IEEE - PDP - Personal Data Privacy Working Group
The purpose of this standard is to have one overall methodological approach that specifies practices to manage privacy issues within the systems/software engineering life cycle processes.
The purpose of this standard is to have one overall methodological approach that specifies practices to manage privacy issues within the systems/software engineering life cycle processes.
I focus on the development of a new standard Work Model type (Technical Specification) that facilitates the consolidation, integration, and implementation of requirements, helping organisations comply with AI laws, regulations, and standards more effectively. The objective is to guide and support organisations on how to meet the multiple requirements imposed by laws, regulations, and standards on AI-based systems. The initiative will not create new requirements but will provide assistance and guidance to organisations on how to consolidate, integrate, implement and audit different sources of requirements
My fellowship addresses three critical gaps in the European AI standardization landscape: The first gap concerns the harmonisation of Documentation Development, as there is an urgent need for technical documentation (Annex ZA, HAS checklists) to connect developing standards with AI Act requirements following the M/593 request. Without this work, standards risk delayed OJEU citation, creating regulatory uncertainty. I've worked on developing preliminary harmonization documents for JT021008 (Trustworthiness), JT021039 (QMS), and JT021024 (Risk Management). The second gap is related to cross-Standard Technical Coherence. As multiple AI standards are developed simultaneously, it creates potential inconsistencies in terminology, requirements, and implementation approaches. I've created mapping documents highlighting interconnections between standards, particularly focusing on how QMS requirements interface with other M/593 standards, to ensure a coherent framework. The third gap focuses on the alignment with EU AI Act Articles, as technical specifications in draft standards must precisely align with AI Act articles to support regulatory compliance. I have contributed targeted technical refinements to clauses 6.4 (transparency) and 6.5 (human oversight) in the Trustworthiness Framework to strengthen alignment with Articles 13 and 14 of the AI Act.
I addressed priorities and gaps on three specific AI areas, including:
The main priorities of my fellowship are to support the development of two European standards for AI systems, Risk Management and Cybersecurity, which will enable organisations to manage risks and address cybersecurity concerns in alignment with the AI Act.
The s-X-AIPI project endeavour is to research, develop, test, and validate a bespoke suite of trustworthy self-X AI technologies tailored for process industries. This initiative aims to bridge the gap between AI capabilities and traditional automation processes, ensuring that AI tools are both accessible and effective across various industrial applications.
With the support of this fellowship, I tackle specific bias detection and mitigation requirements with accompanying illustrative example within CEN/CLC/JTC21 WG3 "Concepts, measures and requirements for managing bias in AI systems" standard that are aligned/harmonised with relevant EU AI Act legislation.
With this fellowship, I significantly contribute to the ICT Standards landscape by addressing the lack of standardised guidelines for processing Personal Identifiable Information (PII) in blockchain and Distributed Ledger Technology (DLT) systems. Approving the New Work Item Proposal (NWIP) for “Guidelines on processing PII using blockchain and DLT” establishes a crucial foundation for privacy-preserving, GDPR-compliant blockchain applications.
By leading the creation of CEN/CENELEC JTC19 WG3, I am ensuring the development of a harmonised European approach to blockchain privacy, reducing fragmentation and fostering interoperability. These efforts align blockchain implementations with European regulations, consumer protection laws, and data governance principles.
The objective is to present LoRa mesh networks to the IRTF GAIA WG of the IETF. GAIA seeks technologies to connect the unconnected world, and with IRTF GAIA as a vehicle, we seek to start the standardisation activity of this new technology.