← All controls
DGC
Data Governance
Operational controls for data governance — with maturity levels, evidence requirements, and implementation guidance.
3 controls matching filters
DGC-002
Agentmedium
PII Handling in AI Systems
Establish controls governing how personally identifiable information is handled when it flows through AI inputs, outputs, training pipelines, and logs.
DGC-003
medium
Data Minimization for AI Systems
Ensure AI systems only process the data strictly necessary for their defined purpose, avoiding unnecessary collection, retention, or use of personal information.
DGC-004
Agentmedium
AI Output Retention and Deletion
Define and enforce retention schedules and deletion procedures for AI-generated content, decisions, and the personal data contained within them.
