RE-IMAGINING DATA PRIVACY IN THE AGE OF GENERATIVE AI: CHALLENGES, RISKS, AND REGULATORY GAPS

RE-IMAGINING DATA PRIVACY IN THE AGE OF GENERATIVE AI: CHALLENGES, RISKS, AND REGULATORY GAPS

AUTHOR – DR. PURANJAN PRASAD PAUL* & MISS MADHURIKA DEY**

* ASSISTANT PROFESSOR AT THE ICFAI UNIVERSITY TRIPURA

** RESEARCH SCHOLAR AT THE ICFAI UNIVERSITY TRIPURA

BEST CITATION – DR. PURANJAN PRASAD PAUL & MISS MADHURIKA DEY, RE-IMAGINING DATA PRIVACY IN THE AGE OF GENERATIVE AI: CHALLENGES, RISKS, AND REGULATORY GAPS, INDIAN JOURNAL OF LEGAL REVIEW (IJLR), 5 (14) OF 2025, PG. 1073-1078, APIS – 3920 – 0001 & ISSN – 2583-2344.

Abstract

Generative AI, especially large language models and multimodal generative systems, has transformed content creation, research, and enterprise workflows. Nonetheless, these systems present new and heightened risks to personal data and privacy. This paper synthesises technical privacy harms, including memorising and data leakage, inference, and model inversion, as well as dataset provenance issues. This section evaluates the effectiveness of current legal frameworks, such as the GDPR, U.S. sectoral enforcement, and the EU AI Act/EDPB guidance, in addressing these harms or their shortcomings in doing so. Regulatory gaps persist. The paper, drawing on recent technical and policy literature, argues that conventional data protection regulations and new AI frameworks fail to sufficiently tackle the accountability loop for generative systems. A hybrid strategy is proposed to address this issue. This strategy integrates technical mitigations, including differential privacy, provenance and data lineage, robust access controls, audit logging, and watermarking of synthetic outputs, alongside regulatory reforms. The reforms encompass clarified responsibilities for modellers and data controllers/processors, mandatory dataset provenance, requirements for model transparency, cooperation in cross-border enforcement, and established liability rules. The objective is to develop a regulatory-technical framework that safeguards individuals while maintaining advantageous innovation.

Keywords: Generative AI, Privacy Risks, U.S.Enforcement