# Privacy and data-protection controls for AI

- **Record type**: Control
- **Kind**: Process
- **Owner**: Data protection officer
- **Frequency**: Once per AI system
- **Duties served**: 13

## What the control achieves

Ensures that personal data used to train, tune or run an AI system is processed on a documented lawful basis, with the assessments, notices, security and individual rights that data-protection law requires.

## How it is typically implemented

The privacy function maps every AI data flow to a legal basis or recognised exception and records the conditions relied on, such as consent wording, the scope of a business-improvement or research exception, or a legitimate-interest balancing. Where the processing is high-risk, a data protection impact assessment is completed before it starts and merged with the wider AI impact assessment where possible. Privacy notices are updated to describe AI uses, minimisation and retention rules are applied to training and inference data, and rights requests and breach handling are extended to cover model outputs that could reveal personal data. Where a regime designates the organisation for enhanced duties, the officer, auditor and periodic assessment requirements are scheduled.

## Evidence it produces

- Data protection impact assessment for an AI system (data_protection_assessment)
- AI data-flow and legal-basis record (register_entry): Each dataset or inference flow with its purpose, legal basis or exception and the conditions met.
- Privacy notice section on AI use (disclosure_notice)
- Independent data audit or DPO review (audit_report)

## Legal duties this control serves

- Carry out a fundamental rights impact assessment before deployment — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-fundamental-rights-impact-assessment
- Collect and use personal information only with consent and for the stated purpose — Nepal Privacy Act 2075, Nepal (satisfies): https://aipolicytracker.org/obligations/nepal-privacy-act-consent-and-purpose
- Deployers must use the provider's transparency information in their data protection impact assessment — EU AI Act, European Union (satisfies): https://aipolicytracker.org/obligations/eu-ai-act-art-26-9-dpia-using-provider-information
- Deployers of emotion recognition or biometric categorisation must inform exposed persons — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-art-50-3-emotion-recognition-notice
- Process personal data only with valid consent or a legitimate use, after notice — India DPDP Act, India (satisfies): https://aipolicytracker.org/obligations/india-dpdp-consent-and-notice
- Implement reasonable security safeguards and notify breaches — India DPDP Act, India (supports): https://aipolicytracker.org/obligations/india-dpdp-security-and-breach-notification
- Significant Data Fiduciaries must appoint a DPO and run impact assessments and audits — India DPDP Act, India (satisfies): https://aipolicytracker.org/obligations/india-dpdp-significant-data-fiduciary-duties
- Identify consent or an applicable PDPA exception before using personal data in AI — PDPC AI advisory guidelines, Singapore (satisfies): https://aipolicytracker.org/obligations/singapore-pdpc-consent-or-exception-for-ai-data
- Notify individuals about the use of personal data in AI recommendations and decisions — PDPC AI advisory guidelines, Singapore (supports): https://aipolicytracker.org/obligations/singapore-pdpc-ai-notification
- Conduct a data protection impact assessment for high-risk processing using new technologies — UAE PDPL, United Arab Emirates (satisfies): https://aipolicytracker.org/obligations/uae-pdpl-impact-assessment-new-technologies
- Carry out a data protection impact assessment for high-risk AI processing — ICO AI guidance, United Kingdom (satisfies): https://aipolicytracker.org/obligations/uk-ico-dpia-for-ai
- Employers and employment agencies must disclose the data collected and their retention policy for the tool — NYC Local Law 144 (automated employment decision tools), New York (United States) (satisfies): https://aipolicytracker.org/obligations/us-new-york-city-local-law-144-data-policy-disclosure
- Governmental entities must not use AI for biometric identification from public data without consent where it infringes rights — Texas Responsible AI Governance Act (TRAIGA), Texas (United States) (supports): https://aipolicytracker.org/obligations/us-texas-responsible-ai-governance-act-traiga-government-biometric-identification-prohibition

## Standards clauses it corresponds to (clause numbers only)

- ISO/IEC 42001:2023: Annex A.7.2, A.7.3; Clause 6.1.4
- NIST AI RMF 1.0: MEASURE 2.10; MAP 4.1; GOVERN 1.1
- ISO/IEC 27001:2022: Annex A 5.34 Privacy and protection of PII
- OWASP Top 10 for LLM Applications: LLM02 Sensitive Information Disclosure

## MIT AI Risk Repository subdomains addressed

2.1, 1.1, 4.1

## Provenance

- **Record page**: https://aipolicytracker.org/controls/privacy-and-data-protection-for-ai
- **Official source**: none recorded — this record is incomplete, see https://aipolicytracker.org/gaps
- **Review status**: pending review
- **Confidence**: high
- **Facts last confirmed**: never confirmed against the official source
- **Retrieved**: 2026-09-24
- **Licence**: https://creativecommons.org/licenses/by/4.0/

> This record is a structured summary with a link to the official text. It is not legal advice. Open the official source before relying on any date or duty. How current each record type must be is published at https://aipolicytracker.org/verification; what a record must carry at all is published at https://aipolicytracker.org/coverage.
