30
10.1163/22131035-14020001 | enigbokan
4.2.3
Possible Mitigation Strategies
One way to mitigate the risk of privacy is to conduct privacy impact assessments
(pia) during the planning stage. pia involves a detailed legal analysis of how
data is collected, processed, stored, and deleted, identifying risks to privacy at
each stage. It also requires evaluating the necessity and proportionality of data
processing, ensuring that only the minimum amount of data necessary for the
objectives is used. Conducting pia s can help identify potential privacy issues
in order to respond with appropriate control measures on time to mitigate the
risk before they become real problems.169
Other possible mitigation strategies include but are not limited to the
following: anonymising and encrypting data can also protect user identities,
making it harder to re-identify individuals and prevent unauthorised access
to confidential information. Encrypting data renders it unreadable to
unauthorized parties, ensuring that even if data is intercepted, it remains
incomprehensible and unusable.170 It is important that developers adhere to
industry best practices and standards, such as the use of strong and unique
encryption keys, regular security audits, and continuous monitoring of security
controls. This proactive approach to data security can significantly reduce the
likelihood of data breaches and unauthorised access. Implementing robust
data protection policies is also critical to safeguard sensitive information.171
Human oversight is necessary to prevent errors and ensure the reliability
of information.172 One concern, however, is that decision-makers may assume
the provided information is accurate and fail to verify it. Additionally, they
may face organisational barriers such as time constraints or pressure from
upper management.173 As a result, instead of verifying accuracy critically, they
‘rubber-stamp’. Rubber stamping can result in the decision-makers erroneously
taking into account wrong information.174 Appropriate oversight and further
verification is necessary to mitigate these challenges.
169
170
171
172
173
174
Krishnapriya Agarwal, ‘How to Mitigate Privacy Issues With ai: Best Practices’ 9
February 2024 <https://www.spotdraft.com/blog/mitigating-privacy-issues-around-ai>
accessed 30 September 2025. See also European Union Artificial Intelligence Act 2024.
Madaoui Nadjia, ‘The Impact of Artificial Intelligence on Legal Systems: Challenges and
Opportunities’ (2024) 164 Problems of Legality 285–303, at 297–299.
Ibid.
Ludivine Stewart ‘Fair and Efficient Asylum Procedures and Artificial Intelligence: Quo
Vadis Due Process? (2024) 55 Computer Law & Security Review 7.
Niklas, (n 50) at 520,521.
Stewart, (n 172) at 7–8.
International Human Rights Law Review (2025) 1–31