The content you scroll through on social media every day, the videos that keep you watching until the end, the ads that pop up as if they know exactly what you want, much of this is shaped by AI-powered processing designed to tailor content to your preferences, based on your likes and repeated viewing of certain content.
However, the use of AI in curating content raises a concern: AI maybe capable of inferring sensitive personal data, such as political opinions, health data, or religious beliefs, from ordinary social media behavior that may appear harmless on their own.
This article invites readers to explore how AI processes data, along with the legal definition of “sensitive personal data” under personal data protection law, and precautions that everyone, as a data subject, should be aware of.
Each platform has its own approach to curating content for users' feeds, depending on the type of content and its business objectives. What they share in common, though, is that the system builds an interest profile for each user based on a variety of behavioral signals, such as how long a user watches a piece of content, likes, shares, and comments. A key feature of this process is that it is personalized: two users who follow the same account may see completely different feeds, because the system tailors results to each individual's profile. For example, TikTok uses a recommendation system known as “For You Page” which is known for its ability to learn a user’s interests quickly from just a few behavioral signals, even before the user follows any accounts. Meanwhile, Facebook’s News Feed ranking system considers the relationship between the user and the poster, the type of content, and past engagement patterns to predict which content a user is most likely to be interested in.
Although none of the data processed in this way is inherently sensitive, the resulting output may nevertheless reveal or enable the inference of sensitive personal data. For example, liking pages or posts related to a political party, politician, or specific policy issue may enable a system to infer or predict a user’s “political opinions.” Similarly, consistently following pages or groups related to a particular religion or belief system may enable the system to infer a user’s “religious beliefs”.
Thailand's Personal Data Protection Act B.E. 2562 (2019) (PDPA) defines categories of “sensitive personal data” under Section 26, including data related to racial, ethic origin, political opinions, cult, religious or philosophical beliefs, sexual behavior, criminal records, health data, disability, trade union information, genetic data, and biometric data.
Section 26 shows that this type of data is highly sensitive. If leaked, it could lead to discrimination against the individual, which is exactly why the law affords it special protection.
The next question to consider is whether data that AI may be considered sensitive personal data under the law. PDPA does not directly address “inferred data”. However, the definition of “personal data” refers to data about an individual that enables that individual to be identified, whether directly or indirectly.
Therefore, if data inferred by AI that can identify an individual may qualify as “personal data” under the law. And if the outcome of AI processing falls within the categories listed in Section 26, such as data relating to racial, religion, health, or sexual behavior, it may be considered processing of “sensitive personal data”, even if that data was never directly disclosed by the data subject.
In 2016, ProPublica revealed that Facebook allowed advertisers to target or “exclude” users based on an “Ethnic Affinity” category. In other words, Facebook let advertisers choose to show or hide ads from users based on their apparent ethnicity, even though Facebook did not directly collect users’ ethic data, but instead inferred it from general online behavior.
Another example is the Meta v. Bundeskartellamt case, which, among other issues, addressed concerns about how Facebook could process or obtain sensitive personal data without users’ knowledge or consent. Under Facebook’s privacy policy, users who sign up for its platform may also be subject to data collection from its other services as well, including Instagram, WhatsApp, Oculus, and Facebook Business Tools. This may allow Facebook to obtain or infer sensitive personal data through less obvious channels, such as Facebook Business Tools embedded in third-party websites. A single visit to a political party’s website might not reveal much about a person’s political stance, However, repeated visits, combined with interactions with embedded Like and Share buttons, may lead to inferences about the individual’s political opinions, especially when combined with other data points that Facebook already holds.
Social media users, who are the data subjects, often accept platform terms and conditions without reading the details of whether the platform uses behavioral data to “infer” personal characteristics, such as interests or consumption habits. If such inference extends to sensitive personal data, the platform may be required to obtain “explicit” consent.
Therefore, if a data subject feels that content curation or ad targeting is crossing privacy boundaries, or may involve personal data they never disclosed or consented to have used, they can exercise their legal rights, such as the right to withdraw consent or the right to object to processing.
Basic practices to help protect one’s privacy include:
The key challenge for organizations is not just considering “what data the organization collects”, but also “what the organization can infer from the data it already has”, and for what purpose that inferred data is used.
Organizations should consider at least the following:
Reference