EU AI Act
EU AI Act - Innovation Measures

EU AI Act EUAI-Art.59: Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox

Where personal data lawfully collected for other purposes is processed in an AI regulatory sandbox solely to develop, train and test an AI system, every one of the Art.59(1) conditions must be met cumulatively: the system is developed to safeguard a substantial public interest in one of the listed areas; the personal data is necessary because anonymised, synthetic or other non-personal data cannot effectively fulfil the Chapter III Section 2 requirement in question; effective monitoring mechanisms identify high risks to the rights and freedoms of data subjects and response mechanisms promptly mitigate them and stop the processing where necessary; the data sits in a functionally separate, isolated and protected processing environment under the prospective provider's control with access limited to authorised persons; originally collected data is shared further only in accordance with Union data protection law and personal data created in the sandbox is not shared outside it; the processing leads to no measures or decisions affecting the data subjects and does not affect their rights; appropriate technical and organisational measures protect the data and it is deleted once sandbox participation ends or the retention period expires; processing logs are kept for the duration of participation; a complete and detailed description of the process and rationale behind training, testing and validation is kept with the test results as part of the Annex IV technical documentation; and a short summary of the project, its objectives and expected results is published on the competent authority's website. Law enforcement processing must in addition rest on a specific Union or national law and meet the same cumulative conditions.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 28 controls across 7 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

SOC 2 · 9 controls

  • SOC2-C1.1 C1.1 Identifying and maintaining confidential information
  • SOC2-C1.2 C1.2 Disposing of confidential information
  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SOC2-P3.1 P3.1 Collecting personal information consistent with objectives
  • SOC2-P4.1 P4.1 Limiting use to identified purposes
  • SOC2-P4.2 P4.2 Retaining personal information
  • SOC2-P4.3 P4.3 Securely disposing of personal information
  • SOC2-P6.1 P6.1 Disclosure to third parties with consent

ISO 27001:2022 · 5 controls

  • 5.15 Access control
  • 5.34 Privacy and protection of personal identifiable information (PII)
  • 8.10 Information deletion
  • 8.3 Information access restriction
  • 8.31 Separation of development, test and production environments

NIST SP 800-53 Rev 5 · 4 controls

  • NIST800-PM-25 PM-25 Minimization of Personally Identifiable Information Used in Testing, Training, and Research
  • NIST800-PT-2 PT-2 Authority to Process Personally Identifiable Information
  • NIST800-PT-3 PT-3 Personally Identifiable Information Processing Purposes
  • NIST800-SI-19 SI-19 De-identification

GDPR · 3 controls

DORA · 1 control

ISO/IEC 42001:2023 · 1 control

  • A.7.3 Acquisition of data

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in EU AI Act - Innovation Measures

You are reading one control. How much of EU AI Act have you already done?

EU AI Act EUAI-Art.59 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of EU AI Act your existing evidence covers. Hold ISO/IEC 42001:2023 and 17 of 43 EU AI Act controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO/IEC 42001:2023 pair alone.

Query this from an agent

The graph holds this control, the 28 it maps to, and the evidence behind each claim, over MCP and REST.