EU AI Act Art. 4a: lawful basis for special-category data in bias detection
Lawful basis to process special-category data for bias detection in high-risk systems, with pseudonymisation and deletion once bias is corrected
AIGE-OBL-EUAIA-ART4A. Drawn from chapter 08.
Text alternative
- Clause: EU AI Act, Art. 4a.
- Duty holder: Provider.
- Applies from: 2026-07-27, In force.
- Artefact: Data governance controls.
- Layer: Layer 02 Inventory & Transparency.
- Evidence record: Dataset card.
- Record schemas: Dataset card .
- The same topic in 19 other frameworks; the crosswalk section below links each clause.
- Id
AIGE-OBL-EUAIA-ART4A- Instrument
- EU AI Act (post-Omnibus) law
- Compared side by side
- ISO 42001 vs EU AI Act · NIST AI RMF vs EU AI Act
- Clause
- Art. 4a
- Duty holder
- Provider
- Authority
- National MSA / DPAs
- Applies from
- In force · new, in force
- System class
- High-risk (Annex III) · High-risk (Annex I)
The artefact that evidences it
Data governance controls; pseudonymisation and retention-as-code; data card noting basis and deletion.
Patterns that build it
- Dataset Admission Gate (layer 1 and 2)
- Fairness Eval Suite (layer 3)
- Drift & Fairness Monitor (layer 4 and 5)
The same topic in other frameworks
From the topic crosswalk: the clauses filed under the same topics as this one. Mappings are illustrative, not a claim of conformity.
Data governance
- EU AI Act Art. 10 Data and data governance (core)
- ISO 42001 A.7 Data for AI systems (core)
- TC260 Framework 3.0 TC260 2.1.3 Data safety risks (core)
- China GenAI Measures GenAI Art. 7 Training-data lawful sourcing (core)
- China GenAI Measures GenAI Art. 8 Data-annotation standards (core)
- China GenAI Measures GenAI Art. 11 Protection of user input and records (core)
- China Deep Synthesis DeepSyn Art. 14 Training-data management (core)
- GB/T 45654 GB/T 45654 Corpus security Training-corpus (data) security requirements (core) (clause not verified)
- EU AI Act Art. 10(2)(f)–(g) Examination for possible biases; measures to detect, prevent and mitigate them (core)
- GDPR Art. 5(1)(c) Data minimisation (core)
- GDPR Art. 25 Data protection by design and by default (core)
- ISO 42001 A.7.3 Acquisition of data (core) (clause not verified)
- CSA AICM DSP-20 Data Provenance and Transparency (core)
- UK ATRS ATRS 2.4.3 Development data specification (core)
- Singapore GenAI GenAI 2 Data (core)
- GAO AI Accountability 2.1 Sources: document sources and origins of data used to develop the models (core)
- GAO AI Accountability 2.2 Reliability: assess reliability of data used to develop the models (core)
- ISO 42001 A.4 Resources for AI systems
- NIST AI RMF MAP 2 MAP 2: Categorization of the AI system is performed
- NIST AI RMF MEASURE 2.10 MEASURE 2.10: Privacy risk of the AI system is examined and documented
- NIST AI RMF MEASURE 2.11 MEASURE 2.11: Fairness and bias are evaluated and results are documented
- TC260 Framework 3.0 TC260 5.1 Model R&D safety guidelines
- EU AI Act Art. 53 Obligations for providers of general-purpose AI models
- EU AI Act Art. 53(1)(c) Copyright policy, including rights reservations
- EU AI Act Art. 5(1)(e) Prohibited: untargeted scraping of facial images
- GPAI Code Copyright 1.1–1.5 Commitment 1: Copyright policy (Measures 1.1 to 1.5)
- GDPR Art. 9 Processing of special categories of personal data
- CSA AICM DSP-21 Data Poisoning Prevention & Detection
- OWASP LLM LLM05:2026 Data and Model Poisoning
- GAO AI Accountability 2.4 Variable selection: assess data variables used in the AI component models
- GAO AI Accountability 2.5 Enhancement: assess the use of synthetic, imputed, and/or augmented data
Fairness and non-discrimination
- EU AI Act Art. 10(2)(f)–(g) Examination for possible biases; measures to detect, prevent and mitigate them (core)
- GDPR Art. 5(1)(a) Lawfulness, fairness and transparency (core)
- NIST AI RMF MEASURE 2.11 MEASURE 2.11: Fairness and bias as identified in the MAP function are evaluated and results are documented (core)
- CSA AICM GRC-11 Bias and Fairness Assessment (core)
- CoE Convention CoE Art. 10 Equality and non-discrimination (core)
- China GenAI Measures GenAI Art. 4(2) Prevent discrimination in design, data, training and service (core)
- GAO AI Accountability 2.7 Bias: assess reliability, quality, and representativeness of the data used in operation, including potential biases (core)
- GAO AI Accountability 3.8 Bias: identify potential biases, inequities, and other societal concerns resulting from the AI system (core)
- GDPR Art. 9 Processing of special categories of personal data
- ISO 42001 A.5.4 Assessing AI system impact on individuals or groups of individuals (clause not verified)
- NIST AI RMF GOVERN 3.1 GOVERN 3.1: Decision-making related to mapping, measuring, and managing AI risks throughout the lifecycle is informed by a diverse team
- UK ATRS ATRS 2.4.2 Model specification
- OECD AI Principles OECD 1.2 Rule of law, human rights and democratic values, including fairness and privacy
- China Algo. Rec. AlgoRec Art. 21 No unreasonable differential treatment in trading conditions
Privacy and data protection
- GDPR Art. 5 Principles relating to processing of personal data (core)
- GDPR Art. 6 Lawfulness of processing (core)
- GDPR Art. 25 Data protection by design and by default (core)
- NIST AI RMF MEASURE 2.10 MEASURE 2.10: Privacy risk of the AI system as identified in the MAP function is examined and documented (core)
- CSA AICM DSP-08 Data Privacy by Design and Default (core)
- OWASP LLM LLM02:2026 Sensitive Information Disclosure (core)
- CoE Convention CoE Art. 11 Privacy and personal data protection (core)
- China GenAI Measures GenAI Art. 7(3) Consent or another lawful basis for personal information in training data (core)
- China GenAI Measures GenAI Art. 11 Protection of user input and records (core)
- GAO AI Accountability 2.8 Security and privacy: assess data security and privacy for the AI system (core)
- EU AI Act Art. 59 Further processing of personal data in the AI regulatory sandbox
- GDPR Art. 35 Data protection impact assessment
- ISO 42001 A.7 Data for AI systems
- CSA AICM DSP-22 Privacy Enhancing Technologies
- UK DUAA UK GDPR Art. 22B Restrictions on automated decision-making
- Singapore GenAI GenAI 2 Data
- OECD AI Principles OECD 1.2 Rule of law, human rights and democratic values, including fairness and privacy
- G7 Code G7 Action 11 Implement data input measures and protect personal data and intellectual property
Open controls that evidence it
Draft controls in the open control profiles that map to this row: each states a requirement and the evidence it must leave behind.
-
AIGE-CTL-DATA-007Special-Category Data Conditions (Data admission and privacy profile) -
AIGE-CTL-DEPLOY-009Fairness monitored by group in production (Deployment and monitoring profile)
Source
Chapter 08, section EU AI Act, post-Omnibus, checked against its sources on the review date above.
Machine-readable
- This obligation:
/api/v1/obligations/aige-obl-euaia-art4a.json - The register:
/api/v1/obligations.json· CSV - Schema and stability promise: open data and API
Cite this obligation
García Aibar, J. (2026). EU AI Act Art. 4a: lawful basis for special-category data in bias detection (AIGE-OBL-EUAIA-ART4A). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0). https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/obligations/aige-obl-euaia-art4a. CC BY 4.0
BibTeX
@misc{aige2026obligation,
author = {Jorge García Aibar},
title = {{EU AI Act Art. 4a: lawful basis for special-category data in bias detection (AIGE-OBL-EUAIA-ART4A)}},
howpublished = {In AI Governance Engineering: The Thesis \& Body of Knowledge},
year = {2026},
version = {0.5.0},
doi = {10.5281/zenodo.22956197},
url = {https://aigovernanceengineer.com/obligations/aige-obl-euaia-art4a},
note = {Version 0.5.0}
}