نوع مقاله : مقاله پژوهشی
عنوان مقاله English
نویسندگان English
In the contemporary knowledge-based economy, data has become the most vital asset of companies, and the obligation to maintain confidentiality plays a fundamental role in safeguarding it; this study, adopting an analytical-comparative approach, examines the legal systems of Iran, the United States, and the European Union in addressing modern challenges of information management—particularly the rise of generative artificial intelligence, the complexities of AI prompting, the right to be forgotten, the recognition of the creator of research data, and similar issues—and finds that the U.S. legal system has embraced a property- and contract-based approach in which legal protection is contingent upon demonstrating reasonable protective measures and risk management, with the recent restrictions on non-compete agreements in 2024 shifting the burden of protection onto non-disclosure agreements and proof of non-entry of sensitive data into public AI models, while the European Union, through Directive 2016/943 and data protection regulations, has adopted a regulatory and rights-based paradigm in which confidentiality is treated as part of fundamental rights and public order, with breaches leading to severe administrative sanctions and the introduction of sensitive data into large language models increasingly interpreted as a practical waiver of confidentiality rights; in Iranian law, confidentiality obligations are considered part of the principle of pacta sunt servanda and civil liability rules, with breach potentially giving rise to both contractual remedies and tort liability, and in the era of artificial intelligence, the submission of sensitive data to uncontrolled systems effectively nullifies confidentiality and eliminates legal protection for trade secrets, prompting this study to critique traditional doctrines and propose innovative solutions such as digital duty of care, segmented confidentiality, algorithmic restitution requiring destruction of models trained on misappropriated data, and recognition of loss of control as a new disclosure criterion, while also suggesting a redefinition of confidentiality obligations from a negative duty to an intensified duty of care, shifting the burden of proof in favor of the injured party, and recognizing a duty of result in managing sensitive data, thereby demonstrating that Iranian law is not devoid of protective capacity but suffers from a lack of technological interpretation, with concepts such as property value, rational benefit, possession, trust, and negligence being adaptable to data, algorithms, and AI outputs.
Keywords:
Commitment, confidentiality, non-disclosure, data, information management, artificial intelligence
کلیدواژهها English