Why AI Makes Data Protection More Important Than Ever

26/08/2026

I have always been fascinated by emerging technology. Part of working in data protection is trying to keep ahead of the game: understanding not only what technology can do now, but what it might be capable of next, and what that means for the people whose data sits behind it.

Oddly enough, my latest reflection on that came from watching the BBC’s Ann Droid.

Set in a remarkably relatable world that feels like the not-too-distant future, Ann Droid follows Sue, a grieving widow who is given Linda, a second-hand humanoid care robot, by her son to help her continue living independently. Linda is there to monitor her health, provide practical support and, perhaps most importantly, provide companionship. What develops is an unlikely friendship as Sue navigates grief, loneliness and life after the death of her husband. It is funny, but the premise underneath the comedy is remarkably serious.

And perhaps that relatability is what makes the premise so thought-provoking. This isn’t a distant technological future that feels impossible to imagine. Against a backdrop of an ageing population, stretched public services, pressure on social care and rapidly developing AI, it feels entirely conceivable.

But this raises another, perhaps more important, question: what does that technology need to know about us in order to do it well?

We generate extraordinary quantities of data simply by living our lives.

Our phones know where we have been. Apps record our interactions. Smart devices generate logs. Cameras capture our movements. Messages, photographs, searches, purchases and online activity all contribute fragments to an increasingly detailed digital picture of us.

Individually, those fragments may appear insignificant. Collectively, particularly when combined with increasingly sophisticated AI, they can tell a remarkably detailed story.

We already see the evidential power of this in criminal investigations. Physical evidence such as DNA, fingerprints or forensic examination remains enormously important, but digital evidence can help investigators reconstruct the wider picture: location data, communications, searches, photographs, timestamps and device activity can establish patterns, relationships and timelines.

What we sometimes casually describe as “data” can, when pieced together, become a detailed reconstruction of a person’s actions and behaviour.

AI dramatically increases our ability to analyse those fragments at scale.

And that is precisely why conversations about AI cannot be separated from conversations about data protection, privacy and governance.

There is also a practical reality driving much of this innovation. Necessity has always been the mother of invention, and organisations are operating in an environment of shrinking budgets, stretched resources and increasing demand. AI offers genuine opportunities to automate routine work, analyse information more efficiently and allow increasingly limited human resources to be focused where they add the greatest value.

For many organisations, exploring these technologies will become less of a luxury and more of a necessity.

But necessity does not remove responsibility. If anything, pressure to do more with less makes good governance even more important. The temptation to adopt technology quickly cannot come at the expense of understanding what it is doing with people’s data, the risks it creates, or whether its use is necessary and proportionate.

The debate is sometimes framed as though regulation is the thing standing in the way of innovation. I see it differently.

Good governance is what allows us to innovate responsibly.

The more powerful our technology becomes, the greater the importance of understanding what information is being collected, why it is being collected, how long it is retained, who can access it, what else it might reveal and — crucially — what might become possible when that information is combined with other datasets or analysed using technology that did not exist when it was originally collected.

That last point matters.

Data collected today may have uses tomorrow that neither the organisation collecting it nor the individual providing it could realistically have anticipated.

That creates enormous opportunities. It also creates enormous responsibility.

For organisations adopting AI, privacy by design cannot simply mean adding a privacy notice after a system has already been procured. Data protection professionals need to be involved early enough to ask the difficult questions:

  • Do we need this data?
  • What are we actually trying to achieve?
  • Is the processing proportionate?
  • What could go wrong?
  • What happens if datasets are combined?
  • What assumptions is the system making?
  • And can we explain and justify the decisions we have made?

Those questions are not anti-technology.

They are what responsible technology looks like.

Watching Ann Droid reminded me just how much of ourselves now exists in data -often scattered across systems, organisations and devices, but increasingly capable of being brought together and interpreted.

AI will undoubtedly enable extraordinary things.

But the greater our ability to collect, connect and understand information about people becomes, the greater our responsibility to use that ability carefully.But the greater our ability to collect, connect and understand information about people becomes, the greater our responsibility to use that ability carefully.

It may be a cliché.

But in the age of AI, it might also be one of the most important principles of data protection.

Leave a comment

  • With Great Power Comes Great Responsibility:

    Why AI Makes Data Protection More Important Than Ever 26/08/2026 I have always been fascinated by emerging technology. Part of working in data protection is trying to keep ahead of the game: understanding not only what technology can do now, but what it might be capable of next, and what that means for the people…

  • Cyber security is a data protection issue: lessons from the ICO’s ACRO reprimand

    14/08/2026 The Information Commissioner’s Office (ICO) has reprimanded ACRO Criminal Records Office following cyber security failings which potentially exposed the personal information of up to 10,920 people. The case is a useful reminder for organisations that cyber security is not simply an IT issue. It is a fundamental part of data protection compliance, accountability and…

  • Council officer convicted for unlawfully accessing personal data

    24/07/2026 The Information Commissioner’s Office (ICO) has recently highlighted an important reminder for all organisations that handle personal information: having access to a system does not mean you are entitled to access every record within it. A former Herefordshire Council employee has received a suspended prison sentence after unlawfully accessing approximately 490 personal records and…

  • Why Smart Companies Keep Getting Data Protection Wrong

    12/07/2026 The biggest data protection risk? It’s certainty. The organisations most likely to get into difficulty with data protection are rarely the ones asking difficult questions. They’re the ones convinced they’re already compliant. Whether it’s a multinational or a start-up, the mistakes are remarkably similar: Collecting data because they can, not because they need to.…