Dr Nóra Ní Loideáin

Contact details

Name:
Dr Nóra Ní Loideáin
Qualifications:
B.A., LL.B., LL.M. (Hons) (National University of Ireland, Galway); Ph.D. (University of Cambridge)
Position:
Director and Reader (Associate Professor), Information Law and Policy Centre
Institute:
Institute of Advanced Legal Studies
Location:
Institute of Advanced Legal Studies 17 Russell Square London WC1B 5DR
Email address:
Nora.NiLoideain@sas.ac.uk
Website:
https://ials.sas.ac.uk/people/dr-nora-ni-loideain

Research Summary and Profile

Research interests:
Law
Regions:
Africa, England, Europe, Ireland, United Kingdom
Summary of research interests and expertise:

Dr Nora Ni Loideain is Associate Professor in Law (Reader) and Director of the Information Law & Policy Centre at the University of London’s Institute of Advanced Legal Studies. Her research focuses on EU law, European human rights law, and technology regulation, particularly within the contexts of privacy and data protection. Nora previously held the posts of: Visiting Fellow, Australian National University; Visiting Lecturer in Law, King’s College London; Research Fellow and Affiliated Lecturer in Law, University of Cambridge.

She has published on topics including AI Digital Assistants, facial recognition, national security surveillance, and cross-border transfers. With her work being cited by leading institutions including the BBC, the United Nations, and the UK House of Lords. Her recent book is the first doctrinal and comparative analysis of the role of Article 8 ECHR within EU data protection and data retention law and the evolving dialogue between the ECHR and EU legal orders concerning law enforcement and national security. It also examines the right to privacy within the jurisprudence of the CJEU and the European Court of Human Rights in an era of AI and data-driven surveillance: Ni Loideain, EU Data Privacy Law and Serious Crime (Oxford University Press 2025).

In 2024, Nora was appointed joint Editor-in-Chief of leading law journal International Data Privacy Law (OUP). She advises and consults on the regulation of AI and emerging technologies. With recent work in the area law enforcement and intelligence for the Alan Turing Institute and was co-author of the following report: The Future of Biometric Technology for Policing and Law Enforcement (Alan Turing Institute 2024). In 2026, she was re-appointed to the UK Home Office's Science and Technology Ethics Advisory Committee (previously known as the 'Biometrics and Forensics Ethics Group') which provides independent advice ensuring the robustness of evidence underpinning biometrics and forensics policy development for public security within the Home Office.

Nora is a member of the Board of Trustees for the British and Irish Legal Information Institute (BAILII) and joint Editor-in-Chief of leading law journal International Data Privacy Law (Oxford University Press). She is a Senior Fellow at the University of Johannesburg and an Associate Fellow at the University of Cambridge Leverhulme Centre for the Future of Intelligence (LCFI). Nora holds BA, LLB, and LLM (Public Law) degrees from the National University of Ireland, Galway, and was awarded a PhD in EU law and European human rights law from the University of Cambridge.

Prior to her academic career, Nora was a Legal and Policy Officer for the Office of the Director of Public Prosecutions of Ireland and clerked for the Irish Supreme Court.

Publication Details

Related publications/articles:

Date Details
01-Sep-2025 EU Data Privacy Law and Serious Crime: Data Retention and Policymaking

Monographs

EU Data Privacy Law and Serious Crime: Data Retention and Policymaking offers a comprehensive and comparative study of the right to private life and data retention within the EU and ECHR legal orders. Exploring EU data retention law and the role of Article 8 ECHR in a variety of contexts, from communications data to passenger name record data, the book casts a spotlight on the mainstreaming of the right to private life across EU policymaking, critically analysing the role of the European Commission and the CJEU as guardians of fundamental rights in their rights review of EU data retention measures.

The book examines the jurisprudence of the CJEU and ECtHR concerning data retention and State surveillance. Three key developments are identified that threaten the protection and future development of the right to private life within the EU and ECHR legal orders: the converging and diverging standards of the CJEU and ECtHR; the fraught dialogue between the CJEU and national courts; and the rise of the CJEU as the vanguard EU institution for data retention policymaking and supranational judicial scrutiny in Europe.

In this dynamic area of EU data protection law and European human rights law, this original and unique book traverses the future development of legal standards within the jurisprudence of the CJEU and ECtHR, giving policy recommendations on how to enhance the right to private life in future EU data retention policymaking. This book will appeal to academics, policymakers, and practitioners interested in the future of the right to privacy in an era of AI and data-driven surveillance.

01-Sep-2025 ‘Gathering of electronic evidence in punitive administrative proceedings in Ireland’ in S Tosza and S Lannier (eds), Gathering Electronic Evidence from Online Services Providers in Administrative Punitive Proceedings (University of Luxembourg 2025), 251-272 (open access)

Chapters

Administrative financial sanctions are an established feature in the regulatory toolkits of supervisory authorities of most legal systems in the EU. However, subject to a few exceptions, Ireland has been a late arrival to this practice. This gap did not go unnoticed and has in the past led to Ireland being criticised for being ‘out of step’ with its European counterparts, particularly its delay in providing for administrative financial sanctions in its legislation on competition law and data protection law.

Recent changes in enforcement powers in these areas have been (primarily) instigated by a growing wave of EU directives and regulations which provide for the imposition of these sanctions by the relevant competent authorities. Relatedly, it is essential to note at this juncture that no general legal framework applies to the collection of ‘digital evidence’ in Ireland.

Within this context, this chapter proceeds as follows. Section 2 provides an overview of the general legal framework and requirements applicable to the collection of evidence in administrative proceedings enshrined in Irish Constitutional Law, as applied and developed in the jurisprudence of the Irish courts (common law). Sections 3 and 4 identify relevant national competent authorities that may impose administrative financial sanctions and acquire digital evidence from Online Service Providers (OSPs) in the exercise of their investigatory and enforcement powers. Section 5 deals with the law and practice on the transfer of data as part of these proceedings both nationally and internationally. The chapter concludes with some reflections on the above findings.

01-May-2024 ‘Entering the next phase’ (2024) 14(2) International Data Privacy Law 87 (co-author with O. Lynskey)

Journal articles

01-Mar-2024 ‘Lawfulness and Police Use of Facial Recognition in the UK: Article 8 ECHR and Bridges v South Wales Police’ in R Matulionyte and M Zalnieriute (eds), Facial Recognition in the Modern State (Cambridge University Press 2024)

Chapters

Police use of facial recognition technologies is on the rise across Europe and beyond. Public authorities state that these powerful algorithmic systems could play a major role in assisting to prevent terrorism, reduce crime, and to safeguard vulnerable persons. There is also an international consensus that these systems pose serious risks to the rule of law and several human rights, including the right to private life, as guaranteed under the European Convention on Human Rights (ECHR).

The world’s first case examining the legality of a facial recognition system deployed by police, Bridges v South Wales Police, thus remains an important precedent for policymakers, courts, and scholars worldwide.

This chapter focuses on the role and influence of the right to private life, as enshrined in Article 8 ECHR, and the relevant case law of the European Court of Human Rights, in the ‘lawfulness’ assessment of the police use of live facial recognition in Bridges. A framework that the Court of Appeal for England and Wales held was ‘not in accordance with the law’ and therefore in breach of Article 8 ECHR. The analysis also considers the emerging policy discourse prompted by Bridges in the United Kingdom surrounding the need for new legislation, a significant shift away from the current AI governance approach of combining new ethical standards with existing law.

01-Jan-2024 Brexit

Chapters

Final version of this chapter was published in Eleni Kosta & Franziska Boehm (eds), The Law Enforcement Directive: A Commentary (Oxford University Press 2024).

The EU made legal history in its unprecedented step to grant adequacy decisions under both the EU General Data Protection Regulation (GDPR) and the EU Law Enforcement Directive (LED) to the UK. Of course, although the UK is now a third country, as a former EU Member State it is still considered part of the ‘European privacy family’. However, subsequent developments suggest that major divergences may be on the cards with respect to the relationship of the UK legal order with the EU and ECHR legal systems and the UK’s alignment with both concerning the protection of personal data.

This chapter identifies and examines the EU, UK, and international legal frameworks governing data sharing for law enforcement and security purposes established as a result of the UK's exit from the EU.The analysis discusses the overall negotiations process underpinning Brexit and examines the key resulting regimes, including the Trade and Cooperation Agreement (TCA) and the EU-UK data adequacy agreements granted under the GDPR and the LED.

The chapter concludes with some critical analysis and reflections on the above frameworks, with particular regard to the implications for the protection of EU fundamental rights, current compliance issues with EU law and Article 8 ECHR posed by the UK Investigtory Powers Act 2016, and how proposed reforms to the UK's Human Rights Act risk jeopardising the TCA and both EU-UK Adequacy Decisions.

Keywords: Brexit, data protection, data adequacy, law enforcement, GDPR, TCA, LED, EU law, EU fundamental rights, ECHR, right to privacy

13-Dec-2021 Rosemary Jay et al, Data Protection Law and Practice (5th edition) (Sweet & Maxwell 2020)

Review

Dr Nóra Ní Loideain reviews the 5th edition of a seminal textbook on data protection for legal practitioners for Society for Computers and Law.

19-Jun-2021 Enabling the use of health data for research: developing a POPIA Code of Conduct for research in South Africa

Articles

Globally, there has been a move toward ‘open science’ that includes the sharing of health data for research. The importance of data sharing for research is generally acknowledged, but this must only be done with legal and ethical procedures and protections in place. The use and sharing of health data for research in South Africa has changed with the coming into force of the Protection of Personal Information Act (POPIA). POPIA should ensure greater transparency and accountability in the use of personal information.

POPIA, however, adopts a principle-based approach to the regulation of personal information, and there is a lack of clarity and uncertainty in the application of some of these principles to the use of health data for research. POPIA provides for sector-specific responses through the development of codes of conduct. In this article, we discuss the need for a code of conduct for health research, and an approach that could be adopted in its development.

03-Jun-2021 Gender as Emotive AI and the Case of ‘Nadia’: Regulatory and Ethical Implications

Conference papers

Selected for presentation at the Privacy Law Scholars Conference 2021, Georgetown University (co-authored with Rachel Adams and Damian Clifford).

This paper unpacks the regulatory and ethical problematics of the artificial intelligence (AI) powered virtual assistant, ‘Nadia’, developed for use in the Australian Government’s National Disabilities Insurance Agency (NDIA).

We explore how Nadia is gendered female, utilises high-risk AI technologies, including emotive-inducing AI and machine learning to monitor highly sensitive health and biometric data, and was developed for use by a group deemed vulnerable to further human rights violations under international law.

Drawing from the human rights frameworks of the EU and the European Convention on Human Rights, particularly the rights to data protection law and privacy, we explore how a system like Nadia poses interferences with, and potential violations to, the fundamental human rights of vulnerable groups, and discuss what regulatory provisions and frameworks could have been put in place to safeguard Nadia.

Keywords: AI, Australia National Disability Insurance Agency (NDIA), biometrics, dignity, emotion monitoring, ethics, facial recognition, governance, regulation, gender, impact assessments, privacy, protection of personal data, virtual personal assistants, vulnerable groups

01-Jul-2020 ‘Regulating health research and respecting data protection: a global dialogue (2020) 10(2) International Data Privacy Law

Articles

(2020) 10(2) International Data Privacy Law - Special Symposium Issue on Health Research and Data Protection in Africa 115 (Editor and author) The global COVID-19 pandemic has focused minds sharply on the valuable role to be played by data collection and analysis for advancing health research, especially how it may help in informing and developing policy responses. Modern health research requires vast collections of data. Ensuring open access and wide sharing of these huge data sets that contain highly sensitive personal information within the international scientific community is also essential to the development of medical treatments and research breakthroughs. The importance of all of these factors drastically increases in times of emergency when rapid responses are urgently needed from the scientific community (such as the development of a vaccine). However, as the European Commission and academic commentators point out, any such measures must also be lawful and proportionate, comply with data protection law, and respect the fundamental rights of those who have shared their health data

24-Apr-2020 ‘Alexa to Siri and the GDPR: The Gendering of Virtual Personal Assistants and the Role of EU Data Protection Law’

Articles

(2020) 36 Computer Law and Security Review (co-author with R. Adams) With female names, voices and characters, artificially intelligent Virtual Personal Assistants such as Alexa, Cortana, and Siri appear to be decisively gendered female. Through an exploration of the various facets of gendering at play in the design of Siri, Alexa and Cortana, we argue that this gendering of VPAs as female may pose a societal harm, insofar as they reproduce normative assumptions about the role of women as submissive and secondary to men. In response, this article turns to examine the potential role and scope of data protection law as one possible solution to this problem. In particular, we examine the role of data privacy impact assessments that highlight the need to go beyond the data privacy paradigm, and require data controllers to consider and address the social impact of their products.

01-Dec-2019 'Addressing indirect discrimination and gender stereotypes in AI virtual personal assistants: the role of international human rights law'

Articles

(2019) 8(2) Cambridge International Law Journal 241 (co-author with R. Adams) Virtual personal assistants (VPAs) are increasingly becoming a common aspect of everyday living. However, with female names, voices and characters, these devices appear to reproduce harmful gender stereotypes about the role of women in society and the type of work women perform. Designed to ‘assist’, VPAs – such as Apple's Siri and Amazon's Alexa – reproduce and reify the idea that women are subordinate to men, and exist to be ‘used’ by men. Despite their ubiquity, these aspects of their design have seen little critical attention in scholarship, and the potential legal responses to this issue have yet to be fully canvassed. Accordingly, this article sets out to critique the reproduction of negative gender stereotypes in VPAs and explores the provisions and findings within international women's rights law to assess both how this constitutes indirect discrimination and possible means for redress. In this regard, this article explores the obligation to protect women from discrimination at the hands of private actors under the Convention on the Elimination of All Forms of Discrimination Against Women, and the work of the Committee on Discrimination Against Women on gender stereotyping. With regard to corporate human rights responsibilities, the role of the United Nations Guiding Principles on Business and Human Rights is examined, as well as domestic enforcement mechanisms for international human rights norms and standards, noting the limitations to date in enforcing human rights compliance by multinational private actors.

28-Jun-2019 ‘A port in the data-sharing storm: the GDPR and the Internet of things’

Articles

(2019) 4(2) Journal of Cyber Policy 178 The onward march of the ‘Internet of Things’ (IoT) heralds an all-encompassing data-driven society where the collection, analysis, sharing, and retention of personal data by service providers, machines and objects will be pervasive and ubiquitous, thereby normalising sustained data gathering from any source possible. In other words, the full realisation of the IoT would best be described as a data-sharing storm where there are no controls or safeguards on what data is shared, who it is shared with, or for what purposes data is used or re-used. As a legal framework that stipulates key principles and safeguards that must be employed when processing of personal data takes place within its scope of application, the EU General Data Protection Regulation (GDPR) represents a port in the data-sharing storm put forward by this vision of the IoT. This article examines what role the recent major upgrade of EU data protection law, under the GDPR, may play in addressing the data protection implications and challenges posed by the IoT for data controllers and processors.

22-May-2019 ‘Ethical and practical issues to consider in the governance of Data Sharing for Genomic and Human Research Data in South Africa: a meeting report’

Articles

AAS Open Res 2019, 2:15 (co-author with C. Staunton et al)

29-Nov-2018 A Bridge too Far? The Investigatory Powers Act 2016 and Human Rights Law” in in L. Edwards (ed), Law, Policy and the Internet (2nd ed., Hart, 2018)

Chapters

01-Feb-2018 An Unstoppable Force and an Immoveable Object? EU Data Protection Law and National Surveillance

Journal articles

 (2018) 8(1) International Data Privacy Law 1 (with C.Kuner, O.Lynskey, C.Millard, F.Cate & D.Svantesson)

01-Jan-2018 Children and Digital Rights

Articles

 (2018) 23(1) Communications Law 1 (with P.Wragg)

01-Nov-2017 Cape Town as a Smart and Safe City: Implications for Governance and Data Privacy (2017) 7(4) International Data Privacy Law 314

Journal articles

(2017) 7(4) International Data Privacy Law 314

01-Sep-2017 Review of R. Jay, Guide to the General Data Protection Regulation

Review

(London: Sweet & Maxwell, 2017) (2017) 22(4) Communications Law 140

Consultancy reports:

Date Details
2024 The Future of Biometric Technology for Policing and Law Enforcement (Alan Turing Institute 2024)

This Report explores the future of biometric technology for UK policing and law enforcement. It analyses technical trends and highlights where new regulatory measures may be required to facilitate responsible uses and restrictions of these systems for public safety purposes. It gathers insights from existing literature, research interviews with a range of experts, a workshop, and incorporates a nationally-representative public survey on biometric systems.

Our study shows that, in the next 5-10 years, the type of biometric systems and data available are likely to broaden dramatically. Moving beyond prevailing purposes of uniquely identifying or verifying individuals, the same technology may be used for making inferences about someone’s behaviour, emotional state, or classifying them into demographic groups, despite significant concerns over the scientific validity and potential benefits of such use cases. New developments such as frictionless biometric formats that require little or no physical contact, and multimodal systems which combine multiple biometric data sources, could also improve the reliability of biometric systems and, in turn, enhance law enforcement capabilities.

This research reinforces existing evidence that the UK’s legal framework for biometrics is inadequate and in need of reform. Current laws are failing to keep pace with changes to biometric technology, which risks undermining public confidence and trust in these systems. Nevertheless, the public survey conducted for this project has demonstrated support for police and law enforcement use of biometric identification and verification systems such as live facial recognition, but not for the use of inferential systems such as polygraph testing or emotion recognition. In general, the UK public is marginally optimistic about the benefits that biometrics could provide for crime reduction. However, many respondents expressed anxiety over the adequacy of safeguards to protect individuals from a range of risks, such as data misuse and discriminatory implications of certain emerging use cases.

To reassure the general public, maximise the benefits of biometric technologies and protect individual rights, our recommendations emphasise the need to simplify the complex web of existing regulatory and policy measures; introduce new protections for emerging biometric systems; and standardise testing and evaluation procedures. This should be achieved through updating existing biometrics legislation and developing new codes of practice for certain data types and systems. Such measures should address the risks, harms and purpose of specific use cases, distinguishing between established technologies, and novel use cases that may involve classification or inferential systems. Any new regulation or codes must apply consistent cross-sector standards for any systems used for public safety purposes, and establish mandatory requirements for independent system auditing and testing. 

This publication is licensed under the terms of the Creative Commons Attribution License 4.0 which permits unrestricted use, provided the original authors and source are credited.

Professional Affiliations

Professional affiliations:

Name Activity
Biometrics and Forensics Ethics Group, UK Home Office
International Data Privacy Law (Oxford University Press) Peer-reviewed journal editor

Collaborations:

Name Type Activity Start date End date
British and Irish Legal Information Institute Trustee 02-Sep-2019
Consultancy & Media
Available for consultancy:
Yes
Media experience:
Yes
Back to top