Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

AI safety teams should share data only for a defined, documented purpose, with a valid authority for the use, and with no more information or access than the task requires. Before transfer, identify the applicable jurisdictions, the data and people involved, each party’s role, and the route the information may take. Then set enforceable limits on use, security, onward sharing, retention, and incident handling.

This is a governance baseline, not a legal determination for a particular dataset. The applicable rules depend on the facts; involve privacy or legal counsel for sensitive data, children’s data, confidential research, high-risk processing, or cross-border transfers.

What should a data-sharing decision establish?

Write down the safety question the sharing is meant to answer before selecting a dataset or recipient. A defensible decision connects that purpose to the specific records, fields, access level, people who will use them, and expected duration. It also identifies the source of the data and any licence, contract, consent, research condition, or other restriction attached to it.

Do not treat public availability as proof that reuse is unrestricted. Check whether the proposed use is compatible with the conditions under which the data was collected or made available, and identify an applicable legal basis or other authority. Under the GDPR, covered personal-data processing must meet its principles, including lawfulness, fairness, transparency, purpose limitation, data minimisation, storage limitation, integrity and confidentiality, and accountability; Article 6 requires a lawful basis.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Clarify the parties’ roles under the applicable law before deciding what agreement and responsibilities are needed. Under the GDPR, a party may be a controller, joint controller, or processor depending on what it actually does, not merely the label in a contract. Where a controller uses a processor, Article 28 requires a binding arrangement addressing prescribed matters, and the processor must provide sufficient guarantees.

How should teams minimise and classify data?

Share only what the task needs

Remove fields and records that do not contribute to the stated safety question. Depending on the task, that may mean sampling, aggregation, removing direct identifiers, or granting access to results or a controlled environment rather than distributing a raw copy. Keep the analysis proportionate: data minimisation reduces exposure, but it does not itself establish that a use is lawful or that re-identification is impossible.

Review sensitive data and high-risk processing separately

Under GDPR Article 9, special categories include racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data used for unique identification, health data, and data concerning sex life or sexual orientation. Processing is restricted unless an applicable Article 9 exception applies. Heightened review is also prudent for vulnerable groups, including children, even where a particular dataset does not fit an Article 9 category.

For processing likely to create high risk to people’s rights and freedoms, assess whether a data protection impact assessment (DPIA) is required before proceeding. If a DPIA identifies residual high risk that cannot be mitigated, the EDPB says the controller must consult the relevant supervisory authority before processing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do not call pseudonymised data anonymous

Pseudonymisation can reduce linkability, but it does not fully sever the connection to a person. Pseudonymised personal data remains subject to applicable data-protection rules. Keep any re-identification key separate, tightly restrict access to it, and assess the risk of linking the shared data with other information available to the recipient. Only genuinely anonymous data falls outside EU data-protection law; whether a dataset meets that standard depends on its content and context, not the name of the transformation used.

What controls belong in the recipient agreement?

Set out what the recipient may do, who may access the data, how it must be protected, and what happens when the work ends. Match the controls to the sensitivity of the data, the recipient’s role, and the safety value of the collaboration.

  • Purpose and permitted use: Specify the approved task and prohibit incompatible reuse.
  • Access and personnel: Limit access to authorised people who need it, and record relevant access decisions.
  • Security: Define appropriate safeguards for storage, transfer, and access, such as encryption, access controls, logging, and secure environments.
  • Retention and disposal: Set the access period and deletion or return requirements, including how copies and derived data are handled where appropriate.
  • Onward sharing: State whether the recipient may disclose data or results to another party and require approval or equivalent protections where needed.
  • Incidents and oversight: Establish a contact and process for incident notification, cooperation, and appropriate audit or assurance.

For GDPR-covered processing, Article 32 requires security measures appropriate to risk, taking account of the state of the art, costs, and the processing’s nature, scope, context, and purpose. Its examples include pseudonymisation and encryption, measures that protect confidentiality, integrity, availability, and resilience, restoration of access after an incident, and regular testing or assessment of safeguards.

What changes when data crosses a border?

For personal data covered by the GDPR, transfers outside the EU must meet Chapter V requirements. Assess the actual route, not only the location of the primary server: map where the recipient, support staff, subprocessors, and other people with access are located, and consider relevant government-request routes. Depending on the destination and circumstances, a transfer may rely on an adequacy decision or appropriate safeguards such as standard contractual clauses (SCCs) or binding corporate rules (BCRs). A commercial contract by itself does not settle every transfer question.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Transfer mechanisms and adequacy status can change. Confirm the current route and destination status for the specific transfer with counsel and current official materials rather than relying on an old template or a general assumption about a country.

Which frameworks apply, and what do they require?

Framework What it contributes Scope and qualification
GDPR Principles and lawful-basis requirements for covered personal-data processing, plus rules concerning special-category data, processors, security, records, DPIAs, and international transfers. Binding regulation within its territorial and material scope; applicability and national implementation or enforcement details depend on the circumstances.
EU AI Act Role- and system-specific AI obligations. Article 10 includes data and data-governance requirements for high-risk AI systems; Article 53 requires providers of general-purpose AI models to draw up and make publicly available a sufficiently detailed summary of training content. Binding regulation with phased application. Do not infer that every AI research dataset must be disclosed or shared; check the actor’s role, system category, applicable dates, and exceptions.
NIST AI Risk Management Framework Operational guidance on lifecycle governance, documented legal requirements and accountability, third-party data risks, risk communication, and practices that enable testing, incident identification, and information sharing. Voluntary framework intended for developers, users, and evaluators across sectors and borders; not a substitute for binding law. NIST AI RMF 1.0 was released on 26 January 2023, and NIST says it is being revised.
OECD AI Principles Support human rights and privacy, robustness, security and safety, accountability and traceability, and representative open datasets that respect privacy. Principles are not universal binding law. Adopted in 2019 and updated in 2024.

The OECD’s 2024 policy analysis discusses divergent approaches to AI and privacy, while its 2025 government report describes practical governance challenges including privacy, bias, security, legal frameworks, intellectual property, interoperability, and rights-holder engagement. These can inform a governance design, but they do not decide whether a particular transfer is lawful.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How should teams share safety findings and incident information?

Safety evaluation and incident response may require sharing findings with external evaluators, partners, affected organisations, or the public. Decide who needs which information and why. Tailor the detail to the recipient and purpose: redact unrelated personal data, confidential research, and security-sensitive or exploit-enabling details when they are not necessary for the safety action.

Establish severity-based escalation and a route for notifying relevant recipients or authorities when required. There is no single incident-disclosure timeline that applies to every sharing scenario; deadlines and duties depend on the event, applicable law, parties’ roles, and any contractual or sector-specific obligations.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What should a team record and revisit?

Maintain a compact decision record that lets the team explain what was shared, why, with whom, under what conditions, and when the decision should be reviewed. NIST’s AI RMF treats documented responsibilities, legal requirements, third-party data controls, risk communication, and incident information-sharing as governance matters across the AI lifecycle. OECD principles likewise support traceability of datasets and processes.

  • Dataset name, source, collection context, provenance, licence or contract, sensitivity, known quality limits, and rights or restrictions.
  • Safety purpose, people affected, data fields and access level, recipient and role, legal basis or other authority, and any relevant consent or research conditions.
  • Risk review and approvals, safeguards, transfer route, access period, retention or deletion date, onward-sharing terms, and incident contact.
  • Changes to the purpose, data, recipient, system use, safeguards, or applicable law that trigger reassessment.

Revisit the decision when any of those conditions changes; an approval for one dataset, purpose, recipient, or system does not automatically cover a materially different use.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.