AI systems create new privacy risks that traditional privacy assessments were not designed to address. Training data, model inputs and outputs, automated decisioning, sensitive attributes, and AI vendors all require structured privacy review.
What to assess
- Training data: where it came from, what personal data it contains, and what consent applies.
- Model inputs and outputs: what personal data flows through the model at inference time.
- Automated decisioning: whether decisions affect individuals and whether human review is required.
- Sensitive attributes: whether the model processes or infers protected categories.
Building the review workflow
AI privacy reviews should be structured, repeatable, and embedded into the AI development lifecycle — not bolted on as a compliance exercise after launch.
