Licensed vendor dataset
Bought data is only as good as the vendor's own provenance; the licence and the vendor's source are both part of the record.
What to record for it
The vendor, the licence and its clause on training, the vendor's own source, and the delivery date.
Personal data is possible: where your personal data column is blank the checker says it could not determine it.
A line that places here
exampleAddress reference file | data vendor | vendor licence
What the checker reads on these lines
9 of the 12 findings- Origin not recorded: Where did this dataset come from, and who in the company can show it?
- Terms not recorded: What terms did this data come under, and where is the copy?
- Terms that need review for this use: Do the terms, read in full, cover training this model, and who has read them?
- Personal data with no lawful basis recorded, or reused from another purpose: What is the lawful basis for training on this data, and has reuse for a new purpose been tested for compatibility?
- Labelled by a vendor, a crowd or a model with no quality check recorded: Who checked these labels, on what sample, and where is the result?
- No version or snapshot date: Which version of this dataset trained the model, and is that copy kept?
- High-risk use with no bias examination recorded: Has this dataset been examined for bias against the people the model decides about, and where is the record?
- Older than your N-year policy threshold (a threshold you set, not a legal deadline): Is this data still representative of the people and cases the model sees today?
- Vendor data with no provider named: Which company supplied this data, under which contract?
Clauses
5 regimes| Regime | Clause |
|---|---|
| ISO/IEC 42001 | ISO/IEC 42001 A.7.3 Acquisition of data ISO/IEC 42001 A.10.3 Suppliers |
| NIST AI RMF | NIST AI RMF MP-4.1 Legal risks of components and third-party data NIST AI RMF MN-3.1 Third-party resources monitored NIST AI RMF GV-6.1 Third-party and intellectual property risk policy |
| EU AI Act | EU AI Act Art. 10 Data and data governance EU AI Act Art. 17 Quality management system |
| GDPR | GDPR Art. 14 Information where personal data have not been obtained from the data subject GDPR Art. 28 Processor |
| UK GDPR | UK GDPR Art. 14 Information to be provided where personal data have not been obtained from the data subject UK GDPR Art. 28 Processor |
The clauses, set out
ISO/IEC 42001 A.7.3Acquisition of dataThe organization shall determine and document details about the acquisition and selection of data used in AI systems, including provenance and consent where applicable.
ISO/IEC 42001 A.10.3SuppliersEstablish a process ensuring that the organization's use of services, products or materials provided by suppliers aligns with its approach to the responsible development and use of AI systems.
NIST AI RMF MP-4.1Legal risks of components and third-party dataApproaches for mapping AI technology and legal risks of its components – including the use of third-party data or software – are in place, followed, and documented, as are risks of infringement of a third-party’s intellectual property or other rights. There is a followed approach for mapping the technology and legal risk carried by each component, including data and software obtained from third parties and the rights position attached to them.
NIST AI RMF MN-3.1Third-party resources monitoredAI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented. Third-party data, model, software and hardware dependencies are monitored on an ongoing basis, not assessed once at procurement, and the controls applied are recorded.
NIST AI RMF GV-6.1Third-party and intellectual property risk policyPolicies and procedures are in place that address AI risks associated with third-party entities, including risks of infringement of a third party’s intellectual property or other rights. Third-party AI risk is addressed by policy covering data, models, software and services obtained externally, including the rights position on training data and model outputs.
EU AI Act Art. 10Data and data governance applies if this system is high-risk under Annex IIIHigh-risk AI systems that make use of techniques involving the training of AI models shall use training, validation and testing data that meet the quality criteria in Art.10(2)-(5): appropriate data governance, examination for possible biases, identification of data gaps/shortcomings, statistically relevant datasets to the intended purpose, and considerations specific to the geographical, contextual, behavioural or functional setting of intended use.
EU AI Act Art. 17Quality management system a provider dutyProviders must put in place a quality management system that ensures compliance with the Regulation, documented systematically in written policies, procedures and instructions, covering at least: a regulatory compliance strategy including conformity assessment and management of modifications; design, design control and design verification techniques; development, quality control and quality assurance techniques; examination, test and validation procedures before, during and after development and the frequency at which they run; technical specifications and standards to be applied and, where harmonised standards are not applied in full, the means used instead; data management systems and procedures spanning acquisition, collection, analysis, labelling, storage, filtration, mining, aggregation and retention; the Art.9 risk management system; the Art.72 post-market monitoring system; Art.73 serious incident reporting procedures; handling of communication with authorities, notified bodies, other operators and customers; record-keeping; resource management including security of supply; and an accountability framework setting out the responsibilities of management and staff for every one of those aspects. Implementation is proportionate to the size of the provider's organisation, but the degree of rigour required to make the systems compliant is not reducible.
GDPR Art. 14Information where personal data have not been obtained from the data subjectWhere personal data has not been obtained from the data subject, provide the same identity, contact, purpose, legal basis, recipient and transfer information as Article 13, plus the categories of personal data concerned and the source the data came from including whether it was a publicly accessible source. Provide it within a reasonable period and at the latest within one month of obtaining the data, or at the latest at the first communication with the data subject if the data is used to communicate with them, or at the latest when the data is first disclosed to another recipient. The obligation does not apply where the data subject already has the information, where provision proves impossible or would involve disproportionate effort in which case appropriate protective measures including making the information publicly available must be taken, where obtaining or disclosure is expressly laid down by Union or Member State law with appropriate safeguards, or where the data must remain confidential under an obligation of professional secrecy.
GDPR Art. 28ProcessorUse only processors providing sufficient guarantees to implement appropriate technical and organisational measures such that the processing meets the Regulation's requirements and protects the rights of the data subject. A processor must not engage another processor without the controller's prior specific or general written authorisation, and under a general authorisation must inform the controller of intended additions or replacements so the controller can object. The processing must be governed by a written contract or other legal act binding the processor to the controller, setting out the subject matter and duration, the nature and purpose, the type of personal data, the categories of data subjects and the controller's obligations and rights, and stipulating that the processor processes only on documented controller instructions including as to transfers, ensures persons authorised to process are under a duty of confidentiality, takes all Article 32 measures, respects the sub-processor conditions, assists the controller in responding to data subject rights requests, assists with Articles 32 to 36, deletes or returns all personal data at the controller's choice at the end of the service and deletes existing copies unless law requires retention, and makes available all information needed to demonstrate compliance and allows for and contributes to audits and inspections. The processor must immediately inform the controller if it considers an instruction infringes data protection law. The same obligations must be imposed on any sub-processor, and the initial processor remains fully liable for the sub-processor's performance. A processor that determines purposes and means is a controller for that processing.
UK GDPR Art. 14Information to be provided where personal data have not been obtained from the data subjectWhere data come from elsewhere the controller must give the Article 13 information plus the categories of data and the source (including whether publicly accessible), within a reasonable period and at the latest one month after obtaining the data, or at first communication with the data subject, or when first disclosing to another recipient, and must tell the data subject before further processing for a new purpose. The duty falls away where the data subject already has the information, where obtaining or disclosure is expressly required by domestic law with appropriate protections, where professional secrecy requires confidentiality, where providing the information is impossible or would involve disproportionate effort (judged by the number of data subjects, the age of the data and the safeguards), or where it would render impossible or seriously impair the purposes; a controller relying on the last two must protect the data subject's interests, including by publishing the information.
UK GDPR Art. 28ProcessorA controller may use only processors giving sufficient guarantees of appropriate measures. A processor may not engage a sub-processor without prior specific or general written authorisation, and under general authorisation must notify changes so the controller can object. Processing must be governed by a written contract or legal act setting out the subject matter, duration, nature, purpose, data types, data subjects and the controller's rights and obligations, and requiring the processor to act only on documented instructions (including on transfers), bind its staff to confidentiality, take Article 32 measures, respect sub-processing conditions, assist with rights requests and with Articles 32 to 36, delete or return data at the end, and provide information and allow audits, informing the controller if an instruction infringes the law. Sub-processors carry the same obligations and the processor stays liable for them. The Commissioner may adopt standard contractual clauses; a processor that determines purposes and means is treated as a controller.