{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-data-006.json",
  "source": "https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-006",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-DATA-006",
    "profile": "data-admission-and-privacy",
    "url": "https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-006",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-data-006.json",
    "title": "Personal Data Screening and Minimisation",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "Personal and special-category data are screened on each snapshot before training, the filter log is kept with the snapshot, each input feature carries a reason and a measured contribution, and retention follows a rule enforced in code.",
    "failureModes": [
      "A snapshot enters training without a PII or special-category scan, or the scan ran and its log was not kept.",
      "Features with no reason and no measured contribution stay in the data, so minimisation is asserted once instead of argued feature by feature.",
      "Special-category fields are used with no documented condition.",
      "Retention follows the storage default rather than the obligation, and data is kept past its deletion date."
    ],
    "scope": "Snapshots and features admitted to training, fine-tuning, evaluation and retrieval pipelines, and their retention. Retrieval indexes and logs are covered for minimisation only; anonymity claims about trained models are outside this control.",
    "enforcementPoints": [
      "deploy",
      "periodic"
    ],
    "verification": [
      {
        "kind": "inspect",
        "text": "Each admitted snapshot has the log of the PII and special-category scan run on it, and its card records a retention rule as enforced in code."
      }
    ],
    "evidence": [
      {
        "artefact": "PII and special-category filter log kept with each snapshot",
        "schemaId": null,
        "schema": null,
        "layer": 1
      },
      {
        "artefact": "Personal-data flag and retention rule on the dataset card",
        "schemaId": "dataset-card",
        "schema": "https://aigovernanceengineer.com/schemas/dataset-card.v1.json",
        "layer": 2
      },
      {
        "artefact": "Retention-set check on the admission record",
        "schemaId": "dataset-admission-record",
        "schema": "https://aigovernanceengineer.com/schemas/dataset-admission-record.v1.json",
        "layer": 1
      }
    ],
    "failureResponse": {
      "effect": "deny",
      "text": "A snapshot with no scan log does not enter training; a feature with neither a reason nor a measured contribution is removed, and a special-category field needs a documented condition before it stays."
    },
    "layer": 1,
    "secondaryLayers": [
      3
    ],
    "patterns": [
      {
        "slug": "dataset-admission-gate",
        "title": "Dataset Admission Gate",
        "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate"
      }
    ],
    "seeds": [],
    "derivedFrom": [
      {
        "kind": "schema",
        "ref": "dataset-card",
        "url": "https://aigovernanceengineer.com/resources/templates#schema-dataset-card"
      },
      {
        "kind": "pattern",
        "ref": "dataset-admission-gate",
        "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate"
      },
      {
        "kind": "chapter",
        "ref": "privacy-and-ai",
        "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
      }
    ],
    "mappings": {
      "obligations": [
        {
          "id": "AIGE-OBL-GDPR-ART25",
          "name": "GDPR Art. 5(1)(c) and 25 minimisation and data protection by design and by default",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art25"
        }
      ],
      "iso42001": [],
      "nistAiRmf": [],
      "owasp": [],
      "atlas": [],
      "aiuc1": [],
      "csaAicm": [],
      "other": []
    },
    "references": [
      {
        "n": 20,
        "title": "Privacy and data protection law applied to AI",
        "text": "Privacy and data protection law applied to AI (AI Governance Engineering Body of Knowledge v0.5.0, chapter 19, section \"Minimisation, privacy by design and PETs\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/privacy-and-ai#minimisation-privacy-by-design-and-pets",
        "verified": "primary"
      },
      {
        "n": 21,
        "title": "Privacy and data protection law applied to AI",
        "text": "Privacy and data protection law applied to AI (AI Governance Engineering Body of Knowledge v0.5.0, chapter 19, section \"Obligation to artefact map\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/privacy-and-ai#obligation-to-artefact-map",
        "verified": "primary"
      },
      {
        "n": 18,
        "title": "Regulation (EU) 2016/679 (GDPR)",
        "text": "Regulation (EU) 2016/679 (GDPR) (Art. 5 principles, incl. 5(1)(b) purpose limitation and 5(1)(c) minimisation; Art. 6 lawful basis and 6(4) compatibility; Art. 7 consent; Art. 9 special categories; Arts. 15 to 17 and 21 rights; Art. 25 data protection by design and by default; Art. 30 records of processing; Arts. 35 and 36 DPIA and prior consultation). Publications Office of the EU (EUR-Lex). 2016-04-27.",
        "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng",
        "verified": "primary"
      },
      {
        "n": 5,
        "title": "Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models",
        "text": "Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models (anonymity of models; legitimate interest; consequences of unlawful processing in development). European Data Protection Board. 2024-12.",
        "url": "https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-282024-on-certain-data-protection-aspects-related-to_en",
        "verified": "primary"
      }
    ],
    "implementationNotes": [
      "Argue minimisation feature by feature in the data card; the EDPB lists source selection, preparation and filtering among the areas an authority examines.",
      "Hold only the fields answers need in retrieval indexes, and use synthetic or masked eval sets wherever a test does not depend on real identities.",
      "Treat a synthetic set as a dataset with its own admission record naming the generator, the seed data and the privacy method: synthetic data inherits the biases, gaps and, where the generator memorised, the source records of its generator."
    ],
    "openQuestions": [
      "What detection rate should a PII or special-category scan reach before its \"pass\" is accepted as evidence, and how is that rate measured?"
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
