1. To the extent strictly necessary to ensure bias detection and correction in relation to high-risk AI systems in accordance with Article 10 (2), points (f) and (g), of this Regulation, providers of such systems may exceptionally process special categories of personal data, subject to appropriate safeguards for the fundamental rights and freedoms of natural persons. In addition to the provisions set out in Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, as applicable, all the following conditions shall be met in order for such processing to occur:
2. Providers and deployers of other AI systems and models and deployers of high-risk AI systems may exceptionally process special categories of personal data to the extent that:
2b. This paragraph does not create any obligation to conduct such bias detection and correction.






The organisation should define and document a strict process for the exceptional use of special categories of personal data for the purpose of bias detection and correction in its AI systems. This process must ensure compliance with all legal safeguards.
The process should include at least the following requirements:
Strict, role-based controls should be placed on access to any special categories of personal data processed for bias detection. Access must be limited to authorised persons with a clear need. All access to this data should be logged and reviewed to prevent misuse. All personnel with access should be subject to specific confidentiality obligations.






The organisation should implement strict measures to control and monitor access to special categories of personal data used for bias detection. This ensures the data is not misused and access is limited on a need to know basis.
Measures should include:
Digiturvamallissa kaikki vaatimuskehikkojen vaatimukset kohdistetaan universaaleihin tietoturvatehtäviin, jotta voitte muodostaa yksittäisen suunnitelman, joka täyttää ison kasan vaatimuksia.
.png)