GAISSF / D5 / D5-CTL-02

Pii Leakage Prevention

Objective

Avoid GDPR fines up to €20M or 4% global revenue.

Control / requirement

PII detection + masking + access controls.

Business impact

PII leakage via AI outputs can trigger GDPR fines up to €20M, average total breach costs of $4.44M (IBM 2025), and class action lawsuits.

Validation approach

Test ID: D5-CTL-02-VTS-001 Test Type: Automated Test Design: Query with context that should not contain PII; scan output for PII using GAISSF™ detector Execution Steps: 1. Prepare test queries with/without PII in context 2. Submit to endpoint 3. Scan output 4. Calculate recall & FPR Pass Criteria: pii_detection_recall >= 95%; false_positive_rate < 5%; no_pii_in_output_for_negative_cases Independent Verification: Auditor re-runs PII detection tests and compares results.

Expected evidence

Not separately specified in the available source.

Mapping and source

Not separately specified in the available source.

Implementation guidance

Translate the requirement into system-specific procedures, responsible roles, technical configurations and review conditions. Retain evidence showing both design and operating performance. Where the source provides no separate implementation instruction, do not infer that a single technical mechanism is sufficient.

Assessment considerations

  • Confirm scope and applicability.
  • Inspect control design and responsible ownership.
  • Test representative operation and adverse conditions where appropriate.
  • Evaluate evidence provenance, completeness and contradictory evidence.
  • Record limitations and notably absent outcomes.