New OECD report examines neural data governance issues

The new analysis outlines key concerns related to the privacy of brain data, while offering policy recommendations for safeguarding and securely using such data for research and commercial purposes.

Contributors:
Alex LaCasse
Staff Writer
IAPP
Neurotechnology that can interpret various human brain signals stands to offer a wide range of medical and scientific breakthroughs. However, the sensitive nature of brain data and the advancement of this novel technology being supercharged by artificial intelligence are leading to greater pushes for safeguards on how such data can be used in different clinical and commercial applications.
The Organisation for Economic Cooperation and Development recently shared key findings from its new paper focusing on governance strategies for neurodata. The paper was developed by two policy groups within the OECD, one comprised of officials from national data protection authorities, privacy professionals and other digital experts, and the other group was primarily comprised of neurotechnology experts.
"Across the growing (neurotechnology) ecosystem, neurodata are becoming a valuable resource for research, product development, personalization, innovation and underpinning many of the new capabilities that new technology can offer," OECD Policy Analyst Laura Kreiling said during a webinar unpacking the findings. "But as the industry expands and (integrates) with AI and other technologies, understanding how new data are generated and used becomes increasingly important for effective governance."
What OECD found
The paper explores how neurodata is collected and processed in a number of applications. Regulators who contributed to the project shared their experiences in an effort to support evidence-based policymaking. The paper also outlines policymaking efforts by global institutions taking an active role in developing international and interoperable frameworks for neurodata governance, such as those being developed by the Council of Europe, the U.N., UNESCO, the ISO and the IEEE.
The paper features a study that engaged 16 firms that develop neurotechnologies for various applications located across six OECD countries.
Christina Michelakaki, another OECD policy analyst, said in the current neurotechnology landscape, "neurodata serves very different functions across companies," where scientific researchers are using different types of neurotechnology tools than those used in clinical settings, for instance. The wide-ranging uses for different types of neurotechnology produces different types of neurodata, she added, and more critically, that creates a larger array of privacy risks.
The 16 companies participating in the study generally classify different types of data into four main categories: Non-physiological data, physiological data, "inferred data," which could encompass AI models interpreting brain activity data to draw conclusions about an individual's emotions, and ancillary data, such as medical device metadata.
"Because your data is collected, processed and monetized in such different ways, a one-size-fits-all approach isn't likely to be effective," Michelakaki said. "Instead, governance frameworks should be sensitive to the specific context, purpose and risk profile of different neurotechnology applications. Governance challenges increase as data moves between actors and purposes, and clarity on roles is necessary."
Perseus Strategies Managing Director Jared Genser, who also serves as outside general counsel to the Neuro Rights Foundation, said "dozens" of commercial entities developing consumer neurotechnology products that use varying forms of brain data.
"In our view, we're recommending starting by protecting neural data and the inferences coming from it as sensitive data from the start, as this is the approach the United Nations is converging upon," he said. "What I found most interesting (in the report) was the mismatched regulatory engagement. The 16 participating companies reported interactions with medical device regulators, while almost none reported engagement with data protection authorities."
Potential policymaking and enforcement
Despite the novel sensitive data governance concerns raised by neurodata, global regulators are taking various proactive steps to ensure safeguards will be in place as uses for such data expand.
U.K. Information Commission Principal Policy Advisor for Emerging Technology Robert McCombe said the IC has sought to provide "regulatory certainty" surrounding neurotechnology, while the latest commercial neurotechnology devices are not yet widely available and widely used among consumers. The agency has been a part of the fourth round of the U.K. government's regulatory pioneers project in partnership with Nestor's Center for Collective Intelligence to engage stakeholders and the public about the potential of neurotechnology.
McCombe said the goal of the regulatory pioneer project is to build up the agency's "academic understanding" of neurotechnology and then develop formal guidance with their base of knowledge. The IC is targeting early 2027 to send neurodata privacy guidance out for public consultation.
"It's a rare opportunity, given where the sector is at," McCombe said. "We are offering what we hope will be great regulatory certainty around privacy and data protection."
The report also contains five overarching policy recommendations for implementing safeguards around uses of neurodata for countries to pursue.
The OECD's Michelakaki said the recommendations include introducing regulations that clarify neurodata policy with respect to designating controller and processor responsibilities and provide certainty on neurodata classification; strengthening data infrastructure by implementing common standards and secure data sharing mechanisms, and improving international cooperation.
"Effective governance should be risk-based, context-specific, innovation-friendly and privacy protective," she said.
On AI, Michelakaki said technologies have "started to become very central to neurotechnology." Ongoing uncertainty surrounding legal frameworks governing medical devices and data privacy are being compounded by data governance concerns when AI is introduced into the equation.
"Technological progress is moving faster than regulatory guidance, and adaptive AI systems face regulatory and legal uncertainties," Michelakaki added. "Most companies did identify ongoing uncertainty around neurodata classification and interaction between medical device, AI and privacy frameworks as areas where greater clarity is needed."

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.
Submit for CPEsContributors:
Alex LaCasse
Staff Writer
IAPP



