← Back to Playbooks

Playbook 3 — Data & Bias

The minimum viable version of data governance an SMB can actually run

Data Origin — Know Where It Came From

“Garbage in, garbage out” applies whether you’re training a model or just feeding one. The fact that data is available doesn’t mean you’re allowed to use it.

GDPR Minimum Viable Compliance

Consent, when that’s the basis

Must be explicit (actively given, not assumed), informed (the person knows what and why), revocable, and not reused for a new purpose without asking again.

Data minimization

Only collect what the AI use actually needs. If you can’t explain why a field is being fed to the model, don’t feed it.

When you need a Data Protection Impact Assessment (DPIA)

Required when the use involves new technology, large-scale data processing, or a meaningful effect on people’s rights — e.g. an AI hiring tool screening every applicant, not a one-off internal experiment. If in doubt, treat it as required; a short DPIA is cheap insurance.

Bias Sanity-Check — For Hiring, Credit, Pricing, or Performance Use Cases

You don’t need a data science team to catch the obvious cases. This is a non-technical version of the subgroup testing the deck describes.

When to Bring in Outside Help

Next Steps

Document the answers to this playbook’s checklists in the AI Project Sheet (Playbook 6) — this is the record that protects you if a decision is ever questioned. If the bias check flags a real gap, pause deployment and go back to Playbook 1’s risk tier before proceeding.