DG-011HighProvider & DeployerPreventive
Data Processing Records (Article 30 GDPR)
Where training or inference involves personal data, providers must maintain records of processing activities as required by GDPR Article 30, describing the categories of data, purposes of processing, and technical safeguards in place.
Articles:Article 10(5)Article 10(6)
Evidence Examples
- GDPR Article 30 record of processing
- Data processing impact assessment
- Data flow diagram
Standards
ISO/IEC 27701:2019ISO 42001:2023 §8.2
Related controls
- DG-001Training Data Quality RequirementsArticle 10(3) requires that training, validation, and testing data sets are subject to data governance practices that ensure relevance,…
- DG-002Bias Detection and CheckingProviders must examine training, validation, and testing datasets for possible biases that could affect health, safety, or fundamental rights, and…
- DG-003Data Documentation and ProvenanceProviders must document the origin, collection methodology, labelling process, and relevant characteristics of all data sets used in training, validation,…
- DG-004Data Representativeness AssessmentArticle 10(3) requires that training data sets are sufficiently representative of the intended population and use-case context, and providers must…
- DG-005Data Relevance and Completeness CheckProviders must verify that data sets used for high-risk AI systems are relevant and complete for the system's intended purpose, documenting any known gaps…
- DG-006Data Annotation Quality AssuranceWhere data labelling or annotation is performed, providers must implement quality assurance procedures to ensure consistency, accuracy, and…
Related EU AI Act terms
Upgrade when it needs to be
The free questionnaire returns preliminary signals. The Full Assessment turns real system material into a governed decision record - extraction, component separation, evidence, national overlays, and a review-ready dossier.
Start free risk preview