Brief explanation: Privacy in AI means protecting personal data throughout the AI lifecycle, from data collection and model training through to deployment and decommissioning. Organisations should apply data minimisation, purpose limitation, and appropriate safeguards when personal data is used in AI systems.
Where it fits: Privacy supports responsible AI governance by ensuring that AI systems respect individuals' rights and comply with relevant data protection obligations. It is closely linked to the data governance requirements within an AI Management System.
Practical use:
- Conduct privacy impact assessments before deploying AI systems that process personal data
- Apply data minimisation principles when selecting training datasets
- Define and enforce purpose limitation for personal data used in AI
- Implement technical safeguards such as anonymisation or pseudonymisation where appropriate
- Review privacy controls as part of AI system lifecycle management
Evidence examples:
- Privacy impact assessments completed for AI systems handling personal data
- Data governance policies referencing AI-specific privacy requirements
- Records of data minimisation decisions during AI system design
- Evidence of anonymisation or pseudonymisation techniques applied
- Supplier data processing agreements covering AI use of personal data
Caveat: This is a learning aid and should be validated against the official ISO/IEC 42001:2023 standard and relevant organisational obligations.