TwinEthos homeRequest access

Control

People whose data an AI feature processes are not told about that processing in plain language, or not told how to object

Where an AI feature processes personal data, the people concerned must receive clear, specific information about that processing (that an AI system processes their data, for what purposes, that it is automated, and the risks), and, where the law grants it, how to exercise the right to object.

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

Family: People are not told they are interacting with, or being processed by, an AI system · control id cond.ai-processing-information-missing-or-no-objection

Reach

2items this one guard addresses
2jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
0standards and frameworks on the same control

Law in force in EC, IT.

Trust and provenance

How far the rules this guard addresses have been checked. Each rule links to its provision, with its citation, official text and its own panel.

This control
Audit-grade: meets all 3 checks of the TwinEthos audit standard that apply to it.
Lanes
Binding law — in force 2
Verification
Sources last verified 3 Oct 2026; each provision states how.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
None of the 2 rules has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 2.
Audit standard
2 of 2 rules audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
3 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.

The guard to add

Describe the AI processing in the notice at collection in plain language, and wire an objection route that stops it for the person.

A section of the privacy notice, and a short notice at the AI feature itself, that says an AI system processes the person's data, for which purposes, that the processing is automated, and what the main risks are, in plain language for the people who use the feature (children included where they can use it). Next to it, an objection route (a setting, form or endpoint) that records the objection and that the AI pipeline checks before processing that person's data, so objecting has an effect rather than only being stated.

Where it goes: 1 application source code, 2 data models, 14 user-facing text.

What reviewers look for: notice text that names the AI processing, its purposes, its automated nature and risks (intelligenza artificiale, inteligencia artificial, artificial intelligence near the purposes), the right to object and how; an objection flag or endpoint that the AI call path checks.

Example (Privacy notice (informativa)), before:

## Informativa privacy
Trattiamo i tuoi dati per fornire il servizio e migliorarlo.

After:

## Informativa privacy
Trattiamo i tuoi dati per fornire il servizio e migliorarlo.

### Uso dell'intelligenza artificiale
Le domande che scrivi all'assistente sono elaborate da un sistema di intelligenza artificiale per
risponderti e per classificare la richiesta. Il trattamento e' automatizzato; i rischi principali sono
risposte inesatte e l'invio del testo al nostro fornitore del modello. Puoi opporti in ogni momento da
Impostazioni > Privacy > Assistente IA: da quel momento i tuoi dati non sono piu' inviati al modello.

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Binding law — in force (2)

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

  • Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Tell people when they are interacting with AI — everywhere, not only where required

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.