Artificial intelligence in Peru: a regulatory analysis of the personal data and AI systems lifecycles
DOI:
https://doi.org/10.18800/dys.202601.006Keywords:
Artificial intelligence, Personal data protection, Privacy by design, AI lifecycle, Impact assessmentAbstract
This article examines, through a comparative regulatory analysis, the relationship between the lifecycle of artificial intelligence (AI) systems and the lifecycle of personal data, with a particular focus on privacy and data protection obligations arising at each stage. Using a comparative perspective, it integrates international standards —such as the European Union Artificial Intelligence Act, the General Data Protection Regulation (GDPR), OECD guidelines, and ISO standards— with the Peruvian regulatory framework, stressing the importance of implementing safeguards that allow identifying risks in each stage.
The roles of the main actors —provider, deployer, importer, authorized representative, distributor, and processor— are analyzed to clarify specific responsibilities regarding personal data processing. The article highlights the need to apply the principles of privacy by design and privacy by default, as well as impact assessments and algorithmic audits, to prevent risks such as discrimination, bias, and lack of transparency. Finally, it puts forward recommendations to strengthen the national regulatory framework in alignment with international standards, concluding that a flexible, principle-based regulatory approach, complemented by technical instruments such as ISO standards, is more effective than rigid regulation in fostering responsible and ethical AI implementation in Peru while safeguarding fundamental rights.








