Skip to main content
Skip to content
Machine Learning

Data Protection and Privacy

The rules, the safeguards and the paperwork that let an AI project touch personal data and pass the review: what may be used, by whom, where it goes, and how you prove it.

01 / 04

The project stalls at the DPO's desk

GDPR, the AI Act, sector rules, a customer contract, each with its own question. Strip the data and the model learns nothing. Copy it and a breach would be of everything.

CH.01 · The problem

The AI project stalls at the DPO's desk.

  1. The rules are many and specific

    GDPR, the AI Act, sector regulation, a works council, a customer contract. Each asks a different question, and the project has to answer all of them before it starts.

  2. Privacy and usefulness pull apart

    Strip the data until it is safe and the model learns nothing. Keep it rich and legal says no. Without a method, the team picks one and loses.

  3. A breach would be of everything

    Data copied into a training environment with wide access is a second copy of the crown jewels. If it leaks, so does the whole history.

Our answer

Safeguards designed with the DPO, then built in

We assess the risk with your data protection officer, choose the technical safeguards that keep the data useful, and write the governance so each use is allowed, logged and reviewable. The project passes the review because it was designed for it.

CH.02 · What we build

How we build it

Three parts: know the risk, put the safeguards in, and keep them in force.

Techniques that keep the data usefulMapped to the regulationGovernance that runsWorking with partners, legally
01

Privacy risk assessment

What data, what use, what could go wrong.

  • Inventory the personal data each use case touches
  • Map the legal bases and the applicable rules
  • Define the threat: who could learn what, how
  • Rate the risk per use case with the DPO
  • Set the safeguards each risk requires
02

Technical safeguards

Built into the pipeline and the model.

  • Minimise: only the fields the task needs
  • Pseudonymise at the source, keys held apart
  • Apply differential privacy or federated training where the risk requires
  • Least access, encryption at rest, in transit and in use
  • Log every access and every model run
03

Governance framework

The rules, the owners, the reviews.

  • Write the data use policy for AI
  • Assign an owner per data set and per model
  • Set retention and deletion, enforced by the pipeline
  • Define the review cadence and the incident path
  • Produce the DPIA and the records of processing
CH.03 · How it runs

How it runs

Four phases, with your DPO at each gate.

  1. 01Phase 1

    Assessment

    Data, rules, threats, risk ratings.

    • Inventory the personal data in scope
    • Map the applicable rules and legal bases
    • Define the threat model
  2. 02Phase 2

    Privacy architecture

    The safeguards, designed.

    • Design minimisation and pseudonymisation
    • Choose the privacy technique per use case
    • Design access, encryption and logging
  3. 03Phase 3

    Implementation

    Built into the pipelines and systems.

    • Implement the safeguards in the data pipeline
    • Apply the technique in model training
    • Enforce access and retention in the systems
  4. 04Phase 4

    Validation and governance

    Proof, then routine.

    • Independent test of the safeguards
    • Produce the DPIA and the records
    • Train the owners on the rules
CH.04 · What changes

What changes

The project passes review, the data stays useful, and a leak would not be a catastrophe.

Approval, with the evidence attached

The DPIA, the safeguards and the logs come out of the design. The DPO reviews a working system.

Models that still learn

Safeguards chosen for the task keep the signal in the data. Accuracy is measured under the safeguard and reported next to the guarantee.

Smaller blast radius

Minimised data, pseudonyms, least access and logs. What an attacker could take is less, and what they took would be traceable.

Side by sidePrivacy at the endPrivacy by design
Data handlingFull copies in a training environmentMinimised, pseudonymised, in place where possible
ControlsAccess lists, hopefullyLeast access, encryption, logs, enforced
Regulatory riskDiscovered at reviewRated in assessment, mapped to each rule
If there is a breachThe whole historyMinimised data, traceable
What you can buildWhatever legal did not stopThe use cases the safeguards allow, on record
CH.05 · Questions

Questions

Some cost accuracy, some cost nothing. Minimisation and pseudonymisation rarely change what a model learns. Differential privacy trades accuracy for a guarantee, and the amount is measured: the model under the safeguard against an unconstrained baseline, reported with the privacy budget so the DPO and the business owner decide together.

GDPR is the baseline and the AI Act adds obligations for some uses. Sector rules, health, finance, public sector, add their own. The assessment maps each use case to the rules that apply, and each safeguard to the article or clause it satisfies, so the DPIA is written from the design.

Any personal or confidential data an AI project touches: customer records, patient data, employee data, transactions, documents with names in them, logs. The technique differs by type: structured records suit minimisation and differential privacy, documents need redaction and access control, partner data suits federated or secure computation.

The safeguards are enforced by the pipelines and systems themselves. Access and model runs are logged, retention and deletion run automatically, and a review cadence with a named owner checks the logs, the budget and the rules against new use cases. An incident path says who does what if something goes wrong.

More in Machine Learning

The map of the practice

Back to Machine Learning
Start

Bring us the problem nobody has cracked yet.

We are a small team of senior specialists. We pick the right model and the right layer, and we build the least machinery that does the job. You get a call with an engineer, not a sales deck.