CRM export
CRM records mix contact details with notes written about people. The notes are the part that surprises a later reader.
What to record for it
The export date, the objects and fields exported, whether free-text notes are included, and the basis for training on them.
Personal data is likely: the checker assumes it where your personal data column is blank, labels the assumption, and words any finding that rests on it as a question.
A line that places here
exampleAccount notes | CRM export | internal
What the checker reads on these lines
9 of the 12 findings- Origin not recorded: Where did this dataset come from, and who in the company can show it?
- Terms not recorded: What terms did this data come under, and where is the copy?
- Personal data with no lawful basis recorded, or reused from another purpose: What is the lawful basis for training on this data, and has reuse for a new purpose been tested for compatibility?
- Article 9, criminal offence or children's data declared: Which condition covers processing this kind of data for training, and has a data protection impact assessment been done?
- No version or snapshot date: Which version of this dataset trained the model, and is that copy kept?
- Declared potential overlap between train and test: Were these two sets separated before training, and on what key?
- High-risk use with no bias examination recorded: Has this dataset been examined for bias against the people the model decides about, and where is the record?
- Older than your N-year policy threshold (a threshold you set, not a legal deadline): Is this data still representative of the people and cases the model sees today?
- Content where a label belongs: Which label belongs in this cell, so the list describes the data without carrying it?
Clauses
5 regimes| Regime | Clause |
|---|---|
| ISO/IEC 42001 | ISO/IEC 42001 A.7.3 Acquisition of data ISO/IEC 42001 A.7.5 Data provenance ISO/IEC 42001 A.4.3 Data resources |
| NIST AI RMF | NIST AI RMF MS-2.10 Privacy risk examined |
| EU AI Act | EU AI Act Art. 10 Data and data governance |
| GDPR | GDPR Art. 5 Principles relating to processing of personal data GDPR Art. 6 Lawfulness of processing GDPR Art. 30 Records of processing activities |
| UK GDPR | UK GDPR Art. 5 Principles relating to processing of personal data UK GDPR Art. 8A Purpose limitation: further processing UK GDPR Art. 30 Records of processing activities |
The clauses, set out
ISO/IEC 42001 A.7.3Acquisition of dataThe organization shall determine and document details about the acquisition and selection of data used in AI systems, including provenance and consent where applicable.
ISO/IEC 42001 A.7.5Data provenanceThe organization shall document the provenance of data used in AI systems to enable evaluation and traceability.
ISO/IEC 42001 A.4.3Data resourcesAs part of identifying resources, the organization shall document information about the data resources utilized for the AI system.
NIST AI RMF MS-2.10Privacy risk examinedPrivacy risk of the AI system – as identified in the MAP function – is examined and documented. Privacy examination covers what the AI system makes possible, inference and re-identification from training data and outputs, not only the lawfulness of the input data.
EU AI Act Art. 10Data and data governance applies if this system is high-risk under Annex IIIHigh-risk AI systems that make use of techniques involving the training of AI models shall use training, validation and testing data that meet the quality criteria in Art.10(2)-(5): appropriate data governance, examination for possible biases, identification of data gaps/shortcomings, statistically relevant datasets to the intended purpose, and considerations specific to the geographical, contextual, behavioural or functional setting of intended use.
GDPR Art. 5Principles relating to processing of personal dataProcess personal data lawfully, fairly and in a transparent manner; collect it for specified, explicit and legitimate purposes and do not process it further in a way incompatible with those purposes; keep it adequate, relevant and limited to what the purpose needs; keep it accurate and up to date, erasing or rectifying inaccurate data without delay; keep it in a form permitting identification no longer than the purpose requires; and secure it against unauthorised or unlawful processing and against accidental loss, destruction or damage using appropriate technical or organisational measures. The controller is responsible for all six principles and must be able to demonstrate compliance with them.
GDPR Art. 6Lawfulness of processingProcess personal data only where at least one lawful basis applies: the data subject's consent, necessity for a contract with the data subject or pre-contractual steps at their request, compliance with a legal obligation, protection of vital interests, performance of a public interest task or exercise of official authority, or legitimate interests that are not overridden by the data subject's interests, rights and freedoms. Public authorities cannot rely on legitimate interests for processing carried out in performance of their tasks. Where the basis is legal obligation or public task, that basis must be laid down in Union or Member State law and the purpose must be determined in it. Before processing for a purpose other than the one collected for, without consent or a legal mandate, assess compatibility against the link between the purposes, the context of collection, the nature of the data, the consequences for the data subject and the safeguards in place.
GDPR Art. 30Records of processing activitiesMaintain a written, including electronic, record of processing activities under the controller's responsibility containing the name and contact details of the controller, any joint controller, the representative and the data protection officer, the purposes of the processing, a description of the categories of data subjects and of personal data, the categories of recipients including those in third countries and international organisations, any transfers to a third country or international organisation with that destination identified and, for transfers under the second subparagraph of Article 49(1), the documentation of suitable safeguards, the envisaged time limits for erasure of each category where possible, and a general description of the Article 32(1) technical and organisational security measures where possible. A processor must maintain an equivalent record of the categories of processing carried out on behalf of each controller. Make the record available to the supervisory authority on request. The obligation does not apply to an organisation employing fewer than 250 persons unless the processing is likely to result in a risk to the rights and freedoms of data subjects, is not occasional, or includes special category or criminal offence data.
UK GDPR Art. 5Principles relating to processing of personal dataPersonal data must be processed lawfully, fairly and transparently; collected, whether from the data subject or otherwise, for specified, explicit and legitimate purposes and not further processed by or for the controller in a way incompatible with the purposes for which the controller collected it (Article 8A decides compatibility); adequate, relevant and limited to what is necessary; accurate and kept up to date, with inaccurate data erased or rectified without delay; kept in identifiable form no longer than necessary, with longer storage only for archiving, research or statistics carried out under Article 84B; and secured against unauthorised or unlawful processing and accidental loss, destruction or damage. The controller is responsible for, and must be able to demonstrate, compliance (accountability). Article 5(3) adds that processing is not lawful merely because it is compatible with the original purpose: a lawful basis under Article 6 is still needed.
UK GDPR Art. 8APurpose limitation: further processingWhether processing for a new purpose is compatible with the purpose of collection is decided by weighing, among other things, the link between the purposes, the context of collection and the relationship with the data subject, the nature of the data (special category or criminal offence data), the possible consequences, and safeguards such as encryption or pseudonymisation. Further processing is treated as compatible where the data subject consents to a specified, explicit and legitimate new purpose; where it is research, archiving or statistics under Article 84B; where it ensures or demonstrates compliance with Article 5(1); where an Annex 2 condition is met (disclosure on request for a public task, archiving disclosures of consent-based data, public security, emergencies, crime, vital interests, safeguarding vulnerable individuals, tax, legal obligations); or where it is necessary for an Article 23(1)(c) to (j) objective and authorised by law. Data collected on consent may be reused only with fresh consent or for compliance, or under Annex 2 or an authorised objective where consent cannot reasonably be sought.
UK GDPR Art. 30Records of processing activitiesEach controller (and representative) must keep a written, including electronic, record of its processing with its name and contacts, purposes, categories of data subjects and data, recipients, transfers abroad with Article 49(1) second-subparagraph safeguards documented, erasure time limits where possible, and a general description of security measures. Each processor must keep a record of the categories of processing it carries out for each controller, transfers and security measures. Records must be made available to the Commissioner on request. Organisations with fewer than 250 employees are exempt unless the processing is likely to result in a risk, is not occasional, or includes special category or criminal offence data.