What does privacy by design mean for an AI project?
Answered
Build privacy in from the first decision about what information you will record, through every use of the data or model, to safe decommissioning. Request only data that is adequate, relevant and limited to what is necessary (data minimisation). If you buy a model or use a pre-trained one, you must still ensure any personal data used to train it meets your privacy standards and the law.
From the guidance
Primary (how) Data and AI Ethics Framework
Section: What privacy means in practice
Read this in Data and AI Ethics Framework (opens in new tab)
Secondary (normative) Data and AI Ethics Framework
Section: Scoping and data acquisition
Read this in Data and AI Ethics Framework (opens in new tab)
Secondary (normative) Data and AI Ethics Framework
Section: Scoping and data acquisition
Read this in Data and AI Ethics Framework (opens in new tab)
Related questions
- Can I use AI to process personal data?
- Can I skip an ATRS record if some of the information is exempt from FOI?
- What safeguards does Article 22 require for solely automated decisions?
- What lawful basis can a public authority use for AI that processes personal data?
- Do AI inferences about people count as special category data?