AIPolicyTracker
RegisterFree · sent to your work emailEU AI ActISO/IEC 42001

AI Data Governance Register

Formats: XLSX and DOCX · Version v1 · Built from dataset bb068ecd9dad · CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.

In brief

The AI Data Governance Register is a free XLSX and DOCX register for EU AI Act and ISO/IEC 42001. One row per dataset that trains, tests or feeds an AI system: provenance, personal data, lawful basis or licence, bias checks and retention, with a procedure and the data duties on record.

Format
XLSX and DOCX · Register
Version
v1, built 28 Sep 2026
Duties cited
9 from 6 instruments
Rows from the records
9
Written for
Deployer / user organisation, Provider / developer, Public authority / government body
Price and licence
Free · CC BY 4.0

What's inside

  • Datasets register with dropdowns for use, personal data and bias checks
  • Procedure document: acceptance criteria, quality and bias checks, retention
  • Data duties sheet: data governance, privacy and copyright duties on record

Preview

The sheets and sections of version v1, as built. Columns marked ▾ have a dropdown; ƒ is a formula.

Sheet: Datasets · 13 columns · blank, 200 rows ready to fill
First rows of the Datasets sheet
DatasetAI system(s) using itData ownerUsed for ▾Source and provenancePersonal data ▾Special-category data ▾Lawful basis / licenceBias and representativeness checked ▾Quality checks doneRetentionLast reviewEvidence link
Rows are yours to fill; the dropdowns, formulas and colour rules are already in place.

One row per dataset that trains, tests or feeds an AI system, including licensed and scraped data.

Sheet: Data duties · 14 columns · 9 rows from the records
First rows of the Data duties sheet
DutyCategoryInstrumentJurisdictionWho it bindsNatureSource referenceApplies fromWhat it requiresEvidence a reviewer expectsISO/IEC 42001NIST AI RMFVerificationRecord
Apply data governance and quality criteria to training, validation and testing dataData governance and qualityEU AI ActEuropean UnionProvider / developerLegal requirementArticle 102027-12-02High-risk AI systems that use data-driven techniques must be developed on training, validation and testing data sets meeting quality criteria: appropriate goverDataset documentation (datasheet); Bias examination reportAnnex A controls on data for AI systemsMAP 2.3, MEASURE 2.1, MEASURE 2.11Source-linkedhttps://aipolicytracker.org/obligations/eu-ai-act-data-governance
Meet general-purpose AI model provider obligationsCopyright and training-data transparencyEU AI ActEuropean UnionGeneral-purpose AI model providerLegal requirementArticle 53 and Annexes XI–XII2025-08-02Providers of general-purpose AI models must keep technical documentation (Annex XI), provide information to downstream providers integrating the model (Annex XIPublic summary of training content; Copyright compliance policyAnnex A controls on data provenance and documentationNIST AI 600-1 (Generative AI profile) — intellectual property and data privacy risksSource-linkedhttps://aipolicytracker.org/obligations/eu-ai-act-gpai-provider-obligations
Deployers must ensure input data they control is relevant and representativeData governance and qualityEU AI ActEuropean UnionDeployer / user organisation, Public authority / government bodyLegal requirementArticle 26(4)2027-12-02To the extent a deployer controls the data fed into a high-risk AI system, it must make sure that input data is relevant to, and sufficiently representative forInput-data quality checklist; Input-data validation resultsAnnex A.7.4, A.7.6MAP 2.3, MEASURE 2.2Verified against the official source 26 Sep 2026https://aipolicytracker.org/obligations/eu-ai-act-art-26-4-deployer-input-data
Deployers must use the provider's transparency information in their data protection impact assessmentPrivacy and personal-data protectionEU AI ActEuropean UnionDeployer / user organisation, Public authority / government bodyLegal requirementArticle 26(9)2027-12-02Where a deployer of a high-risk AI system is required to carry out a data protection impact assessment under Article 35 of the GDPR or Article 27 of the Law EnfData protection impact assessment citing the provider's Article 13 informationClause 6.1.4; Annex A.5.2MAP 3.1, MEASURE 2.10Verified against the official source 26 Sep 2026https://aipolicytracker.org/obligations/eu-ai-act-art-26-9-dpia-using-provider-information
Process personal data only with valid consent or a legitimate use, after noticePrivacy and personal-data protectionIndia DPDP ActIndiaProvider / developer, Deployer / user organisationLegal requirementSections 4 to 7Personal data may be processed only for a lawful purpose with the individual's free, specific, informed and unambiguous consent, or for certain legitimate uses Consent records and noticesAnnex A controls on data for AI systemsSource-linkedhttps://aipolicytracker.org/obligations/india-dpdp-consent-and-notice
Collect and use personal information only with consent and for the stated purposePrivacy and personal-data protectionNepal Privacy Act 2075NepalProvider / developer, Deployer / user organisation, Public authority / government bodyLegal requirementChapter on collection and protection of personal information (reviewer to cite sections)Personal information may be collected only by authorised persons for a lawful purpose with the individual's consent, and must not be used or disclosed for otherConsent and purpose recordsAnnex A controls on data for AI systemsSource-linkedhttps://aipolicytracker.org/obligations/nepal-privacy-act-consent-and-purpose

The recorded duties on training data, personal data and copyright.

Document outline (DOCX)

  1. AI data governance procedure
  2. Scope and roles
  3. Acceptance criteria
  4. Quality and bias checks
  5. Retention and deletion
  6. The duties this procedure serves
  7. Apply data governance and quality criteria to training, validation and testing data
  8. Meet general-purpose AI model provider obligations
  9. Deployers must ensure input data they control is relevant and representative
  10. Manage data quality, model development and monitoring across the lifecycle

How to use it

  1. 1Request the files. Enter your name, company and work email in the form on this page. The XLSX and DOCX download links arrive by email and work for 7 days.
  2. 2Read the README page. It states the version (v1), the dataset it was built from and the licence, so anyone reviewing your copy knows which records it reflects.
  3. 3Fill in your rows. Complete the "Datasets" sheet for your own systems. Dropdowns, formulas and colour rules are already set.
  4. 4Check the duties against your situation. The "Data duties" sheet lists the recorded duties with their source references. Mark which apply to you and follow each link to the official text.
  5. 5Complete the document. Work through the DOCX sections (AI data governance procedure, The duties this procedure serves) and replace each placeholder with your organisation's answer.
  6. 6Keep the evidence and watch for new versions. Link each completed row to the evidence that supports it. When the law on record changes, this template gets a new version and a changelog on this page.

Duties this template covers (9)

Each is cited in the file with its source reference and a link back to the record.

Legal basis

  • EU AI Act European Union · Partially applicable

Version history

Versions of AI Data Governance Register
VersionBuiltDatasetWhat changed
v1bb068ecd9dadFirst version, built from dataset bb068ecd9dad.

Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.

Frequently asked questions

What is in the AI Data Governance Register?

Datasets register with dropdowns for use, personal data and bias checks. Procedure document: acceptance criteria, quality and bias checks, retention. Data duties sheet: data governance, privacy and copyright duties on record.

Which duties does it cite?

9 recorded duties from EU AI Act, India DPDP Act, Nepal Privacy Act 2075 and NYC Local Law 144 (automated employment decision tools), including Article 10, Article 53 and Annexes XI–XII, Article 26(4), Article 26(9), Sections 4 to 7 and Chapter on collection and protection of personal information (reviewer to cite sections). Each row links to the record, and the record to the official source.

Who is it for?

The duties it cites fall on deployer / user organisation, provider / developer and public authority / government body. Whoever owns AI governance for those roles usually completes it, with the system owner supplying the facts.

Is it free?

Yes. Request the XLSX and DOCX with your work email on this page; the download links arrive by email, valid for 7 days. No account and no charge. Licensed CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.

How will I know when it changes?

Version v1 was built on 28 September 2026. The library is rebuilt daily; when a change to the records reaches this template it gets the next version, a changelog below and an entry in the templates feed.

Does completing it make us compliant?

No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.

Disclaimer: informational only, not legal advice. Verify every claim against the linked official sources and consult a qualified lawyer before acting.