Privacy Law Already Covers AI. The Work Is Putting Purpose Limits in the System, Not the Policy PDF.

Table of Contents

Isabel Hahn and Aaron Alva wrote in Tech Policy Press on August 31 that treating AI as outside ordinary privacy law is a mistake. Hahn is a Berkman Klein Center fellow. Alva is a fellow there too and a former FTC technologist. Their line is blunt: regulators are not inventing an exotic category. They are applying purpose limitation, transparency, and accountable deployment to systems that infer, remember, and act.

Classic compliance lined up collection, use, disclosure, and retention with the privacy policy. AI breaks that map. A model infers facts nobody typed. It summarizes across files. It keeps memory. It ranks. Agents then do work the user did not watch step by step. The harm is not only that personal data went into a model. The system may pick its own inputs, pull more than the task needs, carry data across contexts, and finish an action before anyone sees what moved.

Same principles, harder plumbing

Hahn and Alva point to guidance that already says this in different dialects.

The UK ICO has said AI agents need a clear purpose for what they collect and that choosing which databases an agent can reach is how you do minimization. The European Data Protection Supervisor treats human review of outputs and inferences as an accountability control. Hong Kong’s privacy commissioner has stressed access controls and ongoing risk assessment. Singapore’s PDPC has said scraping personal data from public pages can, in some cases, rest on the publicly available exception rather than fresh consent. Australia’s OAIC has said obligations attach to what goes into an AI system and what comes out.

In the United States they read older FTC orders as design instructions. Rite Aid’s settlement required testing before high-risk AI went live. Drizly put minimization and short retention on the security side of a breach. GM’s connected-car case was about collecting and sharing sensitive data for uses people were not told about. Amazon Alexa was about honoring deletion and keeping deleted voice out of training.

State attorneys general can use existing unfairness and deception statutes even where no AI-specific bill has passed.

Purpose has to be a gate, not a sentence

“We use data to provide and improve the service” is too wide once an agent can open mail, search drives, and send messages. “Help the user” is not a permission to touch every store the company owns.

Hahn and Alva want the limit built into the product: which tools the agent may call, which corpora it may search, which memories it may use, whether data can jump from work to personal context, when a human must confirm, and whether outputs may train a model or feed analytics. That is least privilege with a privacy label on it.

Someone still owns the deployment

Autonomy does not delete the deployer. Pre-launch review that only asks “is the model accurate?” misses the privacy questions: Does the agent reach data outside the task? Does it keep what it should drop? Does prompt injection blow through the boundary? Can you reconstruct what it read, which tool it called, and why? Does it behave differently across groups? What happens when it is wrong?

Those tests belong next to accuracy evals, not in a separate ethics appendix nobody runs.

Notice is late. The control has to sit on the action.

A privacy policy cannot carry an agent that stores memory and acts. Hahn and Alva want memory screens that show what the system kept and let the user edit or delete it. Permission receipts that list what the agent accessed for a job. Confirmations before it sends a message or discloses a fact. Separate personal and work modes. Buttons for “do not remember this” and “why did you use that?”

Those features are how you prove purpose limitation when a regulator asks. They also let a user correct the system before the next task inherits a bad memory.

The authors contrast this with ad tech, where privacy and revenue often pull apart. They think AI can sell trust as part of the product if developers put the limits in architecture instead of hoping a notice covers an agent that already acted. The open question is not whether GDPR, state privacy statutes, or Section 5 still apply. They do. The question is whether the next release ships with tool scopes and a memory dashboard or with another paragraph about “improving the service.”

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.