PI’s response to the UK Department for Science, Innovation & Technology on data regulation in the age of AI and other data-intensive technologies

PI responded to DSIT's call for evidence on data regulation and AI, setting out where the UK's data protection framework is working and where it needs improving.

Advocacy

Our submission covers the following topics, following the government's call for evidence:

  • How AI challenges the foundational assumptions of data protection law across the AI lifecycle — training, process and output.
  • The erosion of transparency and data subject rights (access, rectification, erasure, objection) where controllers can no longer identify what personal data they hold, how it's processed, or what it produces
  • Risks from the "mosaic effect", onward identifiability, and proposals to narrow the definition of personal data
  • Changes to automated decision-making (ADM) under the Data (Use and Access) Act 2025, including the shift in burden from controllers to data subjects
  • Regulatory gaps in the UK's AI governance, including uses of AI that should be prohibited outright, such as live biometric identification, sentiment analysis, and behavioural prediction)
  • The intersection of competition and data protection, and the oversight gap around intelligence services' data breaches under the Investigatory Powers Act