Privacy & Data Protection
AI Regulatory Sandbox Personal-Data Governance
What this control does
Govern conditional further processing of personal data in an AI regulatory sandbox under Article 59.
How to implement
Before using Article 59 to further process personal data in an AI regulatory sandbox, assess all the applicable public-interest and necessity conditions with the responsible privacy and sandbox leads. Set up separate, protected processing arrangements, limit access and sharing, and monitor for risks to individuals. Define the required stop, deletion and record-retention arrangements and document the sandbox justification and results. The sandbox route does not remove other applicable data-protection duties or automatically permit special-category data processing. Coordinate any additional data conditions separately.
Suggested timing and triggers
Before qualifying further processing; continuously for safeguards; on material risks or changes; at applicable deletion and documentation triggers.
Evidence examples
Public-interest, necessity and sandbox-route assessment Data segregation, access and security design Risk-monitoring and stop/escalation records Deletion and record-retention arrangements Required technical documentation and published-summary evidence
How to check this control
Trace a sandbox dataset from the approved justification through access, processing and deletion. Check the actual separation and risk-monitoring arrangements, and verify the required documentation without exposing unnecessary personal data.
Related EU AI Act obligations
Article 59
Apply Article 59 Safeguards When Further Processing Personal Data in an AI Regulatory Sandbox
Article 59(1)(a)-(b)
Demonstrate Public-Interest Purpose and Necessity for Sandbox Personal Data Processing
Sub-obligation of Article 59: Apply Article 59 Safeguards When Further Processing Personal Data in an AI Regulatory Sandbox
Article 59(1)(c)
Monitor and Respond to High Risks to Data-Subject Rights During Sandbox Processing
Sub-obligation of Article 59: Apply Article 59 Safeguards When Further Processing Personal Data in an AI Regulatory Sandbox
Article 59(1)(d)-(e)
Segregate, Secure and Restrict Sharing of Sandbox Personal Data
Sub-obligation of Article 59: Apply Article 59 Safeguards When Further Processing Personal Data in an AI Regulatory Sandbox
Article 59(1)(f)
Prevent Sandbox Processing From Affecting Data Subjects and Protect Their Rights
Sub-obligation of Article 59: Apply Article 59 Safeguards When Further Processing Personal Data in an AI Regulatory Sandbox
Article 59(1)(g)-(h)
Protect, Delete and Log Personal Data Processed in the Sandbox
Sub-obligation of Article 59: Apply Article 59 Safeguards When Further Processing Personal Data in an AI Regulatory Sandbox
Article 59(1)(i)-(j)
Document Sandbox Training, Testing and Validation and Prepare the Required Project Summary
Sub-obligation of Article 59: Apply Article 59 Safeguards When Further Processing Personal Data in an AI Regulatory Sandbox