← Pubblicazioni / Publications

Monografia / Book

Neuroprivacy. Problemi teorici e prospettive costituzionali

ENGLISH TITLE

Neuroprivacy: Theoretical Problems and Constitutional Perspectives

Giappichelli · 2023 · 314 pp. · ISBN 979-12-211-0157-7


Citazione italiana

F. Cirillo, Neuroprivacy. Problemi teorici e prospettive costituzionali, Collana Law and Legal Institutions, vol. 10, Giappichelli, Torino, 2023, 314 pp.

Chicago style

Cirillo, Francesco. Neuroprivacy. Problemi teorici e prospettive costituzionali. Law and Legal Institutions 10. Turin: Giappichelli, 2023.

Nota sull’estratto. Il PDF disponibile in questa pagina non riproduce il volume integrale. Contiene l’indice e una selezione limitata di pagine significative dalla versione dell’autore. Il volume completo è disponibile presso l’editore.

Extended Abstract

Page references correspond to the internal pagination of the published volume, not to the sequential page numbers of the PDF file.

Introduction

Neuroprivacy: Theoretical Problems and Constitutional Perspectives examines the relationship between data protection, neuroscience, neurotechnology, and individual freedom through an interdisciplinary inquiry that begins with the concepts of data and information and concludes with a discussion of cognitive liberty. Published in 2023 and developed from research conducted during the immediately preceding years, the book reflects a period in which the debate over so-called neurorights was gaining increasing prominence, while the legal regulation of neural data and technologies capable of recording, inferring, or modifying mental processes still largely depended on the extension of pre-existing legal categories. The book does not therefore present a complete theory of neuroprivacy. Rather, it reconstructs some of the conceptual and regulatory problems that make its formulation possible—and perhaps necessary.

The initial question concerns the ability of public and private actors to collect increasingly detailed information about individuals, deriving it not only from their statements or deliberate actions but also from the traces they leave in digital environments and, potentially, from the direct or indirect observation of brain activity. The growing availability of such information could make it possible to predict tastes, preferences, and behaviour and, at least under certain circumstances, to intervene in the conditions under which individual decisions are formed. The problem, however, is not simply the disclosure of confidential information. It also concerns the use of data that remain formally secret but are processed to classify, anticipate, or influence behaviour. For this reason, the issue is situated at the intersection of privacy, data protection, personal autonomy, and freedom (Introduction, pp. III–X).

The book takes as its starting point the difficulty of clearly separating these dimensions. Privacy may be understood as the protection of a sphere shielded from external interference; data protection concerns the legal conditions governing the processing of information relating to individuals. Cognitive liberty, finally, provisionally designates the individual’s interest in ensuring that their mental processes are not unlawfully observed, reconstructed, or influenced. None of these three notions appears sufficient, when considered in isolation, to describe the phenomenon as a whole. At the same time, it cannot be assumed that their overlap necessarily requires the recognition of an entirely new fundamental right. One of the questions running through the book is precisely whether technological transformations call for new legal categories or, instead, for a different interpretation and combination of existing safeguards.

The concept of neuroprivacy is employed as a synthetic category, rather than as an already established legal definition. As a first approximation, it encompasses the protection of information relating to brain activity and mental processes, as well as the broader problem of the effects that processing such information may have on individuals. The protection of neural data constitutes the most immediately recognisable core of the problem, but does not exhaust it. An adequate legal framework would also need to consider inferences drawn from data that are not strictly neural, secondary uses of information, asymmetries between those who produce data and those who interpret them, and the consequences of technologies capable of affecting cognitive processes.

The structure of the book follows a progression from data to freedom. Chapter One examines the concepts of data and information; Chapter Two reconstructs the evolution of privacy and data protection, with particular attention to health data; Chapter Three considers the regulation of scientific and neuroscientific research; Chapter Four discusses neurotechnologies, neurorights, and the possible construction of neuroprivacy; and Chapter Five examines cognitive liberty and its problematic relationship with free will. This sequence is not intended to demonstrate that freedom can be linearly deduced from data. Rather, it shows how the definitions adopted in the initial stages affect the identification of the interests and safeguards examined in the subsequent chapters.

The method is explicitly interdisciplinary. Constitutional inquiry is accompanied by historical and theoretical reconstruction and by engagement with computer science, information theory, biology, neuroscience, and the philosophy of mind. This openness inevitably entails risks: the same terms carry different meanings across disciplines, and the transfer of scientific concepts into law can generate misleading analogies. The book treats this difficulty not as a marginal inconvenience but as part of its subject matter. Legal categories cannot simply be derived from the empirical sciences; at the same time, a legal framework for neurotechnology developed without at least some understanding of its scientific foundations risks addressing poorly defined objects or attributing capabilities to technologies that they do not possess.

The perspective adopted in 2023 attached a certain urgency to the construction of new safeguards. Viewed retrospectively, that position may be expressed more cautiously. Technological development does not necessarily follow a linear progression towards an ever greater capacity to “read the mind”; many applications produce noisy, probabilistic, and context-dependent data. The actual capacity to influence behaviour causally must also be assessed on a case-by-case basis. This does not eliminate the legal problem, but it suggests that at least four situations should be distinguished more precisely: the recording of neural activity; the inference of mental states; the probabilistic classification of individuals; and interventions in cognitive processes. The risks, interests, and applicable rules may differ considerably across these cases.

Chapter One – Data and Information

The first chapter examines the concepts that form the basis of the entire inquiry. “Data” and “information” are terms employed daily in law, technology, and ordinary language, but they do not possess a single meaning. The chapter shows that the available definitions depend on the scientific paradigm within which they are formulated and cannot be transferred automatically from one discipline to another. This is not merely a terminological issue: the definition of data also determines the boundaries of the object receiving legal protection (pp. 1–7).

The first problem concerns the distinction between data and information. Data may be described as differences, values, signs, or representations capable of being recorded and processed. Information may instead indicate the content communicated or derived through the interpretation of one or more data. Although useful, this distinction is not absolute. A piece of information may become the data input of a subsequent operation; the same sign may be informative in one context and meaningless in another. The relationship between data and information therefore appears functional and dependent on the cognitive operation under consideration, rather than grounded in a stable ontological distinction (pp. 1–7).

The chapter then examines “referability”, meaning the relationship between data and the reality to which they are taken to refer. This relationship is particularly important in law, which defines personal data as any information relating to an identified or identifiable natural person. The legal concept therefore presupposes a connection between an informational element and a particular individual, but does not always explain how that connection should be reconstructed. Data may identify a person directly, acquire identifying capacity through their combination with other elements, or merely support probabilistic inferences. The boundary between personal and non-personal data is consequently variable and depends on the technological context, the resources available, and the operations that can realistically be performed (pp. 8–12).

The difficulty of referability also emerges from the comparison with the physical sciences. In information theory, informational content may be measured independently of its meaning and its relationship with a particular person. The quantity of information concerns the reduction of uncertainty within a system, rather than the semantic truth of a statement or the legal relevance of its content. Mathematical and physical notions can explain the transmission and processing of signals, but they are not sufficient to establish the legal category of personal data (pp. 13–19).

Information theory nevertheless highlights an important aspect: information does not necessarily coincide with a particular material object. It may be encoded on different media, copied, transformed, and transmitted without its content depending entirely on any single physical support. This makes it difficult to apply traditional property categories. Describing data as “property” may serve a descriptive or economic function, but it does not resolve the multiple interests that may attach to the same information. Data may be produced by one person, collected by another, stored by a third, and relate simultaneously to several individuals (pp. 13–19).

The subsequent analysis of semantic information introduces the problems of meaning and truth. A set of signs becomes informative when it can be interpreted within a system of rules or knowledge. Data protection law, however, also applies to information that is inaccurate, incomplete, or disputed. The ability of data to produce consequences for an individual may persist even when the data are false. For legal purposes, information cannot therefore be confined to semantically true content: it must also encompass representations, assessments, and inferences that are treated as reliable and acted upon accordingly (pp. 20–24).

The discussion of the philosophy of computing and artificial intelligence further develops the relationship between data, models, and inferential processes. Computer systems do not merely preserve information that is already available; they construct new classifications by combining different data. A growing proportion of the knowledge associated with individuals is not communicated directly by them, but inferred from their behaviour or from correlations identified within large datasets. The focus of protection therefore tends to shift from the original data to the chain of operations leading to the construction of a profile or prediction (pp. 25–29).

The inquiry then extends to biology, memetics, and neuroscience. In these fields, information is frequently used to describe genetic transmission, cellular processes, learning, and the circulation of cultural models. Informational language provides a powerful explanatory metaphor, but its use is not neutral: it may encourage the representation of organisms, brains, and behaviour as systems of coding and computation. The chapter considers whether these models can assist in understanding neural data, while leaving open the question whether they describe genuine properties of biological phenomena or theoretical instruments constructed by the observer (pp. 30–41).

The historical section reconstructs the introduction of the terms “data” and “information” into legal language. Early forms of regulation did not develop a general theory of information, but governed individual forms of knowledge: documents, registers, secrets, communications, and news. Law therefore protected informational content even before it possessed the contemporary concept of data. Technological innovation nevertheless made the need for a cross-cutting category more apparent—one capable of encompassing automated recording, interconnected archives, and the circulation of information (pp. 42–50).

From the 1970s onwards, data progressively acquired autonomy within legal terminology. The spread of computers and databases produced a shift from protection focused on secrecy to regulation focused on processing. The problem was no longer simply to prevent access to information, but to regulate its collection, storage, combination, alteration, communication, and erasure. Data protection thus emerged as the regulation of processes, rather than merely of objects or content (pp. 51–64).

The concluding clarifications do not seek to establish a universal definition. Data are treated as elements capable of being incorporated into an informational process; information is viewed as the context-dependent result of interpretation or processing. Personal referability is not presented as an immutable property of data, but as a relationship dependent on the knowledge and means available. This approach supports a precautionary conclusion: regulation should not focus exclusively on the abstract nature of an individual item of data, but also on the contexts, combinations, and uses capable of producing effects on individuals (pp. 65–76).

Chapter Two – Privacy and Data Protection

The second chapter reconstructs the development of privacy from the protection of the body and personal spaces to the regulation of informational flows. Its starting point is the material dimension of privacy: the home, correspondence, family life, confidentiality of communications, and personal integrity. Historically, privacy developed as a claim to exclude others from particular places, forms of knowledge, or relationships. The idea of a private sphere does not, however, correspond to an absolute separation from society; it is a legal construction dependent on social relations and the technologies available (pp. 77–87).

The transition from privacy to data protection responds to the limitations of a purely negative model. Information may be collected lawfully and never disclosed publicly, yet still be used in a manner harmful to the person concerned. Data protection therefore introduces safeguards relating to the quality, purposes, and methods of processing. Individual control retains an important role but is supplemented by obligations imposed directly on those who process information (pp. 88–94).

The legal reconstruction traces the development of European regulation from Council of Europe Convention No. 108 to the European Union system and the GDPR. This trajectory consolidated principles such as lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, security, and accountability. The legal framework generally seeks to remain technologically neutral so that it can apply to different forms of processing. This flexibility facilitates adaptation, but may also transfer a considerable part of the concrete definition of safeguards to interpreters and operators (pp. 95–101).

The GDPR’s approach is examined particularly from the perspective of risk management. Protection is not entrusted solely to predetermined prohibitions, but requires prior assessments, technical and organisational measures, data protection by design, and, in more sensitive cases, data protection impact assessments. The model therefore assigns a significant role to the controller’s accountability. This approach can permit solutions proportionate to the context, but presupposes that those responsible for assessing risk possess adequate knowledge and do not reduce compliance to a merely documentary exercise (pp. 102–108).

A central part of the chapter concerns health data, which are employed as a particularly useful field for examining future questions relating to neural data. Health information receives enhanced protection but is at the same time indispensable for diagnosis, treatment, healthcare administration, and research. Its legal regime is therefore characterised by derogations, specific conditions, and balances between individual interests and collective purposes. Health data show particularly clearly that protection cannot consist simply in prohibiting processing: in many circumstances, the use of information is necessary to protect the same person to whom the data relate (pp. 109–119).

The evolution from medical records to electronic health records illustrates the transformation of health information. Data no longer remain confined to the relationship between physician and patient, but circulate through complex infrastructures accessed by different actors and integrating information from heterogeneous sources. This may benefit continuity of care, but it also creates new problems relating to security, quality, access, and reuse. Digitisation therefore changes not only the medium, but also the structure of the relationships within which health data are produced and employed (pp. 120–123).

Professional secrecy is examined as a safeguard that precedes and supplements data protection. It protects relationships of trust and restricts the disclosure of knowledge acquired in the exercise of a profession. It does not, however, necessarily regulate all the operations carried out within digital infrastructures and does not resolve the problems presented by actors involved in processing without being direct parties to the therapeutic relationship. Professional secrecy may therefore function as a residual safeguard, but it cannot replace comprehensive regulation of the informational cycle (pp. 124–130).

The chapter also considers the plurality of sources involved: legislation, decisions of supervisory authorities, guidelines, technical standards, codes of conduct, professional rules, and self-regulatory practices. In the technological sector, effective protection often depends on technical provisions developed by actors other than the legislature. This arrangement may facilitate more rapid updates, but it also raises questions of legitimacy, transparency, and oversight. Privacy regulation consequently appears as a multilevel system in which the boundary between legal rules, technical standards, and professional ethics is not always clear (pp. 131–137).

The conclusion situates privacy and data protection within the system of fundamental rights. The two positions are connected but do not entirely overlap. Privacy protects intimacy and private life; data protection regulates the conditions under which personal information may be used, including information that is not confidential. From this perspective, the processing of neural data may concern both dimensions while also engaging dignity, identity, health, personal freedom, freedom of thought, and non-discrimination. The chapter does not yet establish the existence of an autonomous right to neuroprivacy, but identifies the network of safeguards within which the question should be assessed (pp. 138–143).

Chapter Three – The Law of Neuroscientific Research

The third chapter considers scientific research as a constitutionally protected freedom and, at the same time, as an activity capable of affecting other rights. The Constitution protects freedom of science and promotes its development, but does not exempt research from all limitations. Experiments involving human subjects, the use of personal data, and the consequences of innovation require scientific freedom to be coordinated with health, dignity, self-determination, and collective interests. The problem is therefore not to set science and law against one another in the abstract, but to construct conditions under which research can proceed without marginalising the position of its participants (pp. 144–149).

Processing for scientific purposes receives partially differentiated treatment under the GDPR. The regulation recognises the importance of research and, where appropriate safeguards are in place, permits derogations from certain ordinary constraints. The category of scientific purposes does not, however, create a regulatory free zone: general principles remain applicable and measures such as pseudonymisation, minimisation, and access limitation must be adopted. A decisive issue concerns the scope of the concept of research and the risk that commercial or experimental activities may be characterised as scientific solely to benefit from a more favourable legal regime (pp. 150–154).

The “limits of research” are also examined as a question concerning the source of the applicable rules. The scientific community inevitably participates in defining the standards governing its activities, since the legislature does not always possess the expertise needed to specify methods, risks, and precautions in detail. Technical competence, however, does not amount to authority to determine autonomously how all the interests involved should be balanced. Guidelines and professional standards may supplement legal regulation, but they should not render the underlying normative choices opaque (pp. 155–161).

Informed consent is examined both as a condition for processing and as an expression of self-determination. Consent presents particular difficulties in research: future uses of data may not be entirely foreseeable, projects may involve several institutions, and information may be retained for subsequent studies. Broad consent facilitates research but risks losing specificity; excessively narrow consent may be incompatible with the evolution of a project. The chapter suggests that participants’ freedom cannot be entrusted exclusively to their initial act of consent, but must be supported by organisational safeguards, continuing transparency, and opportunities for oversight (pp. 162–167).

E-health is a field in which research, treatment, and innovation tend to overlap. Wearable devices, digital platforms, and monitoring tools can simultaneously produce data useful for healthcare, research, and commercial development. Changes in purpose are not always apparent to the individual, making it more difficult to distinguish the therapeutic relationship from participation in an experimental activity. The legal framework should therefore consider not only the nature of the data but also the overall architecture within which they are collected and reused (pp. 168–171).

The relationship between research, innovation, and regulation is described as dynamic. Premature regulation may be based on speculative representations of technology; exclusively ex post regulation may intervene only after practices and infrastructures have already become entrenched. The chapter therefore considers flexible instruments, ethical oversight, and forms of progressive assessment. The 2023 text presents this structure as a possible model for other sectors as well; today, this proposal may be read more cautiously as a repertoire of instruments to be evaluated in relation to different practical contexts (pp. 172–180).

The concluding pages identify several specific features of neuroscientific research: the difficulty of anonymising complex brain data; the possibility of deriving information beyond the original purpose; the management of incidental findings; the relationship between scientific validity and ethical acceptability; and the distinction between observing and intervening in brain processes. Participants may not be fully aware of the future inferences that can be drawn from their data, while researchers may encounter clinically significant information not anticipated by the protocol. These problems do not necessarily demonstrate that the entire law of research is inadequate, but they do test the limits of its categories (pp. 181–185).

Chapter Four – Neurorights and Neuroprivacy

The fourth chapter directly addresses the debate over neurorights. Its first section clarifies that the emergence of new terminology does not in itself establish the existence of new rights. Proposals developed in the international literature seek to name interests that may already be protected, at least in part, by traditional rights and freedoms. The question must therefore be broken down: the relevant conduct, actors, risks, and regulatory gaps must be identified before determining whether a new category is necessary (pp. 186–189).

The comparison between neuroscience and law shows that the two disciplines employ different models of the person and of action. Law attributes decisions and responsibility to unitary subjects; neuroscience describes brain mechanisms, unconscious processes, and correlations between neural activity and behaviour. These findings do not automatically invalidate legal categories. Concepts such as will, attribution, and responsibility perform normative functions that do not coincide with the causal description of brain activity. At the same time, law should not invoke a particular conception of the will as an uncontested empirical fact when it operates instead as an institutional premise (pp. 190–195).

The chapter then reviews the principal neurotechnologies and their applications. Neuroimaging techniques, electroencephalography, brain–computer interfaces, neuromodulation, and consumer devices may be employed for diagnostic, therapeutic, rehabilitative, experimental, or commercial purposes. Their actual capabilities vary considerably, and many applications produce statistical correlations rather than directly decipherable mental content. The risks should therefore neither be minimised nor described through an undifferentiated image of “mind reading” (pp. 196–204).

Biolaw provides an initial regulatory framework through informed consent, physical and mental integrity, protection of health, dignity, and oversight of experimentation. These categories are particularly relevant when neurotechnology intervenes in the body or is used in clinical settings. Non-medical applications, however, may escape the most established safeguards. The same technology may qualify as a medical device in one context and a consumer product in another, with significant consequences for the applicable legal regime (pp. 205–213).

The example of the “lie detector” provides an opportunity to examine the relationship between knowledge of brain activity and moral freedom. Technologies purporting to detect lies, memories, or subjective states raise questions of scientific reliability, admissibility in legal proceedings, and freedom from compelled self-exposure. Even when these techniques do not provide direct access to thoughts, their portrayal as objective instruments may confer disproportionate authority upon their results. The risk therefore arises both from the technology’s actual performance and from the institutional and symbolic uses made of it (pp. 214–220).

The protection of neural data is then reconstructed in light of the GDPR. Data derived from brain activity will ordinarily constitute personal data where they can be associated with an individual; they may also fall within special categories when they reveal health information or biometric characteristics. It is not certain, however, that all neural data should be classified in the same manner. Their sensitivity depends on their content, purpose, possible inferences, and context. A legal framework based exclusively on the biological origin of the data risks being both overinclusive and underinclusive: overinclusive in relation to data with no meaningful revelatory capacity, and underinclusive in relation to cognitive inferences derived from non-neural behavioural data (pp. 221–227).

The discussion of new neurorights considers, among other proposals, mental identity, mental privacy, mental integrity, psychological continuity, and cognitive liberty. The book observes that these categories describe partially overlapping interests. Their proliferation may make neglected risks more visible, but may also generate uncertainty regarding their content, right-holders, duty-bearers, and remedies. Recognition of a new right should not be treated as a merely nominal achievement: it requires the definition of obligations, limitations, balancing criteria, and means of protection (pp. 228–245).

Neuroprivacy is ultimately proposed as a unifying perspective, though not necessarily as a self-sufficient right. It may be understood as a field in which the protection of neural data, mental privacy, and safeguards against unlawful cognitive interference converge. Its principal value lies in connecting the processing of information with the conditions under which individual decisions are formed. The category nevertheless remains open: access to mental information must be distinguished from causal intervention in the mind, and criteria are needed to establish when ordinary social or communicative influence becomes legally relevant interference (pp. 246–251).

Chapter Five – Cognitive Liberty

The final chapter examines cognitive liberty as a possible foundation for the safeguards reconstructed in the preceding chapters. The initial problem concerns the relationship between legal freedom and psychological freedom. Law can guarantee spheres of action and protect individuals from coercion, but it cannot demonstrate that decisions are metaphysically free. Legal freedom operates at the normative level: it determines which interferences are prohibited, which choices must be respected, and under what conditions a decision may be attributed to a subject (pp. 252–253).

The reconstruction of classical theories shows that the relationship between freedom and necessity has received different answers. Determinism, indeterminism, and compatibilism do not offer solutions that can be translated directly into law. The legal system need not necessarily adopt a complete theory of mental causation; it may recognise autonomy and responsibility as institutional conditions while taking account of situations in which decision-making capacity is impaired or action results from legally relevant coercion (pp. 254–259).

The problem of free will is then compared with neuroscientific experiments seeking to identify neural antecedents of conscious decisions. The book examines the interpretive difficulties of such research: the simplified nature of experimental tasks, the definition of the moment at which a decision occurs, the relationship between neural correlation and causation, and the possibility of generalising results to complex choices. Neuroscience may contribute to an understanding of decision-making processes, but does not appear capable, by itself, of resolving the philosophical controversy or automatically requiring the revision of legal categories (pp. 260–268).

Contemporary problems of cognitive liberty concern less the demonstration of free will than the conditions under which decisions are actually formed. Persuasion, manipulation, addiction, algorithmic personalisation, and neuromodulation are different phenomena that cannot be subsumed without qualification under a single category. Every social relationship influences cognitive processes; absolute protection from influence would be impossible and probably undesirable. The legal question is to identify forms of interference that, because of their intensity, opacity, purpose, the vulnerability of the recipient, or their ability to bypass deliberation, may be considered incompatible with personal autonomy (pp. 269–271).

The concluding section returns to the alternative between “data and freedom”. Data processing is one of the means by which knowledge about individuals can be acquired and the stimuli directed at them can be personalised. Not every form of processing, however, impairs freedom, just as not every cognitive interference presupposes the use of neural data. The relationship between neuroprivacy and cognitive liberty should therefore be described as a possible connection, rather than a necessary equivalence. Data protection may contribute to preserving conditions of autonomy, but it must be coordinated with rules governing technological design, experimentation, product safety, non-discrimination, and consumer protection (pp. 272–276).

Concluding Remarks

The book’s principal contribution may be found in its attempt to connect three discussions that often proceed separately: the definition of personal information, the development of data protection, and the problem of technological interference with cognitive processes. In a predominantly exploratory manner, the book argues that the regulation of neural data cannot be constructed simply by adding a new category to the list of sensitive data. The entire process must be considered: from the recording of a signal to the production of inferences, and from those inferences to a possible decision or intervention affecting the individual.

The concept of neuroprivacy primarily performs a diagnostic function. It identifies a set of problems situated at the boundary between the body, information, and freedom, without assuming that this set necessarily corresponds to a single subjective right. Protection might be achieved through the coordinated interpretation of existing rights, the introduction of sector-specific rules, or—where gaps emerge that cannot otherwise be addressed—the recognition of new legal positions. Choosing among these solutions would require a more precise analysis of individual technologies and concrete practices.

From the perspective of several years later, some of the book’s original formulations may appear excessively oriented towards a scenario of progressively increasing technological penetration of the mind. Applications that are already operational should be distinguished from experimental possibilities and speculative scenarios. Expressions such as “mind reading”, “mind control”, or “access to thoughts” should also be used cautiously, since they risk obscuring the probabilistic, contextual, and fallible nature of neuroscientific inferences. A less emphatic description does not necessarily weaken the legal argument: even imperfect systems may produce significant effects when their classifications are used by businesses, public authorities, or courts.

The same caution applies to cognitive liberty. Presenting it as a precondition for every other freedom is a theoretically demanding claim and is not indispensable to justify its protection. It is sufficient to observe that certain forms of observation or interference with mental processes may affect interests that are already recognised: self-determination, integrity, freedom of thought, health, identity, and dignity. Cognitive liberty may therefore serve as an interpretive principle or connecting category, without necessarily being assigned the status of the ultimate foundation of the entire system of freedoms.

Read from this more detached perspective, Neuroprivacy does not provide a definitive answer to the question whether new neurorights are necessary. It offers a map of the problems that precede that answer: what constitutes data; when information can be related to a person; how secrecy differs from control over processing; how research and innovation participate in producing their own rules; which neurotechnologies are legally relevant; when an inference becomes legally significant; and to what extent the protection of autonomy can be separated from a metaphysical theory of freedom.

The result is a research programme rather than a conclusive doctrinal construction. Neuroprivacy designates the field in which law is called upon to assess not only who knows certain information, but also how that information is produced, interpreted, and used in relation to individuals. The central question is not whether the mind is destined to become entirely transparent—a scenario that the 2023 book sometimes appears to take more seriously than would now be advisable—but which safeguards should apply when data and cognitive models acquire the capacity, even if only probabilistically, to affect individual opportunities, relationships, and decisions.

Abstract esteso

I riferimenti di pagina rinviano alla numerazione editoriale interna del volume, non al numero progressivo delle pagine del file PDF.

Introduzione

Neuroprivacy. Problemi teorici e prospettive costituzionali affronta il rapporto tra protezione dei dati, neuroscienze, neurotecnologie e libertà individuale attraverso un itinerario interdisciplinare che muove dalla definizione dei concetti di dato e informazione e giunge alla discussione della libertà cognitiva. Pubblicato nel 2023 e sviluppato a partire da ricerche condotte negli anni immediatamente precedenti, il volume riflette una fase nella quale il dibattito sui cosiddetti neurodiritti stava acquistando crescente visibilità, mentre la disciplina giuridica dei dati neurali e delle tecnologie capaci di registrare, inferire o modificare processi mentali rimaneva ancora largamente affidata all’estensione di categorie preesistenti. Il lavoro non presenta, pertanto, una teoria compiuta della neuroprivacy, ma ricostruisce alcuni dei problemi concettuali e normativi che rendono possibile – e forse necessaria – la sua formulazione.

La domanda iniziale riguarda la capacità degli attori pubblici e privati di raccogliere informazioni sempre più precise sulle persone, ricavandole non soltanto dalle loro dichiarazioni o azioni consapevoli, ma anche dalle tracce prodotte nell’ambiente digitale e, in prospettiva, dall’osservazione diretta o indiretta dell’attività cerebrale. Il problema non coincide semplicemente con la pubblicazione di informazioni riservate: riguarda anche l’uso di dati che restano formalmente segreti, ma vengono elaborati per classificare, anticipare o orientare il comportamento. Per questa ragione, la questione viene collocata all’intersezione fra riservatezza, protezione dei dati, autonomia personale e libertà (Introduzione, pp. III-X).

La privacy può essere intesa come protezione di uno spazio sottratto all’ingerenza altrui; la protezione dei dati riguarda le condizioni giuridiche del trattamento delle informazioni riferibili alla persona. La libertà cognitiva, infine, designa in via ancora esplorativa l’interesse dell’individuo a non vedere i propri processi mentali indebitamente osservati, ricostruiti o condizionati. Nessuna delle tre nozioni appare sufficiente, isolatamente considerata, a descrivere l’intero fenomeno. Non è neppure scontato che dalla loro sovrapposizione debba derivare il riconoscimento di un diritto fondamentale completamente nuovo.

La nozione di neuroprivacy è utilizzata come categoria di sintesi, e non come definizione normativa già stabilizzata. Essa comprende la protezione delle informazioni relative all’attività cerebrale e ai processi mentali, ma anche il problema più generale delle interferenze che il trattamento di tali informazioni può produrre sulla persona. Una disciplina adeguata dovrebbe considerare anche le inferenze elaborate a partire da dati non propriamente neurali, gli usi secondari delle informazioni, le asimmetrie tra chi produce e chi interpreta i dati e le conseguenze delle tecniche capaci di incidere sui processi cognitivi.

Il percorso del libro va dal dato alla libertà. Il primo capitolo esamina le nozioni di dato e informazione; il secondo ricostruisce l’evoluzione della privacy e della protezione dei dati, con particolare attenzione ai dati sanitari; il terzo studia la disciplina della ricerca scientifica e neuroscientifica; il quarto affronta le neurotecnologie, i neurodiritti e la possibile configurazione della neuroprivacy; il quinto discute il concetto di libertà cognitiva e il suo problematico rapporto con il libero arbitrio.

Il metodo è dichiaratamente interdisciplinare. La ricerca costituzionalistica è accompagnata da ricostruzioni storiche e teoriche e dal confronto con informatica, teoria dell’informazione, biologia, neuroscienze e filosofia della mente. Le categorie giuridiche non possono essere semplicemente ricavate dalle scienze empiriche; allo stesso tempo, una regolazione delle neurotecnologie costruita senza comprenderne almeno i presupposti rischierebbe di riferirsi a oggetti mal definiti o di attribuire alle tecnologie capacità che esse non possiedono.

Considerata retrospettivamente, l’urgenza attribuita nel 2023 alla costruzione di nuove tutele può essere formulata in termini più cauti. Lo sviluppo delle tecnologie non segue necessariamente una progressione lineare verso una sempre maggiore “lettura della mente”; molte applicazioni producono dati rumorosi, probabilistici e dipendenti dal contesto. È utile separare almeno quattro situazioni: la registrazione dell’attività neurale; l’inferenza di stati mentali; la classificazione probabilistica delle persone; l’intervento sui processi cognitivi. I rischi, gli interessi e le regole applicabili possono variare sensibilmente.

Capitolo I – Dati e informazioni

Il primo capitolo è dedicato ai concetti che costituiscono il presupposto dell’intera ricerca. “Dato” e “informazione” sono termini impiegati quotidianamente dal diritto, dalla tecnica e dal linguaggio comune, ma non possiedono un significato univoco. Il capitolo mostra come le definizioni disponibili dipendano dal paradigma scientifico entro il quale sono formulate e come non sia possibile trasferirle automaticamente da una disciplina all’altra. Dalla nozione di dato dipende anche la delimitazione dell’oggetto della protezione giuridica (pp. 1-7).

Il dato può essere descritto come una differenza, un valore, un segno o una rappresentazione suscettibile di registrazione ed elaborazione. L’informazione può invece indicare il contenuto comunicato o ricavato attraverso l’interpretazione di uno o più dati. Questa distinzione non è assoluta: un’informazione può diventare il dato di una successiva elaborazione; un medesimo segno può essere informativo in un contesto e privo di significato in un altro. La relazione appare funzionale e dipendente dall’operazione conoscitiva considerata.

La “riferibilità” indica il rapporto tra il dato e la realtà alla quale esso viene riferito. Il dato potrebbe identificare immediatamente la persona, acquistare capacità identificativa mediante l’associazione con altri elementi oppure consentire soltanto inferenze probabilistiche. Il confine tra dato personale e non personale risulta perciò mobile e dipendente dal contesto tecnologico, dalle risorse disponibili e dalle operazioni concretamente realizzabili (pp. 8-12).

Nella teoria dell’informazione, il contenuto informativo può essere misurato indipendentemente dal suo significato e dal suo rapporto con una persona determinata. La quantità di informazione concerne la riduzione dell’incertezza all’interno di un sistema, non la verità semantica di un enunciato o la rilevanza giuridica del suo contenuto. Queste nozioni spiegano la trasmissione e l’elaborazione del segnale, ma non sono sufficienti a fondare la categoria del dato personale (pp. 13-19).

L’informazione può essere codificata su supporti diversi, duplicata, trasformata e trasmessa. Ciò rende problematico l’uso delle categorie dominicali tradizionali. Parlare di “proprietà” del dato può avere una funzione descrittiva o economica, ma non risolve i molteplici interessi che insistono sulla medesima informazione. Il dato può essere prodotto da un soggetto, raccolto da un altro, conservato da un terzo e riferirsi contemporaneamente a più persone.

Il diritto della protezione dei dati si applica anche a informazioni inesatte, incomplete o contestabili. La capacità di un dato di produrre conseguenze sulla persona può persistere anche quando il dato è falso. Inoltre, i sistemi informatici non si limitano a conservare informazioni già disponibili: costruiscono classificazioni combinando dati diversi. Il problema tende così a spostarsi dal dato originario alla catena di operazioni che conduce alla produzione di un profilo o di una previsione (pp. 20-29).

La ricognizione si estende alle scienze biologiche, alla memetica e alle neuroscienze, dove l’informazione descrive la trasmissione genetica, i processi cellulari, l’apprendimento e la circolazione di modelli culturali. Il linguaggio informazionale offre una potente metafora esplicativa, ma può indurre a rappresentare organismi, cervelli e comportamenti come sistemi di codificazione e calcolo (pp. 30-41).

La parte storica ricostruisce l’ingresso dei termini “dato” e “informazione” nel linguaggio giuridico. Dagli anni Settanta in avanti, la diffusione degli elaboratori e delle banche dati determina il passaggio da una tutela concentrata sulla segretezza a una regolazione del trattamento: raccolta, conservazione, combinazione, modificazione, comunicazione e cancellazione. La protezione dei dati diviene disciplina di processi, non soltanto di oggetti o contenuti (pp. 42-64).

Le conclusioni non fissano una definizione universale. Il dato è considerato come elemento suscettibile di essere assunto entro un processo informativo; l’informazione come risultato, sempre contestuale, di un’operazione di interpretazione o elaborazione. La regolazione non dovrebbe concentrarsi esclusivamente sulla natura astratta del singolo dato, ma anche sui contesti, sulle combinazioni e sugli usi capaci di produrre effetti sulla persona (pp. 65-76).

Capitolo II – Privacy e protezione dei dati

Il secondo capitolo ricostruisce l’evoluzione della privacy dalla protezione del corpo e degli spazi personali alla disciplina dei flussi informativi. Storicamente, la privacy si sviluppa come pretesa a escludere altri soggetti da determinati luoghi, conoscenze o relazioni; l’idea di uno spazio privato resta però una costruzione giuridica dipendente dai rapporti sociali e dalle tecnologie disponibili (pp. 77-87).

Il passaggio dalla riservatezza alla protezione dei dati risponde all’insufficienza del paradigma puramente negativo. Un’informazione può essere raccolta lecitamente e non essere mai resa pubblica, ma essere ugualmente utilizzata in modo pregiudizievole. La protezione dei dati introduce garanzie relative alla qualità, alle finalità e alle modalità del trattamento, integrando il controllo individuale con obblighi posti a carico di chi tratta le informazioni (pp. 88-94).

La ricostruzione normativa segue lo sviluppo europeo dalla Convenzione n. 108 al GDPR. Si consolidano liceità, correttezza, trasparenza, limitazione delle finalità, minimizzazione, esattezza, limitazione della conservazione, sicurezza e responsabilizzazione. L’approccio del GDPR viene esaminato soprattutto sotto il profilo della gestione del rischio, delle valutazioni preventive, della protezione fin dalla progettazione e delle valutazioni d’impatto (pp. 95-108).

I dati sanitari costituiscono il terreno di osservazione privilegiato per le future questioni relative ai dati neurali. Ricevono una tutela rafforzata, ma sono indispensabili per diagnosi, assistenza, amministrazione sanitaria e ricerca. La protezione non può consistere nel semplice divieto di trattamento: in molte situazioni l’uso dell’informazione è necessario alla tutela della stessa persona cui il dato si riferisce (pp. 109-119).

L’evoluzione dalla cartella clinica al fascicolo sanitario elettronico rende visibile la trasformazione dell’informazione sanitaria. Il dato circola in infrastrutture complesse, accessibili a soggetti differenti e capaci di integrare fonti eterogenee. Ne derivano benefici per la continuità assistenziale, ma anche problemi di sicurezza, qualità, accesso e riutilizzazione (pp. 120-123).

Il segreto professionale tutela il rapporto fiduciario, ma non disciplina necessariamente tutte le operazioni realizzate nelle infrastrutture digitali e non risolve i problemi posti dai soggetti che partecipano al trattamento senza essere parte della relazione terapeutica. La concreta tutela dipende inoltre da legislazione, autorità, linee guida, standard tecnici, codici di condotta e regole professionali: un sistema multilivello nel quale il confine tra norme giuridiche, standard tecnici ed etica professionale non è sempre netto (pp. 124-137).

Privacy e protezione dei dati sono connesse, ma non perfettamente sovrapponibili. Il trattamento dei dati neurali potrebbe interessare entrambe e coinvolgere dignità, identità, salute, libertà personale, libertà di pensiero e non discriminazione. Il capitolo non dimostra ancora l’esistenza di un autonomo diritto alla neuroprivacy, ma individua la rete di garanzie entro la quale la questione dovrebbe essere valutata (pp. 138-143).

Capitolo III – Il diritto della ricerca neuroscientifica

Il terzo capitolo considera la ricerca scientifica come libertà costituzionalmente protetta e, al tempo stesso, come attività capace di incidere su altri diritti. La Costituzione tutela la libertà della scienza e ne promuove lo sviluppo, ma non sottrae la ricerca a ogni limite. Sperimentazione su persone, impiego di dati personali e conseguenze delle innovazioni impongono di coordinare libertà scientifica, salute, dignità, autodeterminazione e interessi collettivi (pp. 144-149).

Il trattamento per finalità scientifiche riceve nel GDPR una disciplina parzialmente differenziata. In presenza di garanzie adeguate sono possibili deroghe ad alcuni vincoli ordinari, ma la ricerca non costituisce una zona franca: restano i principi generali e misure quali pseudonimizzazione, minimizzazione e limitazione dell’accesso. È decisiva l’ampiezza della nozione di ricerca e il rischio che attività commerciali o sperimentali vi siano ricondotte soltanto per beneficiare di un regime più favorevole (pp. 150-154).

La comunità scientifica partecipa inevitabilmente alla definizione degli standard, perché il legislatore non dispone sempre delle competenze necessarie per predeterminare metodi, rischi e cautele. La competenza tecnica, tuttavia, non coincide con la legittimazione a stabilire autonomamente il bilanciamento tra tutti gli interessi. Linee guida e standard professionali possono integrare la disciplina giuridica, ma non dovrebbero rendere opache le scelte normative (pp. 155-161).

Nella ricerca il consenso informato incontra difficoltà particolari: gli usi futuri dei dati possono non essere prevedibili, i progetti possono coinvolgere più istituzioni e le informazioni possono essere conservate per studi successivi. Il consenso ampio facilita la ricerca ma rischia di perdere determinatezza; quello eccessivamente specifico può risultare incompatibile con l’evoluzione del progetto. La libertà del partecipante deve essere sostenuta anche da garanzie organizzative, trasparenza continuativa e possibilità di controllo (pp. 162-167).

Nell’e-health ricerca, assistenza e innovazione tendono a sovrapporsi. Dispositivi indossabili, piattaforme e monitoraggi possono produrre dati utili contemporaneamente alla cura, alla ricerca e allo sviluppo commerciale. Il quadro normativo deve considerare non soltanto la natura del dato, ma anche l’architettura complessiva entro la quale viene raccolto e riutilizzato (pp. 168-171).

Una disciplina troppo anticipata potrebbe fondarsi su rappresentazioni speculative; una regolazione soltanto successiva potrebbe intervenire quando pratiche e infrastrutture sono già consolidate. Le specificità della ricerca neuroscientifica comprendono la difficoltà di anonimizzare dati cerebrali complessi, le inferenze ulteriori rispetto all’obiettivo originario, la gestione dei risultati incidentali, la validità scientifica e la distinzione tra osservazione e intervento sui processi cerebrali (pp. 172-185).

Capitolo IV – Neurodiritti e neuroprivacy

Il quarto capitolo affronta direttamente il dibattito sui neurodiritti. L’emersione di un nuovo lessico non prova, da sola, l’esistenza di diritti nuovi. Le proposte internazionali cercano di nominare interessi forse già protetti, almeno parzialmente, da libertà e garanzie tradizionali. Occorre individuare condotte, soggetti, rischi e lacune normative prima di stabilire se sia necessaria una nuova categoria (pp. 186-189).

Diritto e neuroscienze utilizzano modelli differenti della persona e dell’azione. Il diritto attribuisce decisioni e responsabilità a soggetti unitari; le neuroscienze descrivono meccanismi cerebrali, processi inconsci e correlazioni tra attività neurale e comportamento. Da tali risultati non segue automaticamente la falsità delle categorie giuridiche. Volontà, imputazione e responsabilità svolgono funzioni normative che non coincidono con la descrizione causale dell’attività cerebrale (pp. 190-195).

Neuroimaging, elettroencefalografia, interfacce cervello-computer, neuromodulazione e dispositivi destinati al mercato possono essere impiegati per finalità diagnostiche, terapeutiche, riabilitative, sperimentali o commerciali. Le capacità effettive variano e molte applicazioni restituiscono correlazioni statistiche anziché contenuti mentali direttamente decifrabili. I rischi non devono essere né minimizzati né descritti attraverso l’immagine indifferenziata di una “lettura della mente” (pp. 196-204).

Il biodiritto offre una prima cornice attraverso consenso informato, integrità fisica e psichica, tutela della salute, dignità e controllo della sperimentazione. Queste categorie sono particolarmente pertinenti quando la neurotecnologia interviene sul corpo o opera in ambito clinico. Le applicazioni non mediche possono però sfuggire alle garanzie più consolidate: la medesima tecnologia può essere dispositivo medico in un contesto e prodotto di consumo in un altro (pp. 205-213).

L’esempio della “macchina della verità” permette di esaminare il rapporto tra conoscenza dell’attività cerebrale e libertà morale. Gli strumenti che pretendono di individuare menzogne, ricordi o stati soggettivi sollevano problemi di affidabilità, ammissibilità processuale e libertà da autoesposizioni forzate. Anche senza accesso diretto al pensiero, la rappresentazione del risultato come oggettivo può attribuirgli un’autorità sproporzionata (pp. 214-220).

Un dato derivante dall’attività cerebrale è normalmente personale quando può essere associato a un individuo; può inoltre rientrare nelle categorie particolari se rivela salute o caratteristiche biometriche. Non è certo, però, che ogni dato neurale debba essere qualificato allo stesso modo. Una disciplina fondata soltanto sull’origine biologica rischierebbe di essere troppo ampia per dati privi di reale capacità rivelatrice e troppo stretta per inferenze cognitive ottenute da dati comportamentali non neurali (pp. 221-227).

Identità mentale, privacy mentale, integrità mentale, continuità psicologica e libertà cognitiva descrivono interessi in parte sovrapposti. La loro moltiplicazione può rendere visibili rischi trascurati, ma anche generare incertezza circa contenuto, titolari, destinatari e rimedi. Il riconoscimento di un nuovo diritto richiede la definizione di obblighi, limiti, criteri di bilanciamento e strumenti di tutela (pp. 228-245).

La neuroprivacy è proposta come prospettiva unificante, non necessariamente come diritto autosufficiente. Può essere intesa come il campo in cui convergono protezione dei dati neurali, riservatezza mentale e garanzie contro interferenze cognitive indebite. Resta necessario distinguere l’accesso a informazioni mentali dall’intervento causale sulla mente e stabilire quando una comune influenza sociale o comunicativa divenga un’interferenza giuridicamente rilevante (pp. 246-251).

Capitolo V – Libertà cognitiva

L’ultimo capitolo esamina la libertà cognitiva come possibile fondamento delle tutele ricostruite. Il diritto può garantire spazi di azione e proteggere la persona da costrizioni, ma non può dimostrare che le decisioni siano metafisicamente libere. La libertà giuridica opera sul piano normativo: stabilisce quali interferenze siano vietate, quali scelte debbano essere rispettate e a quali condizioni una decisione possa essere imputata a un soggetto (pp. 252-253).

Determinismo, indeterminismo e compatibilismo non offrono una soluzione direttamente traducibile nel diritto. Il sistema giuridico non deve necessariamente assumere una teoria completa della causalità mentale; può riconoscere autonomia e responsabilità come condizioni istituzionali, pur considerando i casi nei quali la capacità decisionale è compromessa o l’azione è prodotta da coercizioni rilevanti (pp. 254-259).

Gli esperimenti neuroscientifici sugli antecedenti cerebrali delle decisioni coscienti pongono difficoltà interpretative: natura semplificata dei compiti, definizione del momento della decisione, rapporto tra correlazione neurale e causalità, generalizzazione alle scelte complesse. Le neuroscienze contribuiscono alla comprensione dei processi decisionali, ma non risolvono da sole la controversia filosofica né determinano automaticamente una revisione delle categorie giuridiche (pp. 260-268).

I problemi contemporanei riguardano soprattutto le condizioni concrete di formazione delle decisioni. Persuasione, manipolazione, dipendenza, personalizzazione algoritmica e neuromodulazione sono fenomeni diversi. Ogni relazione sociale influenza i processi cognitivi; una tutela assoluta dall’influenza sarebbe impossibile. La questione giuridica consiste nel riconoscere le interferenze che, per intensità, opacità, finalità, vulnerabilità del destinatario o capacità di aggirarne la deliberazione, risultano incompatibili con l’autonomia personale (pp. 269-271).

Il trattamento dei dati è uno dei mezzi attraverso cui acquisire conoscenza sulla persona e personalizzare gli stimoli. Non ogni trattamento lede la libertà, così come non ogni interferenza cognitiva presuppone dati neurali. La protezione dei dati può contribuire a preservare condizioni di autonomia, ma deve essere coordinata con regole sul design delle tecnologie, sulla sperimentazione, sulla sicurezza dei prodotti, sulla non discriminazione e sulla tutela dei consumatori (pp. 272-276).

Considerazioni conclusive

Il contributo principale del volume consiste nel collegare tre discussioni spesso separate: la definizione dell’informazione personale, l’evoluzione della protezione dei dati e il problema delle interferenze tecnologiche sui processi cognitivi. La disciplina dei dati neurali non può limitarsi ad aggiungere una nuova categoria all’elenco dei dati sensibili: occorre considerare l’intero processo dalla registrazione del segnale alla produzione di inferenze e dall’inferenza all’eventuale decisione o intervento sulla persona.

La neuroprivacy svolge soprattutto una funzione diagnostica. Indica problemi situati al confine tra corpo, informazione e libertà, senza presupporre che vi corrisponda necessariamente un unico diritto soggettivo. La protezione potrebbe derivare dall’interpretazione coordinata di diritti esistenti, da regole settoriali oppure, dove emergano lacune non colmabili, dal riconoscimento di nuove posizioni giuridiche.

A distanza di alcuni anni, alcune formulazioni originarie possono apparire eccessivamente orientate verso uno scenario di progressiva penetrazione tecnologica nella mente. È opportuno distinguere applicazioni operative, possibilità sperimentali e ipotesi speculative. Espressioni come “lettura della mente”, “controllo mentale” o “accesso ai pensieri” vanno usate con cautela, perché rischiano di oscurare il carattere probabilistico, contestuale e fallibile delle inferenze neuroscientifiche. Anche sistemi imperfetti, tuttavia, possono produrre effetti rilevanti quando le loro classificazioni sono utilizzate da imprese, amministrazioni o autorità giudiziarie.

La medesima cautela vale per la libertà cognitiva. Non è indispensabile presentarla come precondizione di ogni altra libertà: determinate forme di osservazione o interferenza sui processi mentali possono incidere su autodeterminazione, integrità, libertà di pensiero, salute, identità e dignità. La libertà cognitiva può essere usata come principio interpretativo o categoria di raccordo.

Neuroprivacy non fornisce una risposta definitiva alla domanda se siano necessari nuovi neurodiritti. Offre una mappa dei problemi che precedono quella risposta: che cosa sia un dato; quando un’informazione possa essere riferita alla persona; quali differenze esistano tra segreto e controllo del trattamento; come ricerca e innovazione partecipino alla produzione delle proprie regole; quali neurotecnologie siano concretamente rilevanti; quando un’inferenza divenga giuridicamente significativa; fino a che punto la protezione dell’autonomia possa prescindere da una teoria metafisica della libertà.

Il risultato è una proposta di ricerca più che una costruzione dogmatica conclusa. La neuroprivacy designa il luogo nel quale il diritto è chiamato a valutare non soltanto chi conosca determinate informazioni, ma come esse vengano prodotte, interpretate e utilizzate nei confronti della persona. La questione centrale non è se la mente sia destinata a diventare completamente trasparente, ma quali garanzie applicare quando dati e modelli cognitivi acquistano la capacità, anche soltanto probabilistica, di incidere sulle opportunità, sulle relazioni e sulle decisioni individuali.


PAROLE CHIAVE / KEYWORDS

neuroprivacyneurodirittidati neuraliprotezione dei datineurotecnologielibertà cognitiva