Remove Compliance Remove Definition Remove Due diligence
article thumbnail

GDPR Considerations When Developing and Deploying AI Models: The EDPB’s Opinion on Compliance

Debevoise Data Blog

Given that AI models require large swathes of data to operate, the GDPRs expansive definition of personal data means that many applications of AI involve complex data protection issues especially where those datasets are obtained from third-party sources. Undertaking due diligence on the AI model/system providers data protection compliance.

article thumbnail

Maturing Compliance with the Bulk Sensitive Data Rule (Data Security Program) before the July 8, 2025 Safe Harbor Expires

Debevoise Data Blog

On April 11, 2025, shortly after the first effective date of the DSP the National Security Division (NSD) of DOJ issued asuite of three policy and guidance documents to facilitate compliance with the DSP, including a 90 day civil enforcement safe harbor for good-faith compliance. Intelligence Community.

professionals

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

When AI Failures Could Be “Operations Events” Under Form PF

Debevoise Data Blog

While the SEC initially proposed to define a “significant” disruption as a 20% disruption or degradation of normal volume or capacity, the final version of Form PF did not adopt that definition. Because the $1.5 When Could an AI Failure Trigger Reporting?

article thumbnail

European Data Protection Roundup – January 2025

Debevoise Data Blog

The Italian DPA opened an investigation into DeepSeek for possible GDPR non-compliance associated with its AI chatbot services data collection and processing activities. UK ICO acts on cookie compliance. DeepSeek investigated by Italian DPA over AI chatbot data collection practices. EDPB issues guidelines on pseudonymisation.

article thumbnail

Treasury’s Post-2024 RFI Report on AI in Financial Services – Uses, Opportunities, and Risks

Debevoise Data Blog

For internal uses, respondents emphasized the growing role of AI in compliance, risk management, and operations, with generative AI in particular enhancing tasks like report creation, data analysis, and detecting anomalies in anti-money laundering and sanctions compliance.

article thumbnail

Biden Administration Proposes to Limit Access to Sensitive Personal Data by Countries of Concern

Debevoise Data Blog

Covered data transaction definition. In response to comments to the Advance Notice, the DOJ revised the definition of a “covered data transaction” to any transaction that involves any access to the data by the counterparty to a transaction (rather than any transaction that involves government-related data or bulk U.S. Data mapping.

article thumbnail

Thomson Reuters Launches AI-Powered Contract Analysis Tool in HighQ

LawSites

Integrated with HighQ, the collaboration and workflow platform Thomson Reuters acquired in 2019, HighQ Contract Analysis is designed for attorneys to use in transactional due diligence, compliance review and contract investigations.