The classic trap
Recital 70 opens a narrow door: processing sensitive data (ethnic origin, health, sexual orientation, political views) to detect and correct bias in a high-risk AI system. Providers rush through this opening, forgetting it is a strictly necessary exception, subject to Article 9(2)(g) GDPR and Article 10 of the AI Act. The CNPD will sanction any processing that exceeds the anti-discrimination purpose or fails to demonstrate the absence of alternatives (synthetic data, proxies, public datasets).
The 6 safeguards your compliance file must prove
- Written demonstration that bias detection cannot be achieved with anonymised data, synthetic data or statistical proxies.
- Minimisation: only sensitive categories strictly useful to the fairness test (e.g. gender + age, not religion if irrelevant).
- Technical segregation: sensitive data is isolated in a dedicated environment, never reinjected into the production model training.
- Immediate deletion after the bias testing or audit phase, with timestamped erasure proof.
- DPIA mandatory (Article 35 GDPR) integrated into the Article 11 AI Act technical documentation.
- Reinforced information to data subjects, unless Article 14(5) GDPR applies in a documented manner.
The 'strictly necessary' test: the key argument before the CNPD
Recital 70 uses the word exceptional twice. In practice, the CNPD will expect you to prove that you first tested less intrusive methods: fairness through unawareness, geographic proxies, synthetic data generated by GAN, public reference datasets (FairFace, UCI Adult). Without this documented reasoning, you lose the Article 9(2)(g) exception and fall back into the principle of prohibition.
How Luxgap automates this risk
Our Luxgap Bias Forensics Vault turns bias detection into a cryptographic safe: an isolated, ephemeral and enforceable environment where your sensitive data enters for a fairness audit and leaves as evidence, never as a leak. The tool orchestrates the connection to your MLOps pipelines (Azure ML, AWS SageMaker, Databricks, Vertex AI) to run fairness tests (demographic parity, equalized odds, disparate impact) inside an encrypted enclave, then cryptographically destroys the sensitive data within 72 hours with a timestamped erasure certificate.
- Automatically detects, via a scan of your training datasets, the presence of sensitive variables or proxies (postal code correlated with origin, first name correlated with gender) and alerts the DPO.
- Generates the strictly necessary written justification required by Recital 70, by first testing 4 alternative methods (synthetic data, fairness through unawareness, statistical proxies, public datasets) and documenting why they fail.
- Runs bias tests (Aequitas, Fairlearn, IBM AIF360) inside an Azure Confidential Computing or AWS Nitro Enclaves environment, with no exposure to the rest of the IT system.
- Produces the Article 35 GDPR DPIA ready to file with the CNPD, integrated into the Article 11 AI Act technical documentation.
- Delivers a timestamped cryptographic erasure certificate, enforceable during a CNPD or EU AI Office inspection.
- Instantly alerts via Teams or Slack if a data scientist attempts to reinject sensitive data into the production pipeline.
Available as a complement to a Luxgap DPO or CISO mandate or as a dedicated SaaS module depending on your AI scope. Request a tailored quote and our teams will prepare a demonstration on one of your high-risk models, with a free 48-hour blank audit to measure your bias exposure before any commitment.