AI Training Data Provenance Checker
Customer-generated · source class

Reviews on your own site

Reviews are published by customers under your site terms; the terms decide whether they cover training.

What to record for it

The site, the review terms at the time, the period, and whether reviewer names were removed.

Personal data is likely: the checker assumes it where your personal data column is blank, labels the assumption, and words any finding that rests on it as a question.

A line that places here

example

Product reviews | customer reviews | customer terms and conditions

Check this line

What the checker reads on these lines

9 of the 12 findings

Clauses

5 regimes
RegimeClause
ISO/IEC 42001ISO/IEC 42001 A.7.3 Acquisition of data
ISO/IEC 42001 A.7.5 Data provenance
NIST AI RMFNIST AI RMF MS-2.10 Privacy risk examined
EU AI ActEU AI Act Art. 10 Data and data governance
GDPRGDPR Art. 6 Lawfulness of processing
GDPR Art. 7 Conditions for consent
GDPR Art. 13 Information to be provided where personal data are collected
UK GDPRUK GDPR Art. 6 Lawfulness of processing
UK GDPR Art. 7 Conditions for consent
UK GDPR Art. 8A Purpose limitation: further processing

The clauses, set out

ISO/IEC 42001 A.7.3Acquisition of data

The organization shall determine and document details about the acquisition and selection of data used in AI systems, including provenance and consent where applicable.

What an auditor asks to see: Data acquisition records; Provenance documentation; Consent records; Source identification; Licensing or consent evidence; Selection criteria and rejection rationale
What an auditor will probe: Is data provenance traceable to lawful sources?
Source: ISO/IEC 42001:2023
ISO/IEC 42001 A.7.5Data provenance

The organization shall document the provenance of data used in AI systems to enable evaluation and traceability.

What an auditor asks to see: Provenance records; Lineage diagrams; End-to-end data lineage from source to model; Transformations documented; Datasheets
What an auditor will probe: Is lineage maintained automatically or relies on manual updates?
Source: ISO/IEC 42001:2023
NIST AI RMF MS-2.10Privacy risk examined

Privacy risk of the AI system – as identified in the MAP function – is examined and documented. Privacy examination covers what the AI system makes possible, inference and re-identification from training data and outputs, not only the lawfulness of the input data.

What an auditor asks to see: Privacy risk examination covering training data, inference and outputs; Assessment of re-identification and memorisation risk; Privacy-enhancing measures applied and their assessed effect; Documentation traced to the privacy risks mapping identified
What an auditor will probe: Privacy assessed as lawful basis for input data only; Memorisation and training data extraction not considered; Assessment completed for the original data set and not repeated after retraining
Source: NIST AI Risk Management Framework
EU AI Act Art. 10Data and data governance applies if this system is high-risk under Annex III

High-risk AI systems that make use of techniques involving the training of AI models shall use training, validation and testing data that meet the quality criteria in Art.10(2)-(5): appropriate data governance, examination for possible biases, identification of data gaps/shortcomings, statistically relevant datasets to the intended purpose, and considerations specific to the geographical, contextual, behavioural or functional setting of intended use.

What an auditor asks to see: Data governance procedures; Bias examination records and remediation; Data-quality assessment per dataset
What an auditor will probe: Training data used without bias examination; Datasets not representative of the deployment context
Source: EU AI Act
GDPR Art. 6Lawfulness of processing

Process personal data only where at least one lawful basis applies: the data subject's consent, necessity for a contract with the data subject or pre-contractual steps at their request, compliance with a legal obligation, protection of vital interests, performance of a public interest task or exercise of official authority, or legitimate interests that are not overridden by the data subject's interests, rights and freedoms. Public authorities cannot rely on legitimate interests for processing carried out in performance of their tasks. Where the basis is legal obligation or public task, that basis must be laid down in Union or Member State law and the purpose must be determined in it. Before processing for a purpose other than the one collected for, without consent or a legal mandate, assess compatibility against the link between the purposes, the context of collection, the nature of the data, the consequences for the data subject and the safeguards in place.

What an auditor asks to see: A lawful basis recorded per processing activity, not per system or per department; Legitimate interests assessments showing the interest pursued, the necessity test and the balancing against the data subject's rights; The Union or Member State provision cited where the basis is legal obligation or public task; Compatibility assessments for each secondary use, covering the five factors Article 6(4) names; Evidence that the basis stated to the data subject in the privacy information matches the one recorded internally
What an auditor will probe: Consent recorded as the basis where the processing would happen regardless of the answer, which makes it neither free nor the real basis; Legitimate interests asserted with no balancing test on file, or a balancing test that never reaches an adverse conclusion for any activity; One lawful basis applied to a whole system that covers several distinct processing purposes; The basis switched after the fact when the first one fails, rather than settled before processing began
Source: GDPR
GDPR Art. 7Conditions for consent

Where processing rests on consent, be able to demonstrate that the data subject consented. Where the consent request forms part of a wider written declaration, present it in a manner clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language. Inform the data subject before consenting that consent may be withdrawn at any time, make withdrawal as easy as giving consent, and treat processing carried out before withdrawal as still lawful. Consent is not freely given where performance of a contract, including provision of a service, is made conditional on consent to processing that the contract does not require.

What an auditor asks to see: Consent records capturing who consented, when, to what wording, and through what mechanism; The consent wording and interface as presented, versioned, so an old record can be tied to what was actually shown; The withdrawal mechanism, with evidence it works and takes no more steps than giving consent did; Evidence that consent requests bundled inside terms or a wider declaration are visually and textually separated; Per service, the analysis of which processing is genuinely necessary for the contract and which rests on consent
What an auditor will probe: Consent logged as a boolean with no record of the wording shown, so the organisation cannot demonstrate what was agreed to; Withdrawal routed through a support ticket or a postal address while giving consent was a single click; Service access blocked on consent to analytics or marketing the service does not need; Pre-ticked boxes, silence, or continued use of a site treated as consent
Source: GDPR
GDPR Art. 13Information to be provided where personal data are collected

Where personal data is collected from the data subject, provide at the time it is obtained the identity and contact details of the controller and any representative, the contact details of the data protection officer, the purposes and the legal basis, the legitimate interests where that is the basis, the recipients or categories of recipient, and any intention to transfer to a third country with the existence or absence of an adequacy decision and, for Article 46, 47 or 49(1) transfers, reference to the safeguards and how to obtain a copy. Provide in addition the storage period or the criteria used to determine it, the existence of the rights of access, rectification, erasure, restriction, objection and portability, the right to withdraw consent where consent is the basis, the right to lodge a complaint with a supervisory authority, whether providing the data is a statutory or contractual requirement and the consequences of not providing it, and the existence of automated decision-making including profiling with meaningful information about the logic involved and its significance and envisaged consequences. Before further processing for a new purpose, provide that purpose and the further information first.

What an auditor asks to see: The privacy notice mapped item by item against every information element Article 13 lists; Evidence of the point and timing at which the notice is presented for each collection channel, including forms, telephone and in person; The storage periods or criteria as published, reconciled against the actual retention schedule; The published description of automated decision-making logic, and the reasoning for why it is meaningful to a data subject; Records showing new purpose information was given before the further processing started, with dates
What an auditor will probe: Recipients described only as third parties or trusted partners, which names neither a recipient nor a category; Retention shown as for as long as necessary, which is neither a period nor a criterion; The notice linked from a page footer but not presented at the point of collection, so it is not provided at the time the data is obtained; Automated decision-making logic described in terms that would fit any system, leaving the data subject nothing to contest
Source: GDPR
UK GDPR Art. 6Lawfulness of processing

Processing is lawful only if at least one basis applies: consent for specific purposes, contract with the data subject, legal obligation, vital interests, a public task laid down in domestic law or relevant international law (section 9A of the 2018 Act), a recognised legitimate interest, or legitimate interests not overridden by the data subject's interests, rights and freedoms (particularly where the data subject is a child). Neither legitimate-interest basis is open to public authorities performing their tasks. A recognised legitimate interest (Article 6(1)(ea)) applies only where a condition in Annex 1 is met: disclosure on request to a body that states it needs the data for a public task, national security, public security or defence, responding to an emergency, detecting or preventing crime or prosecuting offenders, and safeguarding a vulnerable individual (under 18, or 18 or over and at risk); no balancing test is required for these. Article 6(11) gives direct marketing, intra-group transmission for internal administration and network and information security as examples of processing that may be necessary for legitimate interests, which still need the balancing test.

What an auditor asks to see: Lawful basis recorded per processing purpose; Legitimate interests assessments for Article 6(1)(f) processing; Annex 1 condition and the requesting body's written statement kept for each recognised legitimate interest disclosure
What an auditor will probe: Treating the Article 6(11) examples as automatically lawful without a balancing test; Public authorities relying on legitimate interests for their core tasks; Recognised legitimate interest claimed where no Annex 1 condition fits
Source: UK GDPR
UK GDPR Art. 7Conditions for consent

Where processing rests on consent the controller must be able to show the data subject consented. A consent request inside a written declaration covering other matters must be clearly distinguishable, intelligible, easily accessible and in plain language, and any part that infringes the Regulation does not bind. The data subject may withdraw consent at any time, must be told so before consenting, and withdrawing must be as easy as giving consent; withdrawal does not undo earlier lawful processing. Whether consent is freely given takes utmost account of whether a contract or service is made conditional on consent to processing the contract does not need. Consent to an area of scientific research counts as consent where the conditions in Article 4(6) are met.

What an auditor asks to see: Consent records showing who consented, when, to what and how; Consent wording and withdrawal mechanism screenshots; Review of bundled consent in terms and conditions
What an auditor will probe: Consent bundled into terms of service; Withdrawal harder than giving consent (for example phone only); No record able to prove a given individual's consent
Source: UK GDPR
UK GDPR Art. 8APurpose limitation: further processing

Whether processing for a new purpose is compatible with the purpose of collection is decided by weighing, among other things, the link between the purposes, the context of collection and the relationship with the data subject, the nature of the data (special category or criminal offence data), the possible consequences, and safeguards such as encryption or pseudonymisation. Further processing is treated as compatible where the data subject consents to a specified, explicit and legitimate new purpose; where it is research, archiving or statistics under Article 84B; where it ensures or demonstrates compliance with Article 5(1); where an Annex 2 condition is met (disclosure on request for a public task, archiving disclosures of consent-based data, public security, emergencies, crime, vital interests, safeguarding vulnerable individuals, tax, legal obligations); or where it is necessary for an Article 23(1)(c) to (j) objective and authorised by law. Data collected on consent may be reused only with fresh consent or for compliance, or under Annex 2 or an authorised objective where consent cannot reasonably be sought.

What an auditor asks to see: Compatibility assessments for each new use of existing data; Annex 2 condition recorded for reuse relying on it; Evidence that consent-based data was not reused beyond Article 8A(4)
What an auditor will probe: Reuse of consent-based data for analytics without fresh consent; No documented compatibility test before repurposing data; Relying on Annex 2 without the request or legal duty it requires
Source: UK GDPR

Other sources in customer-generated