News articles
News text is copyright material; publishers increasingly reserve text and data mining rights.
What to record for it
The publications, the dates, the terms and any reservation of rights, and whether a licence was taken.
Personal data is possible: where your personal data column is blank the checker says it could not determine it.
A line that places here
exampleIndustry news | news scrape | none recorded
What the checker reads on these lines
9 of the 12 findings- Origin not recorded: Where did this dataset come from, and who in the company can show it?
- Terms not recorded: What terms did this data come under, and where is the copy?
- Terms that need review for this use: Do the terms, read in full, cover training this model, and who has read them?
- Personal data with no lawful basis recorded, or reused from another purpose: What is the lawful basis for training on this data, and has reuse for a new purpose been tested for compatibility?
- Labelled by a vendor, a crowd or a model with no quality check recorded: Who checked these labels, on what sample, and where is the result?
- No version or snapshot date: Which version of this dataset trained the model, and is that copy kept?
- High-risk use with no bias examination recorded: Has this dataset been examined for bias against the people the model decides about, and where is the record?
- Older than your N-year policy threshold (a threshold you set, not a legal deadline): Is this data still representative of the people and cases the model sees today?
- Content where a label belongs: Which label belongs in this cell, so the list describes the data without carrying it?
Clauses
5 regimes| Regime | Clause |
|---|---|
| ISO/IEC 42001 | ISO/IEC 42001 A.7.3 Acquisition of data ISO/IEC 42001 A.7.5 Data provenance |
| NIST AI RMF | NIST AI RMF MP-4.1 Legal risks of components and third-party data NIST AI RMF GV-6.1 Third-party and intellectual property risk policy |
| EU AI Act | EU AI Act Art. 10 Data and data governance EU AI Act Art. 15 Accuracy, robustness and cybersecurity EU AI Act Art. 53 general-purpose model providers only Obligations for providers of general-purpose AI models |
| GDPR | GDPR Art. 14 Information where personal data have not been obtained from the data subject GDPR Art. 6 Lawfulness of processing |
| UK GDPR | UK GDPR Art. 14 Information to be provided where personal data have not been obtained from the data subject UK GDPR Art. 6 Lawfulness of processing |
The clauses, set out
ISO/IEC 42001 A.7.3Acquisition of dataThe organization shall determine and document details about the acquisition and selection of data used in AI systems, including provenance and consent where applicable.
ISO/IEC 42001 A.7.5Data provenanceThe organization shall document the provenance of data used in AI systems to enable evaluation and traceability.
NIST AI RMF MP-4.1Legal risks of components and third-party dataApproaches for mapping AI technology and legal risks of its components – including the use of third-party data or software – are in place, followed, and documented, as are risks of infringement of a third-party’s intellectual property or other rights. There is a followed approach for mapping the technology and legal risk carried by each component, including data and software obtained from third parties and the rights position attached to them.
NIST AI RMF GV-6.1Third-party and intellectual property risk policyPolicies and procedures are in place that address AI risks associated with third-party entities, including risks of infringement of a third party’s intellectual property or other rights. Third-party AI risk is addressed by policy covering data, models, software and services obtained externally, including the rights position on training data and model outputs.
EU AI Act Art. 10Data and data governance applies if this system is high-risk under Annex IIIHigh-risk AI systems that make use of techniques involving the training of AI models shall use training, validation and testing data that meet the quality criteria in Art.10(2)-(5): appropriate data governance, examination for possible biases, identification of data gaps/shortcomings, statistically relevant datasets to the intended purpose, and considerations specific to the geographical, contextual, behavioural or functional setting of intended use.
EU AI Act Art. 15Accuracy, robustness and cybersecurity a provider dutyHigh-risk AI systems shall be designed and developed in such a way that they achieve an appropriate level of accuracy, robustness, and cybersecurity, and shall perform consistently in those respects throughout their lifecycle. Resilience to errors, faults and inconsistencies; protection against attempts by unauthorised third parties to alter use, output or performance (incl data poisoning, model poisoning, adversarial examples and confidentiality attacks).
EU AI Act Art. 53Obligations for providers of general-purpose AI models providers of general-purpose modelsProviders of general-purpose AI models must draw up and keep up to date the technical documentation of the model, including its training and testing process and the results of its evaluation, containing at least the Annex XI information, for provision on request to the AI Office and the national competent authorities; draw up, keep up to date and make available to providers who intend to integrate the model information and documentation containing at least the Annex XII elements and sufficient to let them understand the model's capabilities and limitations and meet their own obligations; put in place a policy to comply with Union law on copyright and related rights, including identifying and complying, through state of the art technologies, with a reservation of rights expressed under Art.4(3) of Directive (EU) 2019/790; and draw up and make publicly available a sufficiently detailed summary of the content used for training, following the template provided by the AI Office. The two documentation duties do not apply to models released under a free and open source licence meeting the stated conditions, unless the model has systemic risk. Providers must cooperate with the Commission and the national competent authorities, and where they neither adhere to an approved code of practice nor comply with a European harmonised standard they must demonstrate alternative adequate means of compliance for assessment by the Commission.
GDPR Art. 14Information where personal data have not been obtained from the data subjectWhere personal data has not been obtained from the data subject, provide the same identity, contact, purpose, legal basis, recipient and transfer information as Article 13, plus the categories of personal data concerned and the source the data came from including whether it was a publicly accessible source. Provide it within a reasonable period and at the latest within one month of obtaining the data, or at the latest at the first communication with the data subject if the data is used to communicate with them, or at the latest when the data is first disclosed to another recipient. The obligation does not apply where the data subject already has the information, where provision proves impossible or would involve disproportionate effort in which case appropriate protective measures including making the information publicly available must be taken, where obtaining or disclosure is expressly laid down by Union or Member State law with appropriate safeguards, or where the data must remain confidential under an obligation of professional secrecy.
GDPR Art. 6Lawfulness of processingProcess personal data only where at least one lawful basis applies: the data subject's consent, necessity for a contract with the data subject or pre-contractual steps at their request, compliance with a legal obligation, protection of vital interests, performance of a public interest task or exercise of official authority, or legitimate interests that are not overridden by the data subject's interests, rights and freedoms. Public authorities cannot rely on legitimate interests for processing carried out in performance of their tasks. Where the basis is legal obligation or public task, that basis must be laid down in Union or Member State law and the purpose must be determined in it. Before processing for a purpose other than the one collected for, without consent or a legal mandate, assess compatibility against the link between the purposes, the context of collection, the nature of the data, the consequences for the data subject and the safeguards in place.
UK GDPR Art. 14Information to be provided where personal data have not been obtained from the data subjectWhere data come from elsewhere the controller must give the Article 13 information plus the categories of data and the source (including whether publicly accessible), within a reasonable period and at the latest one month after obtaining the data, or at first communication with the data subject, or when first disclosing to another recipient, and must tell the data subject before further processing for a new purpose. The duty falls away where the data subject already has the information, where obtaining or disclosure is expressly required by domestic law with appropriate protections, where professional secrecy requires confidentiality, where providing the information is impossible or would involve disproportionate effort (judged by the number of data subjects, the age of the data and the safeguards), or where it would render impossible or seriously impair the purposes; a controller relying on the last two must protect the data subject's interests, including by publishing the information.
UK GDPR Art. 6Lawfulness of processingProcessing is lawful only if at least one basis applies: consent for specific purposes, contract with the data subject, legal obligation, vital interests, a public task laid down in domestic law or relevant international law (section 9A of the 2018 Act), a recognised legitimate interest, or legitimate interests not overridden by the data subject's interests, rights and freedoms (particularly where the data subject is a child). Neither legitimate-interest basis is open to public authorities performing their tasks. A recognised legitimate interest (Article 6(1)(ea)) applies only where a condition in Annex 1 is met: disclosure on request to a body that states it needs the data for a public task, national security, public security or defence, responding to an emergency, detecting or preventing crime or prosecuting offenders, and safeguarding a vulnerable individual (under 18, or 18 or over and at risk); no balancing test is required for these. Article 6(11) gives direct marketing, intra-group transmission for internal administration and network and information security as examples of processing that may be necessary for legitimate interests, which still need the balancing test.