{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-data-005.json",
  "source": "https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-005",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-DATA-005",
    "profile": "data-admission-and-privacy",
    "url": "https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-005",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-data-005.json",
    "title": "Purpose Match Before Reuse of Data",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "A run that reads a dataset is denied when the purpose on the dataset's card differs from the purpose declared by the consuming system and no compatibility assessment is recorded.",
    "failureModes": [
      "Data is reused for a purpose incompatible with the one it was collected for: support transcripts reused to profile customers for sales, security footage reused for attendance, fraud features reused for credit limits.",
      "Consent to a service is treated as consent to train a model on the service's data.",
      "A purpose mismatch is caught by nobody because the purpose travels in a document, not as a tag on the data a rule can read."
    ],
    "scope": "Personal data further processed for training, fine-tuning or indexing by a system other than, or for a purpose other than, the one it was collected for.",
    "enforcementPoints": [
      "runtime"
    ],
    "verification": [
      {
        "kind": "test",
        "text": "A run whose declared purpose differs from the purpose on the dataset's card, with no compatibility assessment recorded, is denied, and the denial is filed against the dataset's registry entry."
      }
    ],
    "evidence": [
      {
        "artefact": "Purpose-match verdict per run",
        "schemaId": null,
        "schema": null,
        "layer": 1
      },
      {
        "artefact": "Compatibility and use-case checks on the admission record",
        "schemaId": "dataset-admission-record",
        "schema": "https://aigovernanceengineer.com/schemas/dataset-admission-record.v1.json",
        "layer": 1
      },
      {
        "artefact": "Art. 6(4) compatibility assessment filed against the dataset",
        "schemaId": null,
        "schema": null,
        "layer": 2
      }
    ],
    "failureResponse": {
      "effect": "deny",
      "text": "The run is denied; the request becomes an Art. 6(4) compatibility assessment, and the denied run and the assessment are both filed against the dataset's registry entry."
    },
    "layer": 1,
    "secondaryLayers": [
      2
    ],
    "patterns": [
      {
        "slug": "dataset-admission-gate",
        "title": "Dataset Admission Gate",
        "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate"
      },
      {
        "slug": "training-data-rights-ledger",
        "title": "Training-Data Rights Ledger",
        "url": "https://aigovernanceengineer.com/patterns/training-data-rights-ledger"
      },
      {
        "slug": "policy-card",
        "title": "Policy Card",
        "url": "https://aigovernanceengineer.com/patterns/policy-card"
      }
    ],
    "seeds": [],
    "derivedFrom": [
      {
        "kind": "pattern",
        "ref": "dataset-admission-gate",
        "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate"
      },
      {
        "kind": "schema",
        "ref": "dataset-admission-record",
        "url": "https://aigovernanceengineer.com/resources/templates#schema-dataset-admission-record"
      },
      {
        "kind": "chapter",
        "ref": "privacy-and-ai",
        "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
      }
    ],
    "mappings": {
      "obligations": [
        {
          "id": "AIGE-OBL-GDPR-ART5-1B",
          "name": "GDPR Art. 5(1)(b) and 6(4) purpose limitation",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art5-1b"
        }
      ],
      "iso42001": [],
      "nistAiRmf": [],
      "owasp": [],
      "atlas": [],
      "aiuc1": [],
      "csaAicm": [],
      "other": []
    },
    "references": [
      {
        "n": 19,
        "title": "Privacy and data protection law applied to AI",
        "text": "Privacy and data protection law applied to AI (AI Governance Engineering Body of Knowledge v0.5.0, chapter 19, section \"Purpose limitation and function creep\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/privacy-and-ai#purpose-limitation-and-function-creep",
        "verified": "primary"
      },
      {
        "n": 12,
        "title": "Governing AI development",
        "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"The right to use the data\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-development#the-right-to-use-the-data",
        "verified": "primary"
      },
      {
        "n": 1,
        "title": "Dataset Admission Gate",
        "text": "Dataset Admission Gate (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05): a job may read a dataset version only if a complete, signed admission record admits it for that use). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate",
        "verified": "primary"
      },
      {
        "n": 18,
        "title": "Regulation (EU) 2016/679 (GDPR)",
        "text": "Regulation (EU) 2016/679 (GDPR) (Art. 5 principles, incl. 5(1)(b) purpose limitation and 5(1)(c) minimisation; Art. 6 lawful basis and 6(4) compatibility; Art. 7 consent; Art. 9 special categories; Arts. 15 to 17 and 21 rights; Art. 25 data protection by design and by default; Art. 30 records of processing; Arts. 35 and 36 DPIA and prior consultation). Publications Office of the EU (EUR-Lex). 2016-04-27.",
        "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng",
        "verified": "primary"
      }
    ],
    "implementationNotes": [
      "Use a purpose tag that travels with the data and a layer 01 rule that compares it with the purpose declared by the consuming system; a denied join is proof the purpose limit bit.",
      "The Art. 6(4) test weighs the link between purposes, the context, the nature of the data, the consequences and the safeguards, such as encryption or pseudonymisation; record the outcome, including a partial one (for example \"aggregated topic counts only\")."
    ],
    "openQuestions": [
      "How should purposes be named so that a rule can compare them: a controlled vocabulary per organisation, or the use-case ids of the registry?"
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
