Skip to main content
Deliberate AcademyProfessional AI Education
~15 min left
Lesson 8 of 10
15 min read10 XP

Data, Privacy, and Governance Questions You Must Ask

Deliberate Academy Editorial Team

Reviewed for accuracy and professional relevance

You're 8 lessons in — don't lose your progress.

Sign up free
What you'll learn
  • Identify the baseline data and privacy questions an executive must ask before approving any AI deployment, independent of specific regulatory expertise
  • Explain why "the vendor said it was compliant" is not an adequate answer to a data governance question
  • Recognize when an AI use case likely involves a consequential, individual-level decision that raises the bar on the questions required
  • Recognize the principal regulatory regimes by name — GDPR and UK GDPR, the EU AI Act, and the NIST AI Risk Management Framework — and identify which of the baseline questions each one sits behind
  • Understand the boundary between this lesson's executive-level literacy and the specialized compliance depth covered in a dedicated governance course

An executive approves an AI vendor tool after the vendor confirms, in a sales call, that "we're fully compliant with data protection regulations." Six months later, the organization's legal team discovers the tool was trained on customer data in a way that had not been disclosed to customers, and that no one had actually verified the vendor's compliance claim before rollout. The executive did nothing dishonest — they trusted a confident answer from a party with every incentive to give one. This lesson gives you the baseline questions that would have caught the gap, without requiring you to become a data protection specialist.

The Baseline Questions Every Leader Must Ask

What data does this system use, and did we have the right to use it this way? Data an organization collected for one purpose — say, order fulfillment — is not automatically usable for a different purpose, like training or improving an AI model, without checking whether your original data collection basis actually covers that use. This is a question for your data protection or legal function, but the leader approving the deployment must ask it before rollout, not discover the gap after.

Does this system make or meaningfully influence a decision about a specific individual? Decisions like hiring, credit, insurance pricing, or benefits eligibility carry a materially higher bar than an internal productivity tool, both ethically and under data protection law in many jurisdictions. If the answer is yes, that is the signal to involve legal and compliance expertise before deployment, not after a complaint or regulatory inquiry.

Where is the data hosted and processed, and does that matter for our regulatory obligations? Data residency — which country or region data is physically stored and processed in — has real regulatory consequences in many industries and jurisdictions. A vendor's confident answer that "we handle this" is not the same as your organization having verified what "this" specifically means.

What happens to our data after we stop using this vendor? A frequently overlooked question: whether the vendor retains, continues training on, or deletes your organization's data after a contract ends, and whether that commitment is written into the contract rather than only described informally.

Which regimes will your compliance team actually name? You do not need to master any of these, but you should recognize the vocabulary when it appears in a risk register or a board paper, and you should know that each one has an owner who is not you. In the UK and Europe, GDPR and UK GDPR govern whether you had the right to use data the way the first question asks about — that question is not a matter of good practice, it is that regime in plain language. The EU AI Act layers a risk-tiered set of obligations on top, and its heaviest requirements land on exactly the consequential, individual-level systems the second question is designed to surface: hiring, credit, insurance pricing, benefits eligibility. In the United States, the equivalent pressure comes from sector regulators and a growing patchwork of state privacy laws rather than one central statute, and the NIST AI Risk Management Framework is the standard most commonly cited for structuring the assessment itself. None of this is a checklist you personally complete. Knowing the names is what lets you tell the difference between a team that has genuinely assessed a deployment and one that is describing a vendor's marketing claim back to you.

Critical

"The vendor said it was compliant" is not sufficient due diligence for any AI tool that touches hiring, performance, compensation, credit, or another consequential decision about an individual. Your legal and compliance teams need to be in the conversation before deployment, not after a regulator or a customer raises the question first.

Knowledge check

An executive is evaluating an AI tool that will screen job applications. The vendor states in a sales call that the tool is 'fully compliant with data protection regulations.' What is the correct next step according to this lesson?

Select one answer.

A Data Residency Gap Discovered After Contract Signature — Insurance Company

Chief Operating Officer, mid-size insurance company

Context

A COO approved an AI-powered claims-processing vendor tool after the vendor's sales team confirmed the platform 'meets all relevant compliance requirements' during the pitch. The contract was signed without a specific written data-residency clause.

Action

During onboarding, the company's legal team asked the vendor directly where claims data — including sensitive personal and financial information — would be physically hosted and processed. The vendor's honest answer revealed that data would be processed through a data center outside the jurisdictional boundary the company's own regulatory obligations required for that category of data, a detail the sales conversation had never specified.

Outcome

The company paused rollout and renegotiated the contract to require in-jurisdiction data processing before continuing, a term the vendor was able to accommodate but had not offered proactively. The COO's post-incident review concluded that the gap should have been caught before signature, not during onboarding, and the company adopted a standing requirement that data residency be confirmed in writing as a condition of any AI vendor contract touching customer data, not left to a verbal assurance during the sales process.

Quick check

Why does this lesson treat 'does this system make or meaningfully influence a decision about a specific individual' as one of the most important baseline questions a leader can ask?

Select one answer.

Note

This lesson gives you the baseline questions every leader should ask. It is not a substitute for dedicated compliance expertise. If your organization is building out the operational side of AI governance — formal risk classification, regulatory conformity work, audit documentation — that is the specialized discipline covered in a dedicated compliance-focused course, not this one.

Exercise

~12 min

Your Task

Take an AI tool your organization currently uses or is evaluating. Answer the four baseline questions from this lesson in writing: (1) what data does it use and do we have the right to use it this way, (2) does it make or influence a decision about a specific individual, (3) where is data hosted and does that matter for our obligations, (4) what happens to our data if we stop using this vendor. Flag any question you cannot currently answer as a gap to close before further reliance on the tool.

Success looks like

  • Each of the four questions has either a confirmed answer or an honestly flagged gap — a blank is an acceptable and informative response
  • Any tool touching hiring, credit, or another individual-level consequential decision is flagged for legal or compliance review if that review has not already happened

Watch out for

  • Treating a vendor's verbal or marketing assurance of compliance as equivalent to your own team's independent review
  • Assuming data residency and post-contract data handling are inconsequential details rather than specific contractual terms worth confirming in writing
Key takeaways
  • Four baseline questions — data rights, individual-level decision impact, data residency, and post-contract data handling — catch the most common and most consequential AI data governance gaps.
  • "The vendor said it was compliant" is never sufficient due diligence on its own for a tool touching a consequential decision about an individual.
  • A yes answer to "does this system make or influence a decision about a specific individual" is the trigger for legal and compliance review before deployment, not after a complaint or regulatory inquiry.
  • Data residency and post-contract data handling should be confirmed in writing as contract terms, not left to an informal assurance during a sales conversation.
  • This lesson gives you the questions to ask as a leader — the deeper, specialized compliance work of formal risk classification and regulatory conformity is a distinct discipline covered by a dedicated compliance-focused course.