AIPolicyTracker
Process Owner: Data protection officer Once per AI system

Privacy and data-protection controls for AI

Ensures that personal data used to train, tune or run an AI system is processed on a documented lawful basis, with the assessments, notices, security and individual rights that data-protection law requires.

Duties satisfied
8
done properly, does the work
Duties supported
5
contributes; the duty needs more
Jurisdictions
8
Evidence items
4

How is it implemented?

The privacy function maps every AI data flow to a legal basis or recognised exception and records the conditions relied on, such as consent wording, the scope of a business-improvement or research exception, or a legitimate-interest balancing. Where the processing is high-risk, a data protection impact assessment is completed before it starts and merged with the wider AI impact assessment where possible. Privacy notices are updated to describe AI uses, minimisation and retention rules are applied to training and inference data, and rights requests and breach handling are extended to cover model outputs that could reveal personal data. Where a regime designates the organisation for enhanced duties, the officer, auditor and periodic assessment requirements are scheduled.

Which legal duties does it serve?

Satisfies means the control, operated properly, does the work the duty asks for. Supports means it contributes but the duty needs more. The official text decides; open it before relying on either.

European Union 3 duties

India 3 duties

Nepal 1 duty

New York (United States) 1 duty

Singapore 2 duties

United Arab Emirates 1 duty

United Kingdom 1 duty

Texas (United States) 1 duty

What evidence shows it is operating?

Evidence this control produces
EvidenceTypeWhat it shows
Data protection impact assessment for an AI systemData protection impact assessment
AI data-flow and legal-basis recordRegister entryEach dataset or inference flow with its purpose, legal basis or exception and the conditions met.
Privacy notice section on AI useDisclosure or notice
Independent data audit or DPO reviewAudit or assurance report

Owner: Data protection officer. Frequency: once per ai system.

Which risks does it address?

Subdomains of the MIT AI Risk Repository, with the incidents the AI Incident Database has recorded under each. Counts are live; they say how often a risk has materialised, not how well this control prevents it.

Which standards clauses does it correspond to?

Clause numbers only. A reference means the standard asks for overlapping work, so evidence may be reusable; it never means the standard discharges a legal duty.

Framework references
FrameworkReferenceNoteConfidence
ISO/IEC 42001Annex A.7.2, A.7.3; Clause 6.1.4medium
NIST AI RMFMEASURE 2.10; MAP 4.1; GOVERN 1.1medium
ISO/IEC 27001Annex A 5.34 Privacy and protection of PIImedium
OWASP LLM Top 10LLM02 Sensitive Information Disclosuremedium

Cite this record

AIPolicyTracker (2026). “Privacy and data-protection controls for AI”. https://aipolicytracker.org/controls/privacy-and-data-protection-for-ai (accessed 24 September 2026). Data licensed CC BY 4.0.

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.

Frequently asked questions

Which legal duties does "Privacy and data-protection controls for AI" satisfy?
It is recorded as satisfying 8 and supporting 5 duties across European Union, India, Nepal, New York (United States), Singapore, United Arab Emirates, United Kingdom and Texas (United States). A mapping means the control, operated properly, does the work the duty asks for; the official text decides whether it is enough.
What evidence shows this control is operating?
Data protection impact assessment for an AI system, AI data-flow and legal-basis record, Privacy notice section on AI use and Independent data audit or DPO review. Owner: Data protection officer. Frequency: once per ai system.