Compliance and Governance
Adhere to relevant regulatory governance and technical standards compliance
List legal compliance with territorial-specific regulation of relevant data/privacy e.g. GDPR).
Consolidated compliance documentation shared across teams (eg legal, devs, marketing)
Identify multi-territorial legal compliance (when applicable).
Data retention across jurisdictions
User profiling and user-data access
Content moderation (when applicable) for jurisdiction with enhanced legal compliance (ie. Germany)
Select standards and compliance monitoring.to be used
Document decisions behind the selection of technical standards
Circulate normative conditions for compliance with selected technical standards
This also might include ensuring compliance specs with your 3rd party suppliers and vendors, as well as with your downstream customers.
For regulators / policy makers
Rights Based Compliance
Do your civic tech tenders have established algorithmic governance norms built into contract?
Do your vendors adhere to documented rights-based assessments?
Further Reading
Mandating Human Rights Impacts Assessments in the AI Act (EU)
Data & Society; and the European Center for Not-for-Profit Law. 2021
Resource availability
Regulators can create easy-to-use resources for various application domains. For instance, what laws apply to emotion recognition and detection algorithms? This might include data retention laws, consent statues, protections on camera and/or sensors in public spaces, etc.
PDF-format fact sheets should include a URL that directs to the latest version of legal resources so devs and standards authors are able to access the latest version of the doc.
Information commissioners
Data commissioners
Court rulings
Sample resources
Background resource on the UK’s The Data Protection Act https://www.gov.uk/data-protection
Compliance, documentation & enforcement
Project authorization for publicly tendered projects
Documentation
Formal intake mechanisms for SBOM for AI applications approval
Public repositories for approved SBOM for AI applications
Compliance
Adherence to legal safeguards
Incident response
Access management
Data privacy
Operational security
Enforcement
Delegated parties to oversee documentation, compliance
Proper training and tooling for parties responsible for enforcement
Fit for purpose ADM
Further reading:
The Dutch Tax Authority Was Felled by AI—What Comes Next? European regulation hopes to rein in ill-behaving algorithms Rahul Rao, May 2022, IEEE Spectrum
Risk Mapping
Industry engagement to inform real-world threat assessments
Documented threat vectors
Elaborating on vulnerability pen testing best-practices
Whitelist of of Recommended Standards
Further reading:
UK Information Commissioners Office: AI and data protection risk toolkit