article thumbnail

GDPR Considerations When Developing and Deploying AI Models: The EDPB’s Opinion on Compliance

Debevoise Data Blog

Given that AI models require large swathes of data to operate, the GDPRs expansive definition of personal data means that many applications of AI involve complex data protection issues especially where those datasets are obtained from third-party sources. Undertaking due diligence on the AI model/system providers data protection compliance.

article thumbnail

Maturing Compliance with the Bulk Sensitive Data Rule (Data Security Program) before the July 8, 2025 Safe Harbor Expires

Debevoise Data Blog

The Compliance Guide Clarifications re Secondary Due Diligence Obligations and Model Contractual Language for Onward Transfers In the Guide, DOJ provides helpful guidance on certain important items under the DSP broadly, including the fact that U.S. person fails to detect such violations.

professionals

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

When AI Failures Could Be “Operations Events” Under Form PF

Debevoise Data Blog

While the SEC initially proposed to define a “significant” disruption as a 20% disruption or degradation of normal volume or capacity, the final version of Form PF did not adopt that definition. no more than 24 hours) of an AI-related event that could trigger a Form PF reporting obligation for the firm.

article thumbnail

European Data Protection Roundup – January 2025

Debevoise Data Blog

The EDPB adopted guidelines on pseudonymisation, which clarify the definition of pseudonymised data and how the GDPR applies to it, as well as exploring the advantages of using pseudonymisation. EDPB issues guidelines on pseudonymisation.

article thumbnail

Treasury’s Post-2024 RFI Report on AI in Financial Services – Uses, Opportunities, and Risks

Debevoise Data Blog

Suggested mitigations: Respondents offered several potential mitigants, including strong third-party risk management (TPRM) frameworks and robust due diligence processes, a topic we have previously discussed.

article thumbnail

Biden Administration Proposes to Limit Access to Sensitive Personal Data by Countries of Concern

Debevoise Data Blog

Covered data transaction definition. In response to comments to the Advance Notice, the DOJ revised the definition of a “covered data transaction” to any transaction that involves any access to the data by the counterparty to a transaction (rather than any transaction that involves government-related data or bulk U.S.

article thumbnail

Thomson Reuters Launches AI-Powered Contract Analysis Tool in HighQ

LawSites

Integrated with HighQ, the collaboration and workflow platform Thomson Reuters acquired in 2019, HighQ Contract Analysis is designed for attorneys to use in transactional due diligence, compliance review and contract investigations.