Ethical AI and Personal Data Protection for AI-Driven Mobile Network Operators
Keywords:
Artificial Intelligence of Things (AIoT), Data protection, Differential privacy, Ethical AI, Federated learning, Mobile network operators, Privacy engineeringAbstract
Artificial intelligence now influences both network engineering and subscriber-facing decisions within mobile network operators (MNOs). The data used for these tasks—call detail records, device identifiers, radio measurements, location histories, and inferred profiles—can reveal far more about a person than the original service requires. This study uses a problem-oriented integrative review to examine four interconnected questions: which personal data are required for common MNO use cases; how privacy, fairness, and opacity risks arise; which legal and governance instruments are relevant; and which controls provide auditable evidence. Thailand’s Personal Data Protection Act provides the principal jurisdictional setting, while the EU General Data Protection Regulation and Artificial Intelligence Act are used where they may apply directly or offer a mature benchmark. The review identifies three recurring weaknesses in operator practice: treating pseudonymization as anonymization, treating location as an optional data field even though radio operation makes it inferable, and adopting ethical principles without assigning measurable controls or owners. In response, the study develops an MNO-specific four-layer governance framework that joins regulatory duties, ethical principles, technical safeguards, and lifecycle assurance under the NIST Govern–Map–Measure–Manage functions. Its distinctive contribution is a traceability chain from an AI use case and its data dependencies to risk, control, retained evidence, accountable ownership, and lifecycle action. A structured mobility-demand forecasting demonstration shows how the framework can record purpose, data granularity, privacy tests, performance thresholds, human responsibility, and post-deployment monitoring. The result is a decision-oriented reference for MNOs; it is not an empirical assessment of any operator or a substitute for jurisdiction-specific legal advice.
References
P. V. Klaine, M. A. Imran, O. Onireti and R. D. Souza, “A survey of machine learning techniques applied to self-organizing cellular networks,” in IEEE Communications Surveys & Tutorials, vol. 19, no. 4, pp. 2392–2431, 2017.
3rd Generation Partnership Project (3GPP), AI/ML for NG-RAN & 5G-Advanced Towards 6G, Jan 05, 2026.
W. Y. B. Lim et al., “Federated learning in mobile edge networks: A comprehensive survey,” in IEEE Communications Surveys & Tutorials, vol. 22, no. 3, pp. 2031–2063, 2020.
Y.-A. de Montjoye, C. A. Hidalgo, M. Verleysen, and V. D. Blondel, “Unique in the crowd: The privacy bounds of human mobility,” Scientific Report, vol. 3, Mar. 2013.
A. Jobin, M. Ienca, and E. Vayena, “The global landscape of AI ethics guidelines,” Nature Machine Intellegence, vol. 1, pp. 389–399, 2019.
B. Mittelstadt, “Principles alone cannot guarantee ethical AI,” Nature Machine Intelligence, vol. 1, pp. 501–507, 2019.
European Parliament and the Council of the European Union, Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), Official Journal of the European Union, vol. L119, pp. 1–88, May 4, 2016.
Kingdom of Thailand, Personal Data Protection Act, B.E. 2562 (2019), Government Gazette, vol. 136, pt. 69a, May 27, 2019.
European Parliament and the Council of the European Union, Regulation (EU) 2024/1689 of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act), Official Journal of the European Union, OJ L 2024/1689, Jul. 12, 2024.
N. Bui, M. Cesana, S. A. Hosseini, Q. Liao, I. Malanchini and J. Widmer, “A survey of anticipatory mobile networking: Context-based classification, prediction methodologies, and optimization techniques,” in IEEE Communications Surveys & Tutorials, vol. 19, no. 3, pp. 1790–1821, 2017.
S. Niknam, H. S. Dhillon and J. H. Reed, “Federated learning for wireless communications: Motivation, opportunities, and challenges,” in IEEE Communications Magazine, vol. 58, no. 6, pp. 46–51, Jun. 2020.
Y.-A. de Montjoye, L. Radaelli, V. K. Singh, and A. Pentland, “Unique in the shopping mall: On the re-identifiability of credit card metadata,” Science, vol. 347, no. 6221, pp. 536–539, 2015.
3rd Generation Partnership Project (3GPP), NG Radio Access Network (NG-RAN); Stage 2 Functional Specification of User Equipment (UE) Positioning in NG-RAN, 3GPP TS 38.305, Release 18, Version 18.1.0, May 2024.
N. Mehrabi, F. Morstatter, N. Saxena, K. Lerman, and A. Galstyan, “A survey on bias and fairness in machine learning,” ACM Computing Survey, vol. 54, no. 6, pp. 1–35, Jul. 2021.
S. Wachter, B. Mittelstadt, and C. Russell, “Counterfactual explanations without opening the black box: Automated decisions and the GDPR,” Harvard Journal of Law & Technology, vol. 31, no. 2, pp. 841–887, 2018.
European Commission, “AI Act”, Shaping Europe's Digital Future.
Organisation for Economic Co-operation and Development (OECD), Recommendation of the Council on Artificial Intelligence, OECD/LEGAL/0449, Paris, France: OECD, May 22, 2019.
National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1, Gaithersburg, MD, USA: U.S. Department of Commerce, Jan. 2023.
Council of Europe, Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, CETS No. 225, Strasbourg, France, May 17, 2024.
International Organization for Standardization and International Electrotechnical Commission, ISO/IEC 42001:2023, Information Technology—Artificial Intelligence—Management System, Geneva, Switzerland: ISO, 2023.
L. Floridi et al., “AI4People—An ethical framework for a good AI society: Opportunities, risks, principles, and recommendations,” Minds and Machines, vol. 28, pp. 689–707, 2018.
C. Dwork and A. Roth, “The algorithmic foundations of differential privacy,” Foundations and Trends in Theoretical Computer Science, vol. 9, no. 3–4, pp. 211–407, Aug. 2014.
B. McMahan, E. Moore, D. Ramage, S. Hampson, and B. Agüera y Arcas, “Communication-efficient learning of deep networks from decentralized data,” in Proceedings of 20th International Conference Artificial Intelligence and Statistics, PMLR, vol. 54, 2017 pp. 1273–1282.
International Organization for Standardization and International Electrotechnical Commission, ISO/IEC 42005:2025, Information Technology—Artificial Intelligence (AI)—AI System Impact Assessment, Geneva, Switzerland: ISO, 2025.