Secure and Ethical Data Lifecycle Management in AI Systems

Authors

  • Clara Jensen Postdoctoral Researcher, Department of Artificial Intelligence, Central European Tech University, Vienna, Austria Author

DOI:

https://doi.org/10.5281/

Keywords:

data lifecycle management, AI data security, secure disposal, GDPR, ISO 27001, EU AI Act, responsible AI, data governance

Abstract

Data lifecycle management in AI systems -- encompassing the governance of data from initial acquisition through training, inference, monitoring, and eventual secure disposal -- presents distinct security and ethical challenges at each lifecycle stage. While individual lifecycle stages have received attention in data governance, privacy, and responsible AI research, a comprehensive framework addressing the security and ethical requirements of the full AI data lifecycle remains absent. This paper proposes the Secure and Ethical Data Lifecycle (SEDL) framework, integrating information security management (based on ISO 27001), data protection (GDPR 2016), and responsible AI requirements (EU AI Act 2024) into a unified lifecycle governance model. The SEDL framework specifies thirty governance controls organised across seven lifecycle stages: acquisition, storage and access control, training, inference, monitoring, update and adaptation, and secure disposal. Each control is specified with a formal requirement, threat model, security classification, and regulatory compliance mapping. The framework is evaluated through a security and ethics assessment of twenty AI systems across four industry sectors and through a gap analysis benchmarking current lifecycle management practice against SEDL requirements. Assessment results reveal a mean of 9.3 SEDL control gaps per system (SD = 2.4), with secure disposal (mean controls satisfied = 1.9/5) and monitoring security (mean = 2.4/5) as the weakest lifecycle stages. SEDL-aligned systems demonstrate a 53.7% lower rate of data-related security incidents over 12 months compared to non-aligned systems (IRR = 0.46, p < 0.001). The study contributes the SEDL specification, a Data Lifecycle Security and Ethics (DLSE) maturity model, and an empirical benchmark of AI data lifecycle governance gaps.

Author Biography

  • Clara Jensen, Postdoctoral Researcher, Department of Artificial Intelligence, Central European Tech University, Vienna, Austria

    Postdoctoral Researcher, Department of Artificial Intelligence, Central European Tech University, Vienna, Austria

Downloads

Published

2025-12-20

How to Cite

Secure and Ethical Data Lifecycle Management in AI Systems. (2025). AI Governance and Society Journal P-ISSN 3117-6097 and E-ISSN 3117-6100, 2(4), 1-8. https://doi.org/10.5281/