Topics · 03
AI, Personal Data Governance & Cross-Border Compliance
Trace data flows across foundation models, RAG architectures and third-party APIs, auditing legal bases, notice and consent, retention limits, cross-border compliance and exit terms.
How can enterprises protect proprietary data and personal information from unauthorized secondary training and retention?
Key Trigger Scenarios
- Employees entering confidential client data or proprietary documents into public LLMs
- AI systems processing sensitive personal data, biometric traits or user profiling
- Procuring overseas AI models, cloud infrastructure, annotation or compute resources
- Using real production data for model evaluation, fine-tuning or system iteration
Preliminary Due Diligence & Materials
- 01Compile an AI data inventory mapping categories, sensitivity, recipients and cross-border paths
- 02Review vendor terms to prohibit model training, retention and unauthorized onward sharing
- 03Upgrade privacy policies, just-in-time notices, and personal data rights mechanisms
- 04Establish data incident response plans with verified data deletion and exit protocols
Selected Cases
Judicial Trends & Regulatory Standards
Read each case in its procedural context. Related cases may offer comparisons across technologies; they do not establish a single rule for every system.
EU SCHUFA Scoring Case
A credit agency automatically generated credit scores for use by third parties such as banks. The Court of Justice of the European Union held that when a score plays a decisive role in a third party's decision, the scoring activity constitutes automated individual decision-making governed by Article 22 of the GDPR.
Final Interpretive Judgment
- The court confirmed that scoring falls under the rules on automated individual decision-making when it plays a decisive role in third-party decisions.
- Such processing requires a valid legal basis and appropriate safeguards for data subjects' rights.
EU Automated Decision-Making Explanation Case
The Court of Justice of the European Union ruled that data subjects are entitled to an explanation sufficient to understand and challenge automated decisions. Such explanations must disclose the concrete procedures and principles applied and illustrate how changes in personal data influence the resulting outcome.
Preliminary Ruling
- The explanation must convey the procedures and principles underlying the automated decision in a concise, intelligible format.
- The explanation must enable the data subject to understand how specific personal data affected the decision and to contest the outcome effectively.
Netherlands SyRI Risk Profiling Case
The Dutch government integrated multi-agency public data to generate fraud risk profiles for social welfare recipients. The court held that the regulatory regime lacked sufficient transparency and auditability, failing to strike a fair balance in its interference with the right to private life.
First-Instance Judgment
- The court held that the legislation governing SyRI violated Article 8 of the European Convention on Human Rights.
- The court determined that the system lacked sufficient transparency and verifiability, failing to maintain a fair balance between the interference with privacy rights and the public objective.
Netherlands Ola Driver Data Access Case
Ride-hailing drivers sought access to platform data used for scoring, fraud detection, earning profiles, and wage deductions. The court distinguished between general profiling, dispatch algorithms, and automated deductions with significant effects, ordering the platform to disclose specific categories of underlying data.
First-Instance Order
- The court ordered Ola to disclose the personal data and segment classifications used to generate certain driver profiles.
- Standard automated dispatching was held not to produce significant effects in this case.
Related Services
Tailored Legal Services for This Scenario
AI & Data Compliance
Map data sources, processing roles, purposes, flows and controls across AI systems.
View Legal Service →03AI Product Compliance
Embed legal review into design, development, procurement, testing, launch, operation and updates.
View Legal Service →05Model & Platform Governance
Review admission, risk tiering, content safety, monitoring, audit and accountability for models, algorithms and platforms.
View Legal Service →06Enterprise AI Governance
Establish enterprise AI planning, tool admission, data permissions, internal policies, training, audit and incident response.
View Legal Service →Regulatory Frameworks
Applicable Regulatory Frameworks
China: PIPL Automated Decision-Making Rules
In force
EU GDPR Automated Decision-Making Rules
In force
Singapore Personal Data and AI Guidelines
Current guidance
Hong Kong AI Data Protection Framework
Current guidance
Research team