Data protection principles for AI projects
Apply core data protection principles to AI projects from design to deployment, without legal jargon
A taste of a lesson
Can we fine tune a model on five years of customer support emails?
Possibly, but several questions come first, for your privacy team to answer. Purpose: were customers told their emails might be used this way, and is training compatible with the original purpose? Lawful basis: which applies, and if legitimate interests, does the balancing test hold? Minimisation: could you remove names and identifiers, or use a smaller sample? Risk: fine tuned models can reproduce personal details, and deletion requests become hard. A retrieval design may be easier to manage. Exercise: list the personal data types those emails likely contain.
Written by the teacher as an example. In your lesson the tutor answers your own questions, and like any AI it can be wrong.
What you will be able to do
- Apply core data protection principles to each stage of an AI project
- Identify AI specific privacy risks such as memorisation and inferred sensitive traits
- Map data flows including vendors and international transfers
- Prepare an impact assessment outline and questions for privacy counsel
Lesson plan
- 1 Principles as project tasks Translate core principles into concrete project actions. Start
- 2 Purpose and lawful basis Assess whether data may be reused for AI. Start
- 3 AI specific risks Recognise privacy risks unique to AI systems. Start
- 4 Mapping data and vendors Build a data map covering all flows and parties. Start
- 5 Rights and automated decisions Plan for individual rights and significant automated decisions. Start
- 6 Impact assessment and next steps Outline a data protection impact assessment. Start
Try asking
About this tutor
For project managers, product owners, data and privacy professionals, and technical leads planning AI projects that touch personal data. You learn how core data protection principles apply to AI: lawful basis and purpose, data minimisation, accuracy, storage limits, security, transparency and individual rights, including rights related to automated decisions in some jurisdictions. You look at AI specific issues: training on personal data, personal data appearing in model outputs, vendor and international transfers, and impact assessments. You work through a project case and produce a data map and a list of questions for your privacy team. Education only, not legal advice.
Reviews
4.5
2 ratingsSample
- Folake I.Sample
Clear translation of principles into tasks. The data map exercise was the most useful part. Dense in places but appropriate for the level.
- Henrik O.Sample
The point that deletion from trained weights is hard led us to redesign around retrieval. Saved us a difficult conversation with our DPO later.
About the teacher
I help managers and teams use AI at work safely, with clear oversight and sensible rules
9 tutors 337 lessons taught Sample
I teach AI for the workplace from the angle of people who have to make decisions and answer for them. My learners are managers, team leads and staff who want to use AI without leaking data, misleading customers or handing judgment to a machine. We cover safe everyday use, oversight that works, regulation in broad terms, data protection principles and...
See Alejandra's profile and tutorsMore like this
Other tutors on the same or nearby topics.