and creates new privacy challenges.

To address the topic, we had the pleasure of hosting a panel discussion:

  • Paul Mangold — Assistant Professor — École Polytechnique
  • Matthieu BOUSSARD — VP AI — Craft AI
  • Henri CLAUDOT — Director, innovation & collaborative programs — IDEMIA Public Security
  • Isabelle LANDREAU — Data Protection Officer, Group Data Protection Officer — IDEMIA Public Security
  • Jean-Philippe Clément — Deputy Director General for Public Space and Facilities Services — City of Paris

But what is a data?

We often hear about the need to protect your data, data leaks or even GDPR… But what is a piece of data?

A data is simply information (raw or a set of information) that can be stored and then processed to meet different objectives.

Today, each of us gives his information to hundreds of major players who store it and then process it (a piece of data has value only if it can be processed or refined).

The new challenges surrounding data protection

In recent years, artificial intelligence has continued to progress with models that are increasingly efficient. But this technology does not progress by “magic”; indeed, AI models aggregate data and are also trained on it. Moreover, generative artificial intelligence and its more or less controlled adoption reinforce the need to secure data.

Data protection, privacy, confidentiality… What are the differences?

Today, when we talk about data, many terms and regulations come to mind, but not all of them mean the same thing:

  • Privacy refers to personal data. Be careful, not all countries in the world have the same definition of what constitutes personal data (for example, some countries consider that religion is not a personal data while others do) and data is no longer considered personal only if it is actually anonymized (when it is impossible to re-identify the person later).
  • Confidentiality is the act of ensuring that information is only accessible to authorized persons (it is not made public). However, this concept is not defined in the AI act (the European regulation intended to regulate the use of AI); only a few articles are devoted to it and concern the high-risk regimes (patents, trademarks, sensitive information) of generative AI. Hence the importance of privacy by design, which consists in integrating privacy protection from the very first steps of creating a project, rather than thinking about it afterwards. However, the “creators” of the AI solution are required to inform users about the use of their data in a transparent manner (high-risk AI or not) in accordance with the GDPR regulations.

The importance of data in AI models and its flagship applications

It is all the more important to secure data as part of an AI project because without it, the functioning of AI would be impossible; indeed, they are useful in many situations:

  • For example, the company data “Pay by Phone” (a mobile parking payment solution) is used to indicate free parking spaces. Indeed, 25% of the traffic in this area is actually parking… An effective way to reduce and streamline traffic.
  • For the Idemia Entry Exit system installed at 150 border crossing points, biometric and personal data are used for security purposes in order to set up a device that recognizes which people are allowed or not to leave the Schengen area.

What are the risks in case of a data breach?

Who says base gathering millions of personal data says target of choice for cyber attacks… But what are the consequences for the organizations holding this data?

The data leak can have serious consequences for users of a solution (identity theft, change of certain information…). The AI act also provides for sanctions against organizations that have not been able to protect their users’ data, but beyond economic sanctions (which can reach a significant percentage of the company’s turnover at fault) and administrative, the first (and most burdensome) consequence for these organizations will be the poor image they project to their users (lack of trust and security).

How can data be best secured?

In order to prevent data leaks and their use for malicious purposes, each company aggregating data must secure it in different ways:

  • Privacy by design: by putting data protection at the heart of the system’s design
  • Use only data that is really useful depending on the solution (no need for a high-definition camera to simply know if a parking space is full or empty, for example) and find a compromise between confidentiality and the capacity of the solution. This is more precisely called the “minimization” of data.
  • Host the collected data on European servers.
  • Differential privacy: This mathematical technique consists of injecting a slight “noise” (injection of random false information that serves to mask an individual’s real data) into the data to prevent attacks by “re-identification”. Even by cross-referencing several databases, a hacker will not be able to isolate the profile of a specific user within an AI model.

In conclusion

Data is useful in many ways for AI agents, but both organizations and users have best practices to follow to ensure that a solution is safe to use.

For companies, good system security as well as “reasoned” data collection and clear communication about their use to the public are essential, while users must be trained in proper “digital hygiene” and have a “aware” of these solutions (notably generative AIs) by not giving out their personal information openly in their prompts.

To launch your secure AI project, contact our experts!


메타데이터
post_id
c384516a089b
slug
ai-privacy-how-to-protect-data-c384516a089b
url
https://medium.com/craft-ai/ai-privacy-how-to-protect-data-c384516a089b
canonical_url
https://medium.com/craft-ai/ai-privacy-how-to-protect-data-c384516a089b
author_url
https://medium.com/@craft_ai
status
ok
fetched_at
2026-06-10 08:17:25