Skip to main content

AI governance for personal data

Prove the personal data in training and inference was collected lawfully — and that withdrawal reaches the pipeline. Complements your AI system registry; it does not replace model-risk or runtime tools.

Privacy-native AI governance evidence
What Makes Us Different

What you get

Discover the unique advantages that set our privacy platform apart from traditional solutions.

Featured

Consent-to-pipeline lineage

Tie training and inference uses to the consent or other lawful basis that authorised them — and to withdrawal.

Featured

Article 10 data evidence

Document provenance, purpose limitation, and quality notes for personal data feeding high-risk AI — the GDPR half of EU AI Act Art. 10.

DPIA, then FRIA

Run the GDPR impact assessment first, then extend it for fundamental-rights dimensions instead of maintaining two disconnected files.

AI vendor diligence

Assess processors and model providers for personal-data use, subprocessors, and deletion when a data subject withdraws.

Documentation

Privacy-native, not a second GRC stack

3 sections to explore
01

Not the same as privacy governance

Privacy governance asks whose personal data it is and what rights apply. AI governance asks whether the system that uses that data is lawful, documented, and under control. A GDPR-clean process can still produce biased or unexplained outputs; a classified model can still train on data with no valid basis. High-risk AI that processes personal data typically needs both a DPIA (GDPR Art. 35) and, for some deployers, a FRIA (AI Act Art. 27).

02

What this page covers

Secure Privacy’s AI governance work sits where personal data enters models: lawful basis, consent withdrawal, vendor processing, and impact assessments. Use Systems Management for the AI Act inventory and risk-tier register. Use DPIA workflows for the assessment engine. This module is the evidence chain from consent record to training or inference use.

03

What it does not replace

It does not score model drift, intercept prompts, or enforce runtime tool-call policy. Those jobs belong to dedicated AI governance or gateway platforms. Use this module alongside them when the question is: was this personal data allowed in the system at all, and can you prove it?

Congratulations! 🎉

You've completed all sections of this documentation. Feel free to revisit any section using the table of contents.

Frequently Asked Questions

AI governance FAQs

No. Privacy Governance is the program for RoPA, DSARs, vendors, and DPIAs. AI Governance is the overlay for personal data used in models. They share assessments and vendors; they answer different questions.