IA-04 Privacy
Ensures that the collection and use of personally identifiable information (PII) are properly controlled, kept confidential, and not abused during the development, input, or output processes of the AI system, preventing unauthorized disclosure, excessive surveillance, and personal data breaches.
Representative ScenariosS0032 Training on Personal Data Without ConsentS0034 Secondary Use Beyond Collection PurposeS0035 Implicit Collection and Opaque ConsentS0112 Excessive Collection and Retention of Interaction DataS0114 Confidential Information Inadvertently Disclosed in PromptsS0115 Cross-Border Transfer Violating Localization Requirements
Representative ScenariosS0106 Data Leakage Through Model MemorizationS0107 Membership Inference Revealing ParticipationS0108 Attribute Inference Revealing Undisclosed TraitsS0109 Conversation Content Leaking Across UsersS0110 Reconstruction Risk from Vector RepresentationsS0111 Identity Inference by Correlating Fragmented DataS0113 Model Inversion Reconstructing Training Data
Representative ScenariosS0117 Difficulty Exercising Data Subject RightsS0205 Data Persisting in Models Beyond Retention Limits