0.1 General
This document provides guidance for organizations to address privacy risks in artificial intelligence (AI) systems and machine learning (ML) models. It extends ISO/IEC 27001 principles to AI-specific privacy concerns.
It applies to organizations developing or using AI systems that process personal data.
Example: A company using AI for customer profiling must implement privacy risk controls to avoid data breaches or unlawful processing.
0.2 Relationship with Other Standards
This standard complements ISO/IEC 27001 (ISMS) and ISO/IEC 42001 (AI Management System), focusing on privacy in AI.
Example: Use with ISO/IEC 27001 for overall cybersecurity and add AI-specific privacy measures from this standard.