AI Training Data Provenance Checker
Regime

GDPR: what it asks of a training dataset list

When the company is established in the EU, or processes personal data of people in the EU: the lawful basis, purpose limitation, Article 9 special category data, criminal offence data under Article 10, children's personal data, information where data was not obtained from the person, records of processing and the DPIA, on datasets that carry personal data.

Cited when the GDPR trigger is ticked: established in the EU, or processing personal data of people in the EU.

Three kinds of data, three conditions

Findings that cite it

FindingClause
Origin not recordedGDPR Art. 30
Personal data with no lawful basis recorded, or reused from another purposeGDPR Art. 6
GDPR Art. 5
GDPR Art. 14
Article 9, criminal offence or children's data declaredGDPR Art. 35
GDPR Art. 9
GDPR Art. 10
GDPR Art. 8
Older than your N-year policy threshold (a threshold you set, not a legal deadline)GDPR Art. 5
Content where a label belongsGDPR Art. 5
Vendor data with no provider namedGDPR Art. 28

Source classes anchored here

35
Source classClause
Claims system extractGDPR Art. 5
GDPR Art. 6
GDPR Art. 30
Policy and underwriting systemGDPR Art. 5
GDPR Art. 6
GDPR Art. 30
CRM exportGDPR Art. 5
GDPR Art. 6
GDPR Art. 30
ERP and finance systemGDPR Art. 5
GDPR Art. 6
GDPR Art. 30
HR records and staff surveysGDPR Art. 5
GDPR Art. 6
GDPR Art. 30
Service desk and ticketingGDPR Art. 5
GDPR Art. 6
GDPR Art. 30
Application logs and telemetryGDPR Art. 5
GDPR Art. 6
GDPR Art. 30
Internal document storeGDPR Art. 5
GDPR Art. 6
GDPR Art. 30
Email archiveGDPR Art. 5
GDPR Art. 6
GDPR Art. 30
Data warehouse or lake extractGDPR Art. 5
GDPR Art. 6
GDPR Art. 30
Internal, system not namedGDPR Art. 5
GDPR Art. 6
GDPR Art. 30
Support and call transcriptsGDPR Art. 6
GDPR Art. 7
GDPR Art. 13
Chat logsGDPR Art. 6
GDPR Art. 7
GDPR Art. 13
Reviews on your own siteGDPR Art. 6
GDPR Art. 7
GDPR Art. 13
Survey and complaint free textGDPR Art. 6
GDPR Art. 7
GDPR Art. 13
Call recordingsGDPR Art. 6
GDPR Art. 7
GDPR Art. 13
Licensed vendor datasetGDPR Art. 14
GDPR Art. 28
Data broker listGDPR Art. 14
GDPR Art. 28
Annotation vendor outputGDPR Art. 14
GDPR Art. 28
Licensed image or media libraryGDPR Art. 14
GDPR Art. 28
Credit reference extractGDPR Art. 14
GDPR Art. 28
Government open dataGDPR Art. 14
Academic or research datasetGDPR Art. 14
Open benchmarkGDPR Art. 14
Public register or recordsGDPR Art. 14
Open source codeGDPR Art. 14
Forum postsGDPR Art. 14
GDPR Art. 6
News articlesGDPR Art. 14
GDPR Art. 6
Social media postsGDPR Art. 14
GDPR Art. 6
General web crawlGDPR Art. 14
GDPR Art. 6
Specific website scrapeGDPR Art. 14
GDPR Art. 6
Data shared under an agreementGDPR Art. 14
GDPR Art. 28
Joint venture dataGDPR Art. 14
GDPR Art. 28
Reinsurer, broker or bank feedGDPR Art. 14
GDPR Art. 28
Industry consortium dataGDPR Art. 14
GDPR Art. 28

GDPR: every clause cited

11 of the 40 held

The requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.

GDPR Art. 5Principles relating to processing of personal data

Process personal data lawfully, fairly and in a transparent manner; collect it for specified, explicit and legitimate purposes and do not process it further in a way incompatible with those purposes; keep it adequate, relevant and limited to what the purpose needs; keep it accurate and up to date, erasing or rectifying inaccurate data without delay; keep it in a form permitting identification no longer than the purpose requires; and secure it against unauthorised or unlawful processing and against accidental loss, destruction or damage using appropriate technical or organisational measures. The controller is responsible for all six principles and must be able to demonstrate compliance with them.

What an auditor asks to see: The purpose recorded for each processing activity, stated specifically enough that a later use can be tested against it; Retention schedule per data category with the criteria that set each period, and deletion evidence showing the schedule actually runs; Minimisation analysis per collection point showing why each field is necessary for the stated purpose; Accuracy controls: how inaccurate data is detected, and records of rectification or erasure carried out without delay; The compatibility assessment for any further processing carried out for a new purpose; Assurance output that demonstrates compliance rather than asserts it, such as control testing, internal audit or DPO reporting
What an auditor will probe: Purposes written so broadly, for example business purposes or service improvement, that no later use could ever be incompatible with them; Retention periods published in a policy but implemented in no system, so data is in fact kept indefinitely; Accountability treated as holding the documents rather than being able to show the principles were applied; Minimisation never revisited after launch, so fields added for a discontinued feature keep being collected
Source: GDPR
GDPR Art. 6Lawfulness of processing

Process personal data only where at least one lawful basis applies: the data subject's consent, necessity for a contract with the data subject or pre-contractual steps at their request, compliance with a legal obligation, protection of vital interests, performance of a public interest task or exercise of official authority, or legitimate interests that are not overridden by the data subject's interests, rights and freedoms. Public authorities cannot rely on legitimate interests for processing carried out in performance of their tasks. Where the basis is legal obligation or public task, that basis must be laid down in Union or Member State law and the purpose must be determined in it. Before processing for a purpose other than the one collected for, without consent or a legal mandate, assess compatibility against the link between the purposes, the context of collection, the nature of the data, the consequences for the data subject and the safeguards in place.

What an auditor asks to see: A lawful basis recorded per processing activity, not per system or per department; Legitimate interests assessments showing the interest pursued, the necessity test and the balancing against the data subject's rights; The Union or Member State provision cited where the basis is legal obligation or public task; Compatibility assessments for each secondary use, covering the five factors Article 6(4) names; Evidence that the basis stated to the data subject in the privacy information matches the one recorded internally
What an auditor will probe: Consent recorded as the basis where the processing would happen regardless of the answer, which makes it neither free nor the real basis; Legitimate interests asserted with no balancing test on file, or a balancing test that never reaches an adverse conclusion for any activity; One lawful basis applied to a whole system that covers several distinct processing purposes; The basis switched after the fact when the first one fails, rather than settled before processing began
Source: GDPR
GDPR Art. 7Conditions for consent

Where processing rests on consent, be able to demonstrate that the data subject consented. Where the consent request forms part of a wider written declaration, present it in a manner clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language. Inform the data subject before consenting that consent may be withdrawn at any time, make withdrawal as easy as giving consent, and treat processing carried out before withdrawal as still lawful. Consent is not freely given where performance of a contract, including provision of a service, is made conditional on consent to processing that the contract does not require.

What an auditor asks to see: Consent records capturing who consented, when, to what wording, and through what mechanism; The consent wording and interface as presented, versioned, so an old record can be tied to what was actually shown; The withdrawal mechanism, with evidence it works and takes no more steps than giving consent did; Evidence that consent requests bundled inside terms or a wider declaration are visually and textually separated; Per service, the analysis of which processing is genuinely necessary for the contract and which rests on consent
What an auditor will probe: Consent logged as a boolean with no record of the wording shown, so the organisation cannot demonstrate what was agreed to; Withdrawal routed through a support ticket or a postal address while giving consent was a single click; Service access blocked on consent to analytics or marketing the service does not need; Pre-ticked boxes, silence, or continued use of a site treated as consent
Source: GDPR
GDPR Art. 8Conditions applicable to child's consent

Where consent is the lawful basis and information society services are offered directly to a child, processing the child's personal data on the child's own consent is lawful only from age 16, or from the lower age a Member State has set in law, which may be no lower than 13. Below that age the processing is lawful only to the extent consent is given or authorised by the holder of parental responsibility, and the controller must make reasonable efforts to verify that it was, taking available technology into consideration.

What an auditor asks to see: The assessment of whether the service is an information society service offered directly to children; The age threshold applied per Member State, with evidence the applicable national lower age was checked rather than assumed; The age assurance mechanism, and the reasoning for why it is a reasonable effort given available technology; Parental authorisation records where the user is below the threshold, including the verification carried out on the parent; The procedure and records for what happens when a user is identified as under age after registration
What an auditor will probe: A self declared date of birth with no verification at all treated as reasonable effort; A single threshold of 16 applied across the Union without checking the Member States that set 13, 14 or 15; Parental consent captured from an email address that is never verified as belonging to a parent; The service judged not child directed on the basis of its terms of use rather than its actual audience
Source: GDPR
GDPR Art. 9Processing of special categories of personal data

Do not process personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, nor genetic data, biometric data processed to uniquely identify a person, data concerning health, or data concerning a person's sex life or sexual orientation, unless one of the Article 9(2) conditions applies: explicit consent, employment and social security law obligations, vital interests where the data subject cannot consent, the legitimate activities of a not-for-profit body, data manifestly made public by the data subject, legal claims or courts acting judicially, substantial public interest under Union or Member State law, preventive or occupational medicine and health or social care under an obligation of professional secrecy, public health, or archiving, research and statistics under Article 89(1). The condition applies in addition to an Article 6 lawful basis, never in place of it.

What an auditor asks to see: An inventory identifying where special category data is held, including where it is inferred rather than collected; The Article 9(2) condition recorded per activity alongside its separate Article 6 basis; The Union or Member State law relied on where the condition requires one, cited to the provision; Explicit consent records showing the consent was explicit and specific to the special category processing; Professional secrecy or equivalent confidentiality obligations evidenced for staff handling health data under point (h)
What an auditor will probe: Special category data inferred from behaviour, purchases or free text and never recognised as in scope; An Article 6 basis recorded with no Article 9 condition, or the two conflated into a single entry; Explicit consent asserted from the same tick box used for ordinary consent; Substantial public interest claimed without identifying the Union or Member State law that authorises it
Source: GDPR
GDPR Art. 10Processing of personal data relating to criminal convictions

Process personal data relating to criminal convictions and offences, or related security measures, only under the control of official authority or where Union or Member State law authorises the processing and provides appropriate safeguards for the rights and freedoms of data subjects. A comprehensive register of criminal convictions may be kept only under the control of official authority. An Article 6 lawful basis is required in addition.

What an auditor asks to see: Identification of where conviction and offence data is processed, including screening and vetting results and incident records; The Union or Member State provision authorising the processing, and the safeguards that provision requires; Evidence the required safeguards are actually implemented rather than merely cited; Access restriction and retention applied specifically to this data, tighter than for ordinary personal data; Confirmation that no comprehensive register of convictions is maintained outside official authority
What an auditor will probe: Background screening results retained on the personnel file indefinitely after the hiring decision is made; Reliance on the candidate's consent where national law, not consent, is the authorisation the Article requires; Offence data captured in incident reports or free text fields and never treated as Article 10 data; The authorising law identified but the specific safeguards it mandates never mapped to a control
Source: GDPR
GDPR Art. 13Information to be provided where personal data are collected

Where personal data is collected from the data subject, provide at the time it is obtained the identity and contact details of the controller and any representative, the contact details of the data protection officer, the purposes and the legal basis, the legitimate interests where that is the basis, the recipients or categories of recipient, and any intention to transfer to a third country with the existence or absence of an adequacy decision and, for Article 46, 47 or 49(1) transfers, reference to the safeguards and how to obtain a copy. Provide in addition the storage period or the criteria used to determine it, the existence of the rights of access, rectification, erasure, restriction, objection and portability, the right to withdraw consent where consent is the basis, the right to lodge a complaint with a supervisory authority, whether providing the data is a statutory or contractual requirement and the consequences of not providing it, and the existence of automated decision-making including profiling with meaningful information about the logic involved and its significance and envisaged consequences. Before further processing for a new purpose, provide that purpose and the further information first.

What an auditor asks to see: The privacy notice mapped item by item against every information element Article 13 lists; Evidence of the point and timing at which the notice is presented for each collection channel, including forms, telephone and in person; The storage periods or criteria as published, reconciled against the actual retention schedule; The published description of automated decision-making logic, and the reasoning for why it is meaningful to a data subject; Records showing new purpose information was given before the further processing started, with dates
What an auditor will probe: Recipients described only as third parties or trusted partners, which names neither a recipient nor a category; Retention shown as for as long as necessary, which is neither a period nor a criterion; The notice linked from a page footer but not presented at the point of collection, so it is not provided at the time the data is obtained; Automated decision-making logic described in terms that would fit any system, leaving the data subject nothing to contest
Source: GDPR
GDPR Art. 14Information where personal data have not been obtained from the data subject

Where personal data has not been obtained from the data subject, provide the same identity, contact, purpose, legal basis, recipient and transfer information as Article 13, plus the categories of personal data concerned and the source the data came from including whether it was a publicly accessible source. Provide it within a reasonable period and at the latest within one month of obtaining the data, or at the latest at the first communication with the data subject if the data is used to communicate with them, or at the latest when the data is first disclosed to another recipient. The obligation does not apply where the data subject already has the information, where provision proves impossible or would involve disproportionate effort in which case appropriate protective measures including making the information publicly available must be taken, where obtaining or disclosure is expressly laid down by Union or Member State law with appropriate safeguards, or where the data must remain confidential under an obligation of professional secrecy.

What an auditor asks to see: A source register showing, per dataset, where the data came from and whether the source was publicly accessible; Evidence of the notification sent with its date, tested against the one month, first communication and first disclosure triggers; The disproportionate effort assessment where the exemption is relied on, showing what was weighed rather than only that a conclusion was reached; The alternative protective measures put in place under that exemption, including where the information was made publicly available; Supplier contract terms requiring the source of the data and the lawfulness of its collection to be disclosed
What an auditor will probe: Purchased or enriched marketing data used with no Article 14 notification at all, which is the most common finding in this area; Disproportionate effort claimed because notifying is inconvenient or costly rather than genuinely disproportionate; The source recorded as a vendor name with no indication of where the vendor itself obtained the data; Notification sent at the first marketing contact months after the data was obtained, missing the one month limit
Source: GDPR
GDPR Art. 28Processor

Use only processors providing sufficient guarantees to implement appropriate technical and organisational measures such that the processing meets the Regulation's requirements and protects the rights of the data subject. A processor must not engage another processor without the controller's prior specific or general written authorisation, and under a general authorisation must inform the controller of intended additions or replacements so the controller can object. The processing must be governed by a written contract or other legal act binding the processor to the controller, setting out the subject matter and duration, the nature and purpose, the type of personal data, the categories of data subjects and the controller's obligations and rights, and stipulating that the processor processes only on documented controller instructions including as to transfers, ensures persons authorised to process are under a duty of confidentiality, takes all Article 32 measures, respects the sub-processor conditions, assists the controller in responding to data subject rights requests, assists with Articles 32 to 36, deletes or returns all personal data at the controller's choice at the end of the service and deletes existing copies unless law requires retention, and makes available all information needed to demonstrate compliance and allows for and contributes to audits and inspections. The processor must immediately inform the controller if it considers an instruction infringes data protection law. The same obligations must be imposed on any sub-processor, and the initial processor remains fully liable for the sub-processor's performance. A processor that determines purposes and means is a controller for that processing.

What an auditor asks to see: A processor inventory reconciled against the vendor register or accounts payable, so no processor is missing from it; The Article 28(3) contract for each processor, checked clause by clause against the eight stipulations the Article names; Due diligence evidence gathered before appointment showing sufficient guarantees, distinct from the signed contract; The sub-processor authorisation position for each processor, the current sub-processor list, and evidence changes were notified; Audit or assurance rights exercised in practice, such as a report reviewed with findings tracked, and end of service deletion certificates
What an auditor will probe: The processor's own standard terms accepted, which commonly omit the audit right, the deletion choice and the instruction infringement notice; A processor inventory that misses tools adopted directly by individual teams, which is where undocumented processing usually sits; Sufficient guarantees evidenced only by the existence of the contract, with no assessment carried out before appointment; Sub-processor lists published by the processor and never actually reviewed, so the right to object is theoretical
Source: GDPR
GDPR Art. 30Records of processing activities

Maintain a written, including electronic, record of processing activities under the controller's responsibility containing the name and contact details of the controller, any joint controller, the representative and the data protection officer, the purposes of the processing, a description of the categories of data subjects and of personal data, the categories of recipients including those in third countries and international organisations, any transfers to a third country or international organisation with that destination identified and, for transfers under the second subparagraph of Article 49(1), the documentation of suitable safeguards, the envisaged time limits for erasure of each category where possible, and a general description of the Article 32(1) technical and organisational security measures where possible. A processor must maintain an equivalent record of the categories of processing carried out on behalf of each controller. Make the record available to the supervisory authority on request. The obligation does not apply to an organisation employing fewer than 250 persons unless the processing is likely to result in a risk to the rights and freedoms of data subjects, is not occasional, or includes special category or criminal offence data.

What an auditor asks to see: The record of processing activities in full, checked against the seven controller elements, or the four processor elements, the Article lists; Version history showing when each entry was last reviewed and by whom; Reconciliation of the record against a system inventory or data flow map, to show nothing is missing rather than that the entries read well; The transfer entries with the third country identified and the safeguard documentation referenced; Where the fewer than 250 persons exemption is claimed, the assessment against all three disqualifying conditions
What an auditor will probe: Records written once during the implementation project and never updated against reality, so they describe systems long replaced and omit those adopted since; Entries written at the level of a department or a system rather than a processing activity, which loses the purpose that everything else hangs off; Erasure time limits left blank throughout on the where possible qualifier, while a retention schedule exists elsewhere in the organisation; The small organisation exemption claimed on headcount alone, ignoring that regular non-occasional processing disqualifies it
Source: GDPR
GDPR Art. 35Data protection impact assessment

Where a type of processing, in particular using new technologies and taking account of the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data before the processing begins; a single assessment may address a set of similar operations presenting similar risks. An assessment is required in particular for systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions producing legal or similarly significant effects are based, for large scale processing of special category or criminal offence data, and for systematic monitoring of a publicly accessible area on a large scale. Seek the advice of the data protection officer where one is designated, and where appropriate seek the views of data subjects or their representatives. The assessment must contain at least a systematic description of the envisaged operations and purposes including any legitimate interest pursued, an assessment of the necessity and proportionality of the operations in relation to the purposes, an assessment of the risks to the rights and freedoms of data subjects, and the measures envisaged to address those risks including safeguards, security measures and mechanisms to protect personal data and demonstrate compliance. Carry out a review where necessary and at least when the risk represented by the processing operations changes.

What an auditor asks to see: The screening or threshold process applied to new and changed processing, with its outcomes recorded including the negative ones; Completed assessments checked against the four minimum content elements Article 35(7) requires; The data protection officer's advice sought and given on each assessment, recorded as advice rather than as approval; Where the views of data subjects were sought, the record of what was asked and what came back, or the reasoning for not seeking them; Review records showing assessments were revisited when the processing or its risk changed, with the date and the trigger
What an auditor will probe: An assessment opened at project start and never revisited, so its residual risk conclusion is never tested against how the processing actually turned out; Necessity and proportionality asserted in a sentence, with all the substance of the assessment sitting in the security measures; Risk assessed to the organisation rather than to the rights and freedoms of the individuals the processing affects; Screening applied only to new projects, so material change to existing high risk processing never triggers an assessment; The data protection officer asked to approve the assessment rather than to advise on it, which compromises the independence Article 38(3) requires
Source: GDPR