Gianclaudio Malgieri

dblp:257/0052 · DBLP profile ↗
← Back
10ranked-venue papers
6as first author
5since 2021 · last 2026
0000-0003-3495-8471ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 6 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Mapping Social Media Dependency: Functional and Psychological Platform Reliance as Mechanisms of Digital Vulnerability
abstract
Social media dependency is a central mechanism through which digital vulnerability takes shape, making it critical to understand for research, design, and policy. This study distinguishes between functional dependency (needs-based reliance) and psychological dependency (compulsive engagement) and investigates how these dimensions intersect. We surveyed 873 adult users across Europe, measuring both dependency forms alongside demographics, well-being, motivations, platform choice, and exposure to manipulative design features. Latent profile analysis and multinomial logistic regression revealed five distinct dependency profiles: functional use, low-dependency pragmatic use, high-dependency social use, moderate-dependency hedonic use, and very high-dependency multi-motivated use. These findings show dependency is not uniform but layered and dynamic, shifting with users’ circumstances and socio-technical contexts. By situating dependency within both individual and design-related factors, the study advances theoretical debates on digital vulnerability and offers a profiles-based lens that helps inform the design of more autonomy-supportive social media platforms.
Janneke M. Schokkenbroek, Maria-Lucia Rebrean, Constanta Rosca, Maëlle Picout, Gianclaudio Malgieri, Ben Wagner, Lorena Sánchez Chamorro
CHI5
2025 Assessing the (severity of) impacts on fundamental rights
abstract
"Risk to fundamental rights,", "impact on fundamental rights", "harm to fundamental rights" and "non-material damages" are all terms referring to similar problems, though inherently ambiguous and very problematic, especially in the age of AI-based technologies and digital platforms. Traditionally, legal and social sciences have two different approaches to analysing the impacts on fundamental rights: the rights-based approach and the risk of harm-based approach to fundamental rights. The rights-based approach is binary, focusing on whether rights and obligations are respected or violated. In contrast, a harm-based approach focuses on the anticipation of undesired events and measuring their likelihood and severity. However, focusing solely on "harms'' or "damages'' is reductionist, while existing impact assessment models often use vague terms like "gravity", "intensity," and "magnitude", which do not effectively help measure interferences with fundamental rights. Without operational criteria to measure these risks, most EU digital strategies demanding impact and risk assessments fail. Examples include the Data Protection Impact Assessment (DPIA) in the GDPR, Fundamental Rights Impact Assessments (FRIA) in the AI Act, and systemic risk assessments in the Digital Services Act (DSA). We posit that interferences with fundamental rights are seen as a spectrum that ranges from social contacts to violations, and these interferences can and should be measured. Thus, this article proposes a rights-based approach, combining it with elements from the harm approach and proposes an actionable parameter-based framework (also based on social meaning theories and social perception methodologies) to assess impacts on fundamental rights. The proposed multi-metric approach ensures a comprehensive assessment of the severity of impacts on fundamental rights within EU law, particularly in GDPR, DSA, and AI Act. This approach aims to inform policymaking, prioritise high-risk scenarios and propose mitigation measures in digital markets. This is especially important for detecting and addressing human vulnerabilities in interactions with digital technologies.
Gianclaudio Malgieri, Cristiana Santos
Comput. Law Secur. Rev.1
2024 Licensing high-risk artificial intelligence: Toward ex ante justification for a disruptive technology
abstract
The regulation of artificial intelligence (AI) has heavily relied on ex post, reactive tools. This approach has proven inadequate, as numerous foreseeable problems arising out of commercial development and applications of AI have harmed vulnerable persons and communities, with few (and sometimes no) opportunities for recourse. Worse problems are highly likely in the future. By requiring quality control measures before AI is deployed, an ex ante approach would often mitigate and sometimes entirely prevent injuries that AI causes or contributes to. Licensing is an important tool of ex ante regulation, and should be applied in many high-risk domains of AI. Indeed, policymakers and even some leading AI developers and vendors are calling for licensure in the area. To substantiate licensing proposals, this article specifies optimal terms of licensure for AI necessary to justify its use. Given both documented and potential harms arising out of high-risk AI systems, licensing agencies should require firms to demonstrate that their AI meets clear requirements for security, non-discrimination, accuracy, appropriateness, and correctability before being deployed. Under this ex ante model of regulation, AI developers would bear the burden of proof to demonstrate that their technology is not discriminatory, not manipulative, not unfair, not inaccurate, and not illegitimate in its lawful bases and purposes. While the European Union's General Data Protection Regulation (GDPR) can provide key benchmarks here for ex post regulation, the proposed AI Act (AIA) offers a first regulatory attempt towards an ex ante licensure regime in high-risk areas, but it should be strengthened through an expansion of its scope and substantive content and through greater transparency of the ex ante justification process.
Gianclaudio Malgieri, Frank Pasquale
Comput. Law Secur. Rev.1
2023 Quod erat demonstrandum? - Towards a typology of the concept of explanation for the design of explainable AI
abstract
In this paper, we present a fundamental framework for defining different types of explanations of AI systems and the criteria for evaluating their quality. Starting from a structural view of how explanations can be constructed, i.e., in terms of an explanandum (what needs to be explained), multiple explanantia (explanations, clues, or parts of information that explain), and a relationship linking explanandum and explanantia, we propose an explanandum-based typology and point to other possible typologies based on how explanantia are presented and how they relate to explanandia. We also highlight two broad and complementary perspectives for defining possible quality criteria for assessing explainability: epistemological and psychological (cognitive). These definition attempts aim to support the three main functions that we believe should attract the interest and further research of XAI scholars: clear inventories, clear verification criteria, and clear validation methods.
Federico Cabitza, Andrea Campagner, Gianclaudio Malgieri, Chiara Natali, David Schneeberger, Karl Stöger, Andreas Holzinger
Expert Syst. Appl.3
2022 Priceless data: : why the EU fundamental right to data protection is at odds with trade in personal data
abstract
Many free online services, including search engines and social media, use business models based on the collecting and processing of personal data of its users. The user data are analysed, leased or sold to generate profits. Basically, the users are not paying for the services with subscription fees or any kind of monetary payment, but with their personal data. In this paper, we argue that these business models, treating personal data as a commodity, are problematic under EU data protection law, which disqualifies personal data as a commodity. Both under the EU Charter of Fundamental Rights and the General Data Protection Regulation (GDPR), the legal rights to data protection are inalienable. This is at odds with the actual trade in personal data in the data economy, since the ‘payment’ cannot be a transfer of ownership of personal data. It could be argued that the ‘payment’ is not a transfer of ownership of personal data, but rather a transfer of personal data rights, i.e., granting a right to collect and process the data. However, even from that perspective, users would retain inalienable rights to stop or restrict the data processing, as the GDPR does not allow mandating data subject rights to others. Because the legal basis for the processing of personal data is often consent, people can invoke their data subject rights (and thus withdraw their ‘payment’) at any time and at will after having received (access to) online services. This causes considerable legal uncertainty in transactions, particularly on the side of data controllers, and may not contribute to the EU's envisioned data economy.
Bart Custers, Gianclaudio Malgieri
Comput. Law Secur. Rev.2
2020 Data protection and research: A vital challenge in the era of COVID-19 pandemic
abstract
A vital challenge
Gianclaudio Malgieri
Comput. Law Secur. Rev.1
2020 Vulnerable data subjects
abstract
Discussion about vulnerable individuals and communities spread from research ethics to consumer law and human rights. According to many theoreticians and practitioners, the framework of vulnerability allows formulating an alternative language to articulate problems of inequality, power imbalances and social injustice. Building on this conceptualisation, we try to understand the role and potentiality of the notion of vulnerable data subjects. The starting point for this reflection is wide-ranging development, deployment and use of data-driven technologies that may pose substantial risks to human rights, the rule of law and social justice. Implementation of such technologies can lead to discrimination systematic marginalisation of different communities and the exploitation of people in particularly sensitive life situations. Considering those problems, we recognise the special role of personal data protection and call for its vulnerability-aware interpretation. This article makes three contributions. First, we examine how the notion of vulnerability is conceptualised and used in the philosophy, human rights and European law. We then confront those findings with the presence and interpretation of vulnerability in data protection law and discourse. Second, we identify two problematic dichotomies that emerge from the theoretical and practical application of this concept in data protection. Those dichotomies reflect the tensions within the definition and manifestation of vulnerability. To overcome limitations that arose from those two dichotomies we support the idea of layered vulnerability, which seems compatible with the GDPR and the risk-based approach. Finally, we outline how the notion of vulnerability can influence the interpretation of particular provisions in the GDPR. In this process, we focus on issues of consent, Data Protection Impact Assessment, the role of Data Protection Authorities, and the participation of data subjects in the decision making about data processing.
Gianclaudio Malgieri, Jedrzej Niklas
Comput. Law Secur. Rev.1
2019 Automated decision-making in the EU Member States: The right to explanation and other "suitable safeguards" in the national legislations
abstract
The aim of this paper is to analyse the very recently approved national Member States’ laws that have implemented the GDPR in the field of automated decision-making (prohibition, exceptions, safeguards): all national legislations have been analysed and in particular 9 Member States Law address the case of automated decision making providing specific exemptions and relevant safeguards, as requested by Article 22(2)(b) of the GDPR (Belgium, The Netherlands, France, Germany, Hungary, Slovenia, Austria, the United Kingdom, Ireland). The approaches are very diverse: the scope of the provision can be narrow (just automated decisions producing legal or similarly detrimental effects) or wide (any decision with a significant impact) and even specific safeguards proposed are very diverse. After this overview, this article will also address the following questions: are Member States free to broaden the scope of automated decision-making regulation? Are ‘positive decisions’ allowed under Article 22, GDPR, as some Member States seem to affirm? Which safeguards can better guarantee rights and freedoms of the data subject? In particular, while most Member States refers just to the three safeguards mentioned at Article 22(3) (i.e. subject's right to express one's point of view; right to obtain human intervention; right to contest the decision), three approaches seem very innovative: a) some States guarantee a right to legibility/explanation about the algorithmic decisions (France and Hungary); b) other States (Ireland and United Kingdom) regulate human intervention on algorithmic decisions through an effective accountability mechanism (e.g. notification, explanation of why such contestation has not been accepted, etc.); c) another State (Slovenia) require an innovative form of human rights impact assessments on automated decision-making.
Gianclaudio Malgieri
Comput. Law Secur. Rev.1
2018 The right to data portability in the GDPR: Towards user-centric interoperability of digital services
abstract
The right to data portability is one of the most important novelties within the EU General Data Protection Regulation, both in terms of warranting control rights to data subjects and in terms of being found at the intersection between data protection and other fields of law (competition law, intellectual property, consumer protection, etc.). It constitutes, thus, a valuable case of development and diffusion of effective user-centric privacy enhancing technologies and a first tool to allow individuals to enjoy the immaterial wealth of their personal data in the data economy. Indeed, a free portability of personal data from one controller to another can be a strong tool for data subjects in order to foster competition of digital services and interoperability of platforms and in order to enhance controllership of individuals on their own data. However, the adopted formulation of the right to data portability in the GDPR could benefit from further clarification: several interpretations are possible, particularly with regard to the object of the right and its interrelation with other rights, potentially leading to additional challenges within its technical implementation. The aim of this article is to propose a first systematic interpretation of this new right, by suggesting a pragmatic and extensive approach, particularly taking advantage as much as possible of the interrelationship that this new legal provision can have with regard to the Digital Single Market and the fundamental rights of digital users. In sum, the right to data portability can be approximated under two different perspectives: the minimalist approach (the adieu scenario) and the empowering approach (the fusing scenario), which the authors consider highly preferable.
Paul de Hert, Vagelis Papakonstantinou, Gianclaudio Malgieri, Laurent Beslay
Comput. Law Secur. Rev.3
2018 Pricing privacy - the right to know the value of your personal data
Gianclaudio Malgieri, Bart Custers
Comput. Law Secur. Rev.1