Pritechk Support  /  AI and Governance  /  Data and privacy

06/ 09

Knowledge area

Data, Privacy & Records

Is information used lawfully, appropriately and with enduring control?

Govern the data entering AI, the information it creates and the traces it leaves—from provenance and permitted use to retention, access, quality and records obligations.

What good
looks like.

01

Purpose limitation

Information is used for a clear, authorised and compatible purpose.

02

Minimum necessary

Collection, disclosure, prompt content and retention are constrained.

03

Provenance and quality

Material data sources, limitations and transformations are understood.

04

Records by design

Prompts, outputs and decisions are captured when they form part of the official record.

Make it
operational.

01

Map information flows

Trace collection, retrieval, inference, output, logging, sharing, storage and deletion.

02

Assess privacy

Identify authority, notice, disclosure, re-identification and individual impact.

03

Control knowledge sources

Set quality, access, currency, citation and stewardship rules.

04

Define the record

Determine what must be retained, where, for how long and with which audit trail.

Make the decision
reviewable.

01Data-flow and information asset map
02Privacy impact assessment
03Dataset or knowledge-source documentation
04Retention, access and records schedule

Design governance teams can operate.

Connect accountability, evidence and oversight to the way AI is actually delivered and used.

Start a conversation