AIG-014 Special Category Data in Training and Evaluation Datasets
Description
Every dataset used to train, fine-tune or evaluate a model carries a recorded screening result naming the special categories of personal data it was screened for, the outcome and the date of the screen. Where a dataset holds such data, the record of processing activities entry for it records the lawful basis relied on, a necessity assessment showing that no less intrusive alternative was available, the security measures applied, a named sign-off and a retention and deletion schedule. A dataset held solely for bias detection and correction carries its own entry with its own deletion date. Access to a dataset holding special category data is restricted to the roles that entry names.
Rationale
The old wording was a conditional prohibition, so a pipeline nobody had examined passed it by default. The screening result is what makes absence provable: a recorded negative screen and an unexamined dataset look identical until somebody writes the result down. The bias-correction case needs its own entry because the necessity argument and the deletion obligation are different from those for a dataset used to build the model. DAT-024 holds special category and criminal conviction data across all processing, including the HR, support and telemetry data no AI system touches; this control holds the training and evaluation datasets. DAT-013 holds the impact assessment and DAT-019 the lawful basis for processing generally.
Applicability (9 profiles)
Screening of the provider's training and evaluation sets is the provider's. Evaluation sets the deployer builds from its own data carry the DAT-024 screening result.
New Art.4a(1), inserted by Regulation (EU) 2026/1744, is what makes the bias-detection case usable and what it costs. Special categories may be processed only to the extent strictly necessary for bias detection and correction under Art.10(2), points (f) and (g), only where the same result cannot be reached by processing other data including synthetic or anonymised data and only under technical limitations on re-use with state-of-the-art security and privacy-preserving measures. The screening record therefore carries a finding the GDPR basis does not supply on its own, that no less intrusive dataset would have worked. The dataset held solely for bias correction is the one Art.4a(1) is about.
Screening of the provider's training and evaluation sets is the provider's. Evaluation sets the deployer builds from its own data carry the DAT-024 screening result.
Framework Mappings (10)
| EU-AI-Art.10.4 | Data Governance — Special Category Data Processing for Bias Detection | partial |
| GDPR-Art.10 | Criminal Conviction and Offence Data | informative |
| GDPR-Art.5.1a | Lawfulness, Fairness and Transparency of Processing | partial |
| GDPR-Art.9.1 | Prohibition on Processing Special Categories of Personal Data | informative |
| GDPR-Art.9.2 | Exceptions to the Special Category Prohibition | informative |
| PT-7 | Specific Categories of Personally Identifiable Information | partial |
| MP-4.1-005 | AI Technology and Legal Risk Mapping | MP-4.1-005 | informative |
| MP-4.1-010 | AI Technology and Legal Risk Mapping | MP-4.1-010 | informative |
| MS-2.10-001 | AI Privacy Risk Examination | MS-2.10-001 | informative |
| MEASURE 2.10 | AI Privacy Risk Examination | informative |
Evidence (2)
Screening results for training and evaluation datasets, with the record of processing activities entry for each dataset that screened positive, recording the lawful basis, the necessity assessment, the security measures applied, the sign-off and the deletion schedule.
Example: ROPA entry · Health Data in Bias Correction Pipeline (OneTrust or SharePoint), recording GDPR Art. 9(2)(g) basis, necessity justification, pseudonymisation and encryption controls applied, DPO sign-off, and deletion schedule
Test: Request the screening results for the datasets used by production models and the record of processing activities entries for those that screened positive. Verify: (1) every dataset in the sample carries a screening result with the categories screened for, the outcome and the date, (2) a positive result has a corresponding record of processing activities entry, (3) the entry states the lawful basis relied on for that category, (4) necessity is assessed and records why no less intrusive alternative was available, (5) the security measures and the roles permitted to access the dataset are listed, (6) a retention and deletion schedule is stated, (7) a dataset held solely for bias detection and correction has its own entry and its own deletion date.
Technical access controls configuration demonstrating that special category training data is isolated and accessible only to authorised roles in the data pipeline.
Example: AWS S3 bucket policy and IAM role configuration for special-category-training-data bucket: access restricted to ml-training-role with MFA required, object-level encryption enabled (SSE-KMS), no public access, access logs enabled
Test: Review the access control configuration for the storage holding any training or evaluation dataset that screened positive. Verify: (1) access is restricted to the roles named in the record of processing activities entry for that dataset, (2) encryption at rest is applied, (3) no public access is permitted, (4) access logging is enabled, (5) the configuration matches the security measures the entry states.
Questions (2)
Does every training and evaluation dataset carry a recorded special-category screening result?
The screening result records what the dataset was screened for, the outcome and the date, whether or not special category data was found. A dataset that has never been screened does not meet the control even if it holds no such data.
Where a training or evaluation dataset holds special category personal data, which of the following are recorded for it?
Answer for the datasets that screened positive. If no dataset holds special category data, the screening results in Q1 are the evidence and this question does not apply. Absence should be recorded positively rather than assumed.