The Law of Synthetic Data: Corporate and Financial Information in the European Union and the United States

Investigator: Maria Lucia Passador

Abstract:
This research examines the legal implications of synthetic data for corporate governance and financial regulation through a comparative analysis of the European Union and the United States. It proceeds from the premise that synthetic data should not be understood merely as a technical response to privacy constraints or data scarcity, but as a development that challenges the legal assumptions governing the production, use, and accountability of information within corporate and financial decision-making.

The project investigates the legal classification of synthetic data and their implications for directors’ duties, corporate disclosure, internal governance, model risk management, prudential supervision, and financial stability. It analyzes the extent to which existing legal standards remain adequate where material corporate and regulatory decisions increasingly rely upon information generated through statistical and computational processes rather than direct observation.

Adopting a comparative doctrinal methodology, the research contrasts the European regulatory framework—including the GDPR, the AI Act, financial-services legislation, and prudential supervision—with the United States’ framework of securities regulation, banking supervision, model risk management, and Delaware fiduciary law. By situating synthetic data within the broader architecture of corporate and financial law, the project seeks to develop a coherent legal framework for evaluating the governance, reliability, and institutional accountability of synthetic information in contemporary markets.