Secure Data For Responsible Artificial Intelligence
Data forms the foundation on which artificial intelligence systems are built, making its protection and responsible management essential. The International Federation of Artificial Intelligence believes that true innovation cannot be separated from respect for privacy, the protection of individual rights, and the safe and fair use of information.
Privacy First
Trusted Data
Transparent Use
Continuous Accountability
Sustainable Protection Requires
a System, Not Isolated Measures
The Federation encourages institutions to adopt a clear data governance framework that defines responsibilities, classifies information, manages access rights, documents processing, assesses risks, and responds to security incidents.
Define Responsibilities
Clarify the roles and entities responsible for collecting, processing, and protecting data.
Data Classification & Access Control
Align data sensitivity with appropriate levels of access, storage, and sharing.
Documentation & Risk Assessment
Maintain clear processing records and regularly review potential impacts.
Response & Continuous Improvement
Develop incident response plans and update policies in line with technological and regulatory changes.
A Practical Framework for Responsible Data Use
Seven principles that form the foundation of any responsible practice when collecting data or using it to develop and operate artificial intelligence systems.
Data must be collected and processed for a specific and legitimate purpose, in a clear and fair manner that enables individuals to understand how their information is used and with whom it may be shared
Data should only be collected for clearly defined and stated purposes, and should not be reused for incompatible purposes without a legitimate basis or appropriate consent.
Data should be limited to what is necessary to achieve the specified purpose, avoiding the collection of additional information that is not directly relevant to the required service, system, or activity.
Data should be accurate, up to date, and relevant, particularly when it influences the outputs of artificial intelligence systems or decisions affecting individuals.
Data protection requires appropriate organizational and technical measures to prevent unauthorized access, leakage, alteration, or loss during storage, transmission, and processing.
Data should not be retained longer than necessary. Once the intended purpose has been fulfilled, it should be securely deleted, anonymized, or destroyed.
Organizations that collect or process data are responsible for documenting their practices, assessing risks, and demonstrating compliance with privacy and information protection principles.
Protection Follows Data at Every Stage of Its Journey
Privacy is not addressed at a single point; safeguards are applied throughout the entire data lifecycle, from the source through to secure deletion or anonymization.
Source & Collection
Verify the legitimacy of the data source, clarify the purpose, and assess whether the data is necessary.
Training & Processing
Assess data quality, representation, and bias, while minimizing sensitive data wherever possible.
Operation & Decision-Making
Clarify the role of artificial intelligence, control access, and ensure appropriate human oversight.
Review & End of Lifecycle
Monitor risks, update safeguards, and securely delete or anonymize data when no longer needed.
Clarity, Access, Correction, Deletion & Review
These rights enable individuals to understand how their data is processed and to engage with that processing in a fairer and more transparent manner.
Right to Know
Understand what data is collected, the purpose of its use, the responsible entity, and how long it will be retained.
Right to Rectification
Request the correction of inaccurate data, completion of missing information, or updates where necessary.
Withdrawal of Consent
Withdraw consent in cases where consent is the legal basis used for processing personal data.
Right of Access
Request access to stored personal data and obtain a clear copy whenever legally available.
Right to Erasure
Request the deletion of data when it is no longer needed or when there is no longer a legitimate basis for retaining it.
Right to Object & Review
Object to certain forms of processing and request a review of significant decisions based primarily on automated processing.
This content provides general guidance only and does not constitute legal advice or an announcement of supervisory or legal mechanisms that have not been officially adopted by the Federation.
