What does privacy by design mean for an AI project?

Answered

Build privacy in from the first decision about what information you will record, through every use of the data or model, to safe decommissioning. Request only data that is adequate, relevant and limited to what is necessary (data minimisation). If you buy a model or use a pre-trained one, you must still ensure any personal data used to train it meets your privacy standards and the law.

From the guidance

Primary (how) Data and AI Ethics Framework

You must design and build privacy into your project from the start. This includes: the very first decisions you make about what information you intend to record; every way that the data, or AI system built using this data, is used throughout your project; the safe decommissioning of the system and data set. This concept is referred to in the UK GDPR as privacy by design and default.

Secondary (normative) Data and AI Ethics Framework

The data you request and acquire must be adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed. This is known as data minimisation.

Secondary (normative) Data and AI Ethics Framework

Your project might not itself gather or process personal data. For example, if you procure an AI model from a third party or use a pre-trained model. Here you must still ensure that any personal data used to train these models meets your privacy standards and complies with relevant legislation.

Related questions