Privacy and data-protection controls for AI
Ensures that personal data used to train, tune or run an AI system is processed on a documented lawful basis, with the assessments, notices, security and individual rights that data-protection law requires.
- Duties satisfied
- 8
- done properly, does the work
- Duties supported
- 5
- contributes; the duty needs more
- Jurisdictions
- 8
- Evidence items
- 4
How is it implemented?
The privacy function maps every AI data flow to a legal basis or recognised exception and records the conditions relied on, such as consent wording, the scope of a business-improvement or research exception, or a legitimate-interest balancing. Where the processing is high-risk, a data protection impact assessment is completed before it starts and merged with the wider AI impact assessment where possible. Privacy notices are updated to describe AI uses, minimisation and retention rules are applied to training and inference data, and rights requests and breach handling are extended to cover model outputs that could reveal personal data. Where a regime designates the organisation for enhanced duties, the officer, auditor and periodic assessment requirements are scheduled.
Which legal duties does it serve?
Satisfies means the control, operated properly, does the work the duty asks for. Supports means it contributes but the duty needs more. The official text decides; open it before relying on either.
European Union 3 duties
-
satisfies Legal requirement confidence highDeployers must use the provider's transparency information in their data protection impact assessment
EU AI Act · Article 26(9) · applies from 2 Aug 2026
DPIA built on the provider's documentation.
-
supports Legal requirement confidence highCarry out a fundamental rights impact assessment before deployment
EU AI Act · Article 27 · applies from 2 Aug 2026
Reuse of the DPIA workflow and findings.
-
supports Legal requirement confidence highDeployers of emotion recognition or biometric categorisation must inform exposed persons
EU AI Act · Article 50(3) · applies from 2 Aug 2026
Lawful basis and safeguards for biometric data.
India 3 duties
-
satisfies Legal requirement confidence highProcess personal data only with valid consent or a legitimate use, after notice
India DPDP Act · Sections 4 to 7
Legal basis and notice recorded for each training and inference data source.
-
satisfies Legal requirementSignificant Data Fiduciaries must appoint a DPO and run impact assessments and audits
India DPDP Act · Section 10
Schedules the DPO, independent audit and periodic DPIA duties.
-
supports Legal requirementImplement reasonable security safeguards and notify breaches
India DPDP Act · Section 8(5) and 8(6); DPDP Rules on breach intimation
Breach handling extended to model outputs and training data.
Nepal 1 duty
-
satisfies Legal requirement confidence highCollect and use personal information only with consent and for the stated purpose
Nepal Privacy Act 2075 · Chapter on collection and protection of personal information (reviewer to cite sections)
Consent and purpose documentation for Nepal personal data.
New York (United States) 1 duty
-
satisfies Legal requirement confidence highEmployers and employment agencies must disclose the data collected and their retention policy for the tool
NYC Local Law 144 (automated employment decision tools) · NYC Administrative Code Section 20-871(b)(3); 6 RCNY Section 5-303 · applies from 5 Jul 2023
Data notice with types, sources and retention.
Singapore 2 duties
-
satisfies Legal requirement confidence highIdentify consent or an applicable PDPA exception before using personal data in AI
PDPC AI advisory guidelines · Advisory guidelines, sections on consent, business improvement and research exceptions
Maps each AI data use to consent or a named exception and records the conditions.
-
supports Legal requirement confidence highNotify individuals about the use of personal data in AI recommendations and decisions
PDPC AI advisory guidelines · Advisory guidelines, section on notification obligation
Privacy notice content on AI data use.
United Arab Emirates 1 duty
-
satisfies Legal requirement confidence highConduct a data protection impact assessment for high-risk processing using new technologies
UAE PDPL · Article on data protection impact assessment (reviewer to cite article number)
DPIA before high-risk processing with new technologies.
United Kingdom 1 duty
-
satisfies Legal requirement confidence highCarry out a data protection impact assessment for high-risk AI processing
ICO AI guidance · UK GDPR Article 35; ICO guidance, accountability and governance section
DPIA with AI-specific sections before processing starts.
Texas (United States) 1 duty
-
supports Legal requirement confidence highGovernmental entities must not use AI for biometric identification from public data without consent where it infringes rights
Texas Responsible AI Governance Act (TRAIGA) · Business and Commerce Code Section 551.054 · applies from 1 Jan 2026
Consent and lawful basis for biometric data.
What evidence shows it is operating?
| Evidence | Type | What it shows |
|---|---|---|
| Data protection impact assessment for an AI system | Data protection impact assessment | |
| AI data-flow and legal-basis record | Register entry | Each dataset or inference flow with its purpose, legal basis or exception and the conditions met. |
| Privacy notice section on AI use | Disclosure or notice | |
| Independent data audit or DPO review | Audit or assurance report |
Owner: Data protection officer. Frequency: once per ai system.
Which risks does it address?
Subdomains of the MIT AI Risk Repository, with the incidents the AI Incident Database has recorded under each. Counts are live; they say how often a risk has materialised, not how well this control prevents it.
- 2.1 Compromise of privacy by obtaining, leaking or correctly inferring sensitive information Privacy & Security88 incidents · 80 risk entries
- 1.1 Unfair discrimination and misrepresentation Discrimination & Toxicity118 incidents · 83 risk entries
- 4.1 Disinformation, surveillance, and influence at scale Malicious actors138 incidents · 84 risk entries
Which standards clauses does it correspond to?
Clause numbers only. A reference means the standard asks for overlapping work, so evidence may be reusable; it never means the standard discharges a legal duty.
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| ISO/IEC 42001 | Annex A.7.2, A.7.3; Clause 6.1.4 | medium | |
| NIST AI RMF | MEASURE 2.10; MAP 4.1; GOVERN 1.1 | medium | |
| ISO/IEC 27001 | Annex A 5.34 Privacy and protection of PII | medium | |
| OWASP LLM Top 10 | LLM02 Sensitive Information Disclosure | medium |
Cite this record
AIPolicyTracker (2026). “Privacy and data-protection controls for AI”. https://aipolicytracker.org/controls/privacy-and-data-protection-for-ai (accessed 24 September 2026). Data licensed CC BY 4.0.
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- Which legal duties does "Privacy and data-protection controls for AI" satisfy?
- It is recorded as satisfying 8 and supporting 5 duties across European Union, India, Nepal, New York (United States), Singapore, United Arab Emirates, United Kingdom and Texas (United States). A mapping means the control, operated properly, does the work the duty asks for; the official text decides whether it is enough.
- What evidence shows this control is operating?
- Data protection impact assessment for an AI system, AI data-flow and legal-basis record, Privacy notice section on AI use and Independent data audit or DPO review. Owner: Data protection officer. Frequency: once per ai system.