Industry consortium data
Pooled industry data comes with the pool's rules on use, usually narrower than members assume.
What to record for it
The consortium, the rules on use, the contribution and the extract date.
Personal data is possible: where your personal data column is blank the checker says it could not determine it.
A line that places here
exampleFraud pool extract | industry consortium | data sharing agreement
What the checker reads on these lines
7 of the 12 findings- Origin not recorded: Where did this dataset come from, and who in the company can show it?
- Terms not recorded: What terms did this data come under, and where is the copy?
- Personal data with no lawful basis recorded, or reused from another purpose: What is the lawful basis for training on this data, and has reuse for a new purpose been tested for compatibility?
- Article 9, criminal offence or children's data declared: Which condition covers processing this kind of data for training, and has a data protection impact assessment been done?
- No version or snapshot date: Which version of this dataset trained the model, and is that copy kept?
- High-risk use with no bias examination recorded: Has this dataset been examined for bias against the people the model decides about, and where is the record?
- Older than your N-year policy threshold (a threshold you set, not a legal deadline): Is this data still representative of the people and cases the model sees today?
Clauses
5 regimes| Regime | Clause |
|---|---|
| ISO/IEC 42001 | ISO/IEC 42001 A.7.3 Acquisition of data ISO/IEC 42001 A.10.3 Suppliers |
| NIST AI RMF | NIST AI RMF MN-3.1 Third-party resources monitored |
| EU AI Act | EU AI Act Art. 10 Data and data governance |
| GDPR | GDPR Art. 14 Information where personal data have not been obtained from the data subject GDPR Art. 28 Processor |
| UK GDPR | UK GDPR Art. 14 Information to be provided where personal data have not been obtained from the data subject UK GDPR Art. 28 Processor |
The clauses, set out
ISO/IEC 42001 A.7.3Acquisition of dataThe organization shall determine and document details about the acquisition and selection of data used in AI systems, including provenance and consent where applicable.
ISO/IEC 42001 A.10.3SuppliersEstablish a process ensuring that the organization's use of services, products or materials provided by suppliers aligns with its approach to the responsible development and use of AI systems.
NIST AI RMF MN-3.1Third-party resources monitoredAI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented. Third-party data, model, software and hardware dependencies are monitored on an ongoing basis, not assessed once at procurement, and the controls applied are recorded.
EU AI Act Art. 10Data and data governance applies if this system is high-risk under Annex IIIHigh-risk AI systems that make use of techniques involving the training of AI models shall use training, validation and testing data that meet the quality criteria in Art.10(2)-(5): appropriate data governance, examination for possible biases, identification of data gaps/shortcomings, statistically relevant datasets to the intended purpose, and considerations specific to the geographical, contextual, behavioural or functional setting of intended use.
GDPR Art. 14Information where personal data have not been obtained from the data subjectWhere personal data has not been obtained from the data subject, provide the same identity, contact, purpose, legal basis, recipient and transfer information as Article 13, plus the categories of personal data concerned and the source the data came from including whether it was a publicly accessible source. Provide it within a reasonable period and at the latest within one month of obtaining the data, or at the latest at the first communication with the data subject if the data is used to communicate with them, or at the latest when the data is first disclosed to another recipient. The obligation does not apply where the data subject already has the information, where provision proves impossible or would involve disproportionate effort in which case appropriate protective measures including making the information publicly available must be taken, where obtaining or disclosure is expressly laid down by Union or Member State law with appropriate safeguards, or where the data must remain confidential under an obligation of professional secrecy.
GDPR Art. 28ProcessorUse only processors providing sufficient guarantees to implement appropriate technical and organisational measures such that the processing meets the Regulation's requirements and protects the rights of the data subject. A processor must not engage another processor without the controller's prior specific or general written authorisation, and under a general authorisation must inform the controller of intended additions or replacements so the controller can object. The processing must be governed by a written contract or other legal act binding the processor to the controller, setting out the subject matter and duration, the nature and purpose, the type of personal data, the categories of data subjects and the controller's obligations and rights, and stipulating that the processor processes only on documented controller instructions including as to transfers, ensures persons authorised to process are under a duty of confidentiality, takes all Article 32 measures, respects the sub-processor conditions, assists the controller in responding to data subject rights requests, assists with Articles 32 to 36, deletes or returns all personal data at the controller's choice at the end of the service and deletes existing copies unless law requires retention, and makes available all information needed to demonstrate compliance and allows for and contributes to audits and inspections. The processor must immediately inform the controller if it considers an instruction infringes data protection law. The same obligations must be imposed on any sub-processor, and the initial processor remains fully liable for the sub-processor's performance. A processor that determines purposes and means is a controller for that processing.
UK GDPR Art. 14Information to be provided where personal data have not been obtained from the data subjectWhere data come from elsewhere the controller must give the Article 13 information plus the categories of data and the source (including whether publicly accessible), within a reasonable period and at the latest one month after obtaining the data, or at first communication with the data subject, or when first disclosing to another recipient, and must tell the data subject before further processing for a new purpose. The duty falls away where the data subject already has the information, where obtaining or disclosure is expressly required by domestic law with appropriate protections, where professional secrecy requires confidentiality, where providing the information is impossible or would involve disproportionate effort (judged by the number of data subjects, the age of the data and the safeguards), or where it would render impossible or seriously impair the purposes; a controller relying on the last two must protect the data subject's interests, including by publishing the information.
UK GDPR Art. 28ProcessorA controller may use only processors giving sufficient guarantees of appropriate measures. A processor may not engage a sub-processor without prior specific or general written authorisation, and under general authorisation must notify changes so the controller can object. Processing must be governed by a written contract or legal act setting out the subject matter, duration, nature, purpose, data types, data subjects and the controller's rights and obligations, and requiring the processor to act only on documented instructions (including on transfers), bind its staff to confidentiality, take Article 32 measures, respect sub-processing conditions, assist with rights requests and with Articles 32 to 36, delete or return data at the end, and provide information and allow audits, informing the controller if an instruction infringes the law. Sub-processors carry the same obligations and the processor stays liable for them. The Commissioner may adopt standard contractual clauses; a processor that determines purposes and means is treated as a controller.