Administrative Measures for the Security Assessment of Generative AI Services (2023) and Algorithmic Recommendation Management Provisions (2022)
Generative AI Measures

Administrative Measures for the Security Assessment of Generative AI Services (2023) and Algorithmic Recommendation Management Provisions (2022) CN-GAI-A11: Protection of User Input and Records

Providers must fulfil personal-information protection duties for user input information and usage records; must not collect unnecessary personal information, unlawfully retain input/records that can identify users, or unlawfully provide them to others; and must handle data-subject access, copy, correction, supplement and deletion requests in accordance with law.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 3 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

GDPR · 3 controls

  • GDPR-Art.15 Right of access by the data subject
  • GDPR-Art.17 Right to erasure (right to be forgotten)
  • GDPR-Art.5 Principles relating to processing of personal data

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Generative AI Measures

Query this from an agent

The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.