Skip to content
>_<
AI EngineeringWiki

Privacy Practices

Compliance · 5 min

Practical steps to implement data protection in your AI projects.

Technical & Organizational Measures (TOM) — illustration from the German article

Technical & Organizational Measures (TOM)

  • Encryption at rest and in transit
  • Access controls and authentication
  • Logging and monitoring
  • Regular security testing
  • Staff training
  • Incident response plan
Data Processing Agreement (DPA) — illustration from the German article

Data Processing Agreement (DPA)

  • Contract with all processors
  • Processors must meet GDPR standards
  • Right to audit
  • Sub-processor approval required

Documentation

  • Art. 30 Processing Records
  • Data Protection Impact Assessment (DPIA)
  • Consent management
  • Processing purposes
  • Retention schedules

Data Subject Rights

RightDeadline
Access1 month
Rectification1 month
Erasure1 month
Portability1 month
AI-Specific Considerations — illustration from the German article

AI-Specific Considerations

  • Log AI decisions for accountability
  • Document training data sources
  • Implement human oversight
  • Regular bias testing
  • Transparency in AI communications

Related articles

Was this article helpful?

Continue the learning path

The learning path puts these articles in order, and the Hub carries the building blocks we have checked in our own operations.

Why AI Engineering
  • Local and self-hosted
  • Documented and verifiable
  • From our own operations
  • Made in Austria
Not legal advice.