10. of Inference
You do not make any checks on personal data before you use it for training machine learning models.
Threat |
|
You are not checking personal data before using it in training, so you cannot expect your model to be accurate. Therefore, some of the decisions it will make will also not be accurate, which implies it may unfairly make decisions about a subject, such as mortgage approvals/refusals. A requirement of many data privacy regulations is that the data be kept accurate. It is also possible that an attacker may modify the data deliberately to poison the model and you could be leaving yourself open to injection attacks. |
|
GDPR |
Chapter 2, Art. 5 – 1.(d) Chapter 2, Art. 5 – 1.(f) |
CCPA & CPRA |
N/A |
OECD ... |