Missing Personal Data Impact Assessment
個人資料影響評估缺漏
Inception
Risk Description
When an organization develops an AI system involving large volumes of personal data without a privacy impact assessment (PIA) at the design stage; due to missing prior records and privacy-by-design, the system struggles to demonstrate due diligence during breach disputes, leading to severe penalties and loss of trust.
Framework Mappings
EU AI ActArt.10、Art.27
ISO/IEC 42001Annex A.5.2、A.5.4
NIST AI RMFMAP 3.1、MEASURE 2.10
ISO/IEC 5338設計與開發
MIT AI Risk RepositoryDomain 2
Risk Treatment & Implementation Guidance
For AI systems involving large volumes of personal data, require a privacy impact assessment at the design stage and retain the assessment records and risk-benefit rationale; Embed privacy-by-design in the development process, specifying data collection scope, purposes of use and retention periods in requirements and design documents