Before you feed personal data into an AI tool or model, ask: what data is included, what’s the legal basis, how long will outputs and logs be kept, and whether the use matches your privacy notices and user expectations.
The Evidence Question to Ask Yourself: Can you show what data was used in the AI project, the legal basis, retention setting, and how it matches your privacy notices?