Government open data
Government open data usually comes under an open licence with an attribution line; small-area data can still point at people.
What to record for it
The publisher, the release, the licence and its attribution wording, and the download date.
Personal data is unlikely: where your personal data column is blank the checker reads no, and says it assumed so.
A line that places here
exampleCensus small-area extract | public open data | CC BY 4.0
What the checker reads on these lines
7 of the 12 findings- Origin not recorded: Where did this dataset come from, and who in the company can show it?
- Terms not recorded: What terms did this data come under, and where is the copy?
- Terms that need review for this use: Do the terms, read in full, cover training this model, and who has read them?
- Personal data with no lawful basis recorded, or reused from another purpose: What is the lawful basis for training on this data, and has reuse for a new purpose been tested for compatibility?
- No version or snapshot date: Which version of this dataset trained the model, and is that copy kept?
- Declared potential overlap between train and test: Were these two sets separated before training, and on what key?
- Older than your N-year policy threshold (a threshold you set, not a legal deadline): Is this data still representative of the people and cases the model sees today?
Clauses
5 regimes| Regime | Clause |
|---|---|
| ISO/IEC 42001 | ISO/IEC 42001 A.7.3 Acquisition of data ISO/IEC 42001 A.7.5 Data provenance |
| NIST AI RMF | NIST AI RMF MP-4.1 Legal risks of components and third-party data NIST AI RMF GV-6.1 Third-party and intellectual property risk policy |
| EU AI Act | EU AI Act Art. 10 Data and data governance |
| GDPR | GDPR Art. 14 Information where personal data have not been obtained from the data subject |
| UK GDPR | UK GDPR Art. 14 Information to be provided where personal data have not been obtained from the data subject |
The clauses, set out
ISO/IEC 42001 A.7.3Acquisition of dataThe organization shall determine and document details about the acquisition and selection of data used in AI systems, including provenance and consent where applicable.
ISO/IEC 42001 A.7.5Data provenanceThe organization shall document the provenance of data used in AI systems to enable evaluation and traceability.
NIST AI RMF MP-4.1Legal risks of components and third-party dataApproaches for mapping AI technology and legal risks of its components – including the use of third-party data or software – are in place, followed, and documented, as are risks of infringement of a third-party’s intellectual property or other rights. There is a followed approach for mapping the technology and legal risk carried by each component, including data and software obtained from third parties and the rights position attached to them.
NIST AI RMF GV-6.1Third-party and intellectual property risk policyPolicies and procedures are in place that address AI risks associated with third-party entities, including risks of infringement of a third party’s intellectual property or other rights. Third-party AI risk is addressed by policy covering data, models, software and services obtained externally, including the rights position on training data and model outputs.
EU AI Act Art. 10Data and data governance applies if this system is high-risk under Annex IIIHigh-risk AI systems that make use of techniques involving the training of AI models shall use training, validation and testing data that meet the quality criteria in Art.10(2)-(5): appropriate data governance, examination for possible biases, identification of data gaps/shortcomings, statistically relevant datasets to the intended purpose, and considerations specific to the geographical, contextual, behavioural or functional setting of intended use.
GDPR Art. 14Information where personal data have not been obtained from the data subjectWhere personal data has not been obtained from the data subject, provide the same identity, contact, purpose, legal basis, recipient and transfer information as Article 13, plus the categories of personal data concerned and the source the data came from including whether it was a publicly accessible source. Provide it within a reasonable period and at the latest within one month of obtaining the data, or at the latest at the first communication with the data subject if the data is used to communicate with them, or at the latest when the data is first disclosed to another recipient. The obligation does not apply where the data subject already has the information, where provision proves impossible or would involve disproportionate effort in which case appropriate protective measures including making the information publicly available must be taken, where obtaining or disclosure is expressly laid down by Union or Member State law with appropriate safeguards, or where the data must remain confidential under an obligation of professional secrecy.
UK GDPR Art. 14Information to be provided where personal data have not been obtained from the data subjectWhere data come from elsewhere the controller must give the Article 13 information plus the categories of data and the source (including whether publicly accessible), within a reasonable period and at the latest one month after obtaining the data, or at first communication with the data subject, or when first disclosing to another recipient, and must tell the data subject before further processing for a new purpose. The duty falls away where the data subject already has the information, where obtaining or disclosure is expressly required by domestic law with appropriate protections, where professional secrecy requires confidentiality, where providing the information is impossible or would involve disproportionate effort (judged by the number of data subjects, the age of the data and the safeguards), or where it would render impossible or seriously impair the purposes; a controller relying on the last two must protect the data subject's interests, including by publishing the information.