VeritomeHelp Centre
/
Browse documentation
Using Veritome

Data governance: Art. 10 dataset practices per system

The Data domain of the Obligations register: Art. 10 training, validation and testing data practices for every high-risk system, the deployer's Art. 26(4) input-data duty, and the GDPR rows generated beside them.

Updated Veritome documentation

Obligations, filtered to the Data domain, is the portfolio view of Article 10 — the dataset practices behind every high-risk system: relevant design choices, provenance and collection, preparation, assumptions, availability and suitability, examination for possible biases, and the identification of gaps. It is where the GDPR rows the engine generates for a system sit too.

What the view shows

Every Art. 10 obligation on every applicable system, with its status, owner and due date. Systems where the engine determined Art. 10 does not apply (by role and tier) simply have no rows — the engine decides applicability, the register reports it.

Open a row and the drawer holds the work:

  • Dataset inventory — what data trains, validates and tests the system, and where it came from.
  • Quality criteria — the checks Art. 10(2) lists: design choices, collection processes and origin, preparation, assumptions, availability and suitability, examination for biases, gaps and how they are addressed.
  • Residency and lineage — where the data lives and how it flows.

Fields auto-save as you type, and each checklist item takes evidence directly — attach the data-quality report or lineage export right where it is claimed. The data-governance record is one of the obligations with a dedicated smart-form editor, linked from the drawer.

Deployers take note

Art. 10 is written for providers, but a deployer feeding a high-risk system its own input data has Art. 26(4): to the extent you control the input data, ensure it is relevant and sufficiently representative for the intended purpose. The engine surfaces that as its own obligation on the deployer's record, in this same domain.

The GDPR rows

The five GDPR questions answered at classification generate obligations here beside the EU AI Act ones — lawful basis (GDPR Art. 6), special categories (Art. 9), the information duties (Art. 12–14), automated decision-making (Art. 22), the processor contract (Art. 28), the DPIA (Art. 35) and transfers (Art. 44–49) — each gated only by your answers. With the Data domain selected the register also shows the record of processing activities (GDPR Art. 30) and the data-subject request panels, so the organisation-level GDPR records live next to the per-system duties. See GDPR for AI systems.

  • Work an obligation — the general checklist, evidence and owner mechanics used here.
  • The Evidence hub — one uploaded data-governance policy can satisfy obligations on many systems.