top of page

Name

Contribuinte

Startup Stage

Climbing without investment

Company

Tax Data

Business Position

B2D - Business to Business to Developer

Risk Impact Assessment

56%

Resume of assessment

Stage: 3. Legal compliance of data

Has the company observed the legal guidelines for the processing of personal data?

Answer: Yes

Stage: 3. Legal compliance of data

Will the smart autonomous system use personal data?

Answer: No

Stage: 3. Legal compliance of data

The intelligent autonomous system will use sensitive personal data (personal data on racial or ethnic origin, religious conviction, political opinion, membership of a trade union or organization of a religious, philosophical or political nature, data relating to health or sex life, genetic or biometric data , when linked to a natural person)?

Answer: No

Stage: 3. Legal compliance of data

Has the intelligent autonomous system performed age verification of data subjects prior to processing?

Answer: No

Stage: 3. Legal compliance of data

Does the company have Terms of Use and Privacy Policy for the collection, storage and use of customer personal data on a digital platform?

Answer: No

Stage: 3. Legal compliance of data

Has the company established procedures to ensure that the legal basis and its purpose are identified before starting any further processing of personal data or special category data?

Answer: Yes

Stage: 3. Legal compliance of data

Has the company implemented the right to withdraw consent, the right to object and the right to delete personal data from the smart autonomous system?

Answer: No

Stage: 3. Legal compliance of data

Has the company established a Data Protection Officer (DPO), with designated responsibility, having participated in the development of the intelligent autonomous system?

Answer: No

Stage: 3. Legal compliance of data

Will the intelligent autonomous system be used to aid decision making?

Answer: No

Stage: 3. Legal compliance of data

Will the intelligent autonomous system replace human decisions that require judgment?

Answer: No

Stage: 3. Legal compliance of data

Will the intelligent autonomous system be used by a different part of the organization than the one that developed it?

Answer: No

Stage: 4. Trend (discrimination) of data

Are there documented processes for testing the dataset against bias and other unexpected results?

Answer: No

Stage: 4. Trend (discrimination) of data

Has a gender-based analysis been performed on who provides the data?

Answer: No

Stage: 4. Trend (discrimination) of data

Has an analysis been performed based on the race of the data provider?

Answer: Yes

Stage: 4. Trend (discrimination) of data

Has an analysis been performed based on the ethnicity of the data provider?

Answer: No

Stage: 5. About the risks of intelligent autonomous system

Did the company, before developing the intelligent autonomous system, carry out a Privacy Impact Assessment on the use of personal data against the risks of non-compliance with privacy and data protection?

Answer: No

Stage: 5. About the risks of intelligent autonomous system

Has a summary of what intelligent autonomous system intends to do in the Privacy Impact Assessment, what processing will it involve and what are the expected results?

Answer: No

Stage: 5. About the risks of intelligent autonomous system

Has the company carried out a detailed analysis of the decision-making impact on data subjects, the possible legal effects and the mitigations and protections against each risk?

Answer: Yes

Stage: 5. About the risks of intelligent autonomous system

Are the resulting impacts of the decision reversible?

Answer: No

Stage: 6. Data security and confidentiality

Has the intelligent autonomous system considered security and privacy from the design stage?

Answer: Yes

Stage: 6. Data security and confidentiality

Has the intelligent autonomous system considered security and privacy from the design stage?

Answer: No

Stage: 6. Data security and confidentiality

Has the company put in place measures to achieve privacy by design and standard, such as encryption, pseudonymization, and anonymization?

Answer: Yes

Stage: 6. Data security and confidentiality

Has the company put in place measures to achieve privacy by design and standard, such as encryption, pseudonymization, and anonymization?

Answer: No

Stage: 6. Data security and confidentiality

Has the company considered in the process of completing the Privacy Impact Assessment to include consultation with internal experts in each area?

Answer: Yes

Stage: 6. Data security and confidentiality

Has the company considered in the process of completing the Privacy Impact Assessment to include consultation with internal experts in each area?

Answer: Yes

Stage: 6. Data security and confidentiality

Did the company consider, in the process of completing the Privacy Impact Assessment, the consultation of external experts on the risks of acting?

Answer: No

Stage: 6. Data security and confidentiality

Did the company consider, in the process of completing the Privacy Impact Assessment, the consultation of external experts on the risks of acting?

Answer: No

Stage: 6. Data security and confidentiality

Does the company release the Privacy Impact Assessment report to interested parties?

Answer: No

Stage: 6. Data security and confidentiality

Does the company require processing not to take place until mitigation controls have been implemented in accordance with the Privacy Impact Assessment report?

Answer: Yes

Stage: 6. Data security and confidentiality

Has the company considered the privacy implications of collecting personal data generated or processed over the lifecycle of the intelligent autonomous system?

Answer: Yes

Stage: 6. Data security and confidentiality

Has the company established a documented process/policy with appropriate document controls, with deadlines set for periodic reviews to ensure they remain current?

Answer: No

Stage: 6. Data security and confidentiality

Has the company established a documented process/policy with appropriate document controls, with deadlines set for periodic reviews to ensure they remain current?

Answer: No

Stage: 6. Data security and confidentiality

Is the data used by the intelligent autonomous system inside an enclosed space?

Answer: No

Stage: 6. Data security and confidentiality

Was the intelligent autonomous system designed to consider the impact of the AI system on the right to privacy, data protection, the right to physical, mental and/or moral integrity?

Answer: No

Stage: 6. Data security and confidentiality

the intelligent autonomous system been trained to handle personal data (including sensitive personal data)?

Answer: Yes

Stage: 6. Data security and confidentiality

Has the company created a Committee or equivalent, responsible for providing overall oversight of the intelligent autonomous system, its use and the associated data risks within the organization?

Answer: No

Stage: 6. Data security and confidentiality

Has the company created a Committee or equivalent, responsible for providing overall oversight of the intelligent autonomous system, its use and the associated data risks within the organization?

Answer: No

Stage: 6. Data security and confidentiality

Has the company put in place supervisory mechanisms for data processing, such as limiting access to qualified personnel, mechanisms for recording access to data to make changes?

Answer: No

Stage: 6. Data security and confidentiality

If personal data is shared by the intelligent autonomous system with third parties, are there appropriate safeguards?

Answer: No

Stage: 7. Governance of the intelligent autonomous system (or data)

Has the company implemented an overall privacy governance and management strategy/structure that supports compliant use of the smart autonomous system?

Answer: No

Stage: 7. Governance of the intelligent autonomous system (or data)

Has the company developed a framework that includes appropriate technical and organizational measures designed to effectively implement data protection principles?

Answer: Yes

Stage: 7. Governance of the intelligent autonomous system (or data)

Has the company developed a framework that includes appropriate technical and organizational measures designed to effectively implement data protection principles?

Answer: Yes

Stage: 7. Governance of the intelligent autonomous system (or data)

Has the company developed documentation that provides evidence that senior management is responsible for properly understanding and addressing the risks associated with the intelligent autonomous system?

Answer: Yes

Stage: 7. Governance of the intelligent autonomous system (or data)

Has the company established technical, operational roles and assigned responsibilities to ensure effective management and data security in the intelligent autonomous system?

Answer: No

Stage: 7. Governance of the intelligent autonomous system (or data)

Has the company established assurances that job descriptions assign responsibilities to ensure the smart autonomous system's compliance with data protection legislation and industry regulations?

Answer: No

bottom of page