S0117RS3-T07-S0117-Z · Full risk code

Difficulty Exercising Data Subject Rights

資料主體權利難以行使

Operation & Monitoring
Risk Description

When a user requests that the organization delete their personal data and exclude it from the model; due to unmitigated control gaps, the organization can delete the source data but cannot remove the learned influence from model parameters, nor can it afford retraining, triggering external stakeholder impacts and causing only a partial response is possible, and the right is effectively obstructed.

Framework Mappings

EU AI ActArt.10
NIST AI 600-1Data Privacy
ISO/IEC 42001Annex A.7.2
ISO/IEC 5338運作與監控
MIT AI Risk RepositoryDomain 2

Risk Treatment & Implementation Guidance

Establish a data-subject rights procedure specifying scope and timelines for handling deletion of source data and its model influence; Evaluate machine-unlearning feasibility and honestly disclose technical limits where full removal is impossible; Design for erasability before data enters training—batch training and provenance tagging—to lower future response costs