AI Policy

1. Introduction and purpose

At the Public Affairs Academy, we train and advise organisations on public affairs and communications. To improve our services and make them more efficient, we make use of artificial intelligence (AI).

This document explains how we use AI, what data we use and what precautions we take to comply with applicable laws and regulations. Through this AI Policy, we aim to inform our clients and other stakeholders transparently about our approach, in accordance with the recommendations of the Netherlands Chamber of Commerce (KVK) and the guidelines of the Dutch Data Protection Authority (AP).

2. Scope

This policy applies to all employees, advisers and partners of the Public Affairs Academy who are involved in the use of AI applications as part of our advisory services. It covers:

  • All IT systems and software that use AI, including internally developed and external AI solutions.
  • All data collected, processed, stored and/or shared by the Public Affairs Academy in connection with AI applications.
  • All processes and procedures for the quality and risk management of AI systems.

3. Vision and principles

3.1 Safety and due care

Our primary focus is on safety and due care. Much of the information we work with may be politically or socially sensitive. We apply strict protocols to safeguard the confidentiality of data, particularly because the reputations and interests of clients and third parties may be at stake.

3.2 Transparency

We aim to inform our clients clearly about when and how we use AI. In accordance with the recommendations of the KVK, we take a transparent approach:

  • We specify which AI applications we use.
  • We explain the purposes for which these applications are used.
  • We describe how data is collected, processed and retained.

3.3 Compliance with laws and regulations

We comply with all relevant laws and regulations, such as the General Data Protection Regulation (GDPR) and the forthcoming EU AI Act (AI Regulation). In doing so, we follow the guidelines of the Dutch Data Protection Authority (AP).

  • We apply ‘privacy by design’ and ‘privacy by default’. This means that privacy is taken into account from the design stage of a product or service and that default settings are made as privacy-friendly as possible.
  • We assess AI applications against the principles of proportionality and data minimisation. This means that we do not collect more data than is strictly necessary.

3.4 Ethical use

AI must never be used in a way that conflicts with prevailing ethical and societal standards, or that leads to discrimination, violations of fundamental rights or undesirable influence on political processes. In doing so, we endorse the principles of fairness, reliability and accountability as enshrined in the draft AI Regulation.

4. AI applications used and their purposes

4.1 Data analysis and monitoring

We use AI to analyse large volumes of information, such as media reports, political debates and policy documents. AI helps us identify connections, trends and sentiments, enabling us to advise our clients more effectively on their communications strategies and lobbying activities. It is important to emphasise that, in this context, we use AI solely as a tool to support our advisers. Ultimately, they are responsible for carrying out a human review of accuracy and quality.

4.2 Automation of routine tasks

We also use AI to automate repetitive tasks, such as organising and categorising documents or preparing standard reports. This enables our advisers to focus on delivering high-quality, personalised advice.

4.3 LLMs and content creation

To support our advisory processes and make them more efficient, we use various AI tools. Below, we explain how and for what purposes we use these applications, as well as the precautions we take.

Purposes and use
  • Summarisation and text generation: AI is used to summarise or draft texts, reports or advice. This enables our advisers to understand the content of a document more quickly and to produce an initial draft more efficiently, after which they manually review, refine and amend the content.
  • Idea development and brainstorming: We use AI tools as a creative sparring partner, for example to explore alternative perspectives or potential strategies within a communications dossier or lobbying process.
  • Language review and translation: When preparing public affairs documentation in multiple languages, AI can assist with rapid translation suggestions or textual corrections.
  • Creating images: We also use AI tools to create ideas for images, visualisations and icons, as well as the images, visualisations and icons themselves.
Types of data and limitations
  • Input: The information we use in connection with AI consists primarily of fully or partly public data or previously anonymised client information. Where necessary, sensitive or confidential information is restructured or removed before we use these tools.
  • Principle: We do not submit directly identifiable personal data, trade secrets or other strictly confidential information to AI providers unless an explicit data processing agreement with sufficient safeguards can be established.
Privacy and security
  • Processing outside our systems: Input provided to AI tools is processed on external servers. We are aware that this may involve potential risks concerning the privacy of our clients’ data. We therefore do not share confidential data and take additional technical measures, such as pseudonymisation, before entering data.
  • Assurance for clients: For each project, we assess whether it is appropriate to process all or part of the data using the relevant AI tool, taking into account the sensitivity of the information.
  • Continuity and oversight: We monitor updates to and the terms and conditions of the AI tools we use, including any changes to their privacy and security practices. If these change, we review our internal procedures to ensure that we continue to comply with applicable laws and regulations.
Quality and risk assurance
  • Human review: The output of AI tools is always reviewed by an adviser for accuracy, relevance and tone of voice. LLMs may produce factually incorrect or incomplete answers (‘hallucinations’); we therefore carefully verify the results before incorporating them into our advice or communications products.
  • Awareness of bias: Because AI models may be susceptible to inherent biases, we take an additional step to check that the content is not unintentionally discriminatory or otherwise undesirable.
  • DPIA and risk analysis: When using external AI services with a potentially higher risk profile, such as those involving the processing of sensitive data, we may carry out a Data Protection Impact Assessment (DPIA) where necessary to identify potential risks and mitigating measures.

By using AI tools, we continuously improve our advisory work while maintaining the confidentiality of client information and complying with privacy legislation. Should you have any specific questions about this, please feel free to contact our office.

5. Data processing

5.1 Data collection

  • Sources: We collect data from public sources, such as news websites, social media, parliamentary databases and policy documents. We may also process data provided by clients, provided that the appropriate explicit consent has been obtained.
  • Lawfulness: We ensure that we have a valid legal basis for the processing, such as consent, legitimate interests or the performance of a contract in which the potential use of AI has been agreed.

5.2 Data minimisation

We process only the data necessary to achieve our purpose, including advanced data analyses or risk assessments. Irrelevant and unnecessary data is not stored or is deleted as soon as possible.

5.3 Retention periods

We apply clear retention periods in accordance with the GDPR. Data is not retained for longer than necessary for the purpose for which it was collected.

5.4 Security

  • Technical measures: We use encryption, firewalls and secure storage to protect data against unauthorised access.
  • Organisational measures: Employees are trained in the secure use of data and sign a confidentiality agreement. Access to systems is restricted to authorised individuals.

6. Roles and responsibilities

6.1 Management

The management of Public Affairs Academie has ultimate responsibility for the AI policy and monitors compliance with all laws and regulations relevant to the use of AI.

6.2 Privacy officer

Where applicable, our privacy officer is responsible for overseeing the correct processing of personal data, carrying out DPIAs and supporting risk assessments relating to AI systems.

6.3 IT management

The IT administrator is responsible for the technical infrastructure and the implementation of security measures.

6.4 Advisers

Our advisers work with AI-generated results and report anomalies or errors in those results. They remain responsible at all times for the interpretation and application of the data in their advice to clients. Written work will never be sent to a client without a human review.

7. Risk management and quality assurance

7.1 Risk classification

Before implementing a new AI application, we carry out a risk assessment. This assessment focuses on:

  • The sensitivity of the data and its political or societal significance.
  • The potential impact on the rights and freedoms of individuals concerned.
  • The risk of bias or discrimination in the model.

7.2 Evaluation and testing

We test AI systems before they are used and periodically during their use. We assess reliability, accuracy and ethical considerations. Where necessary, we make adjustments to improve the quality of the AI models and limit potential adverse effects. We may also decide not to use an AI system.

7.3 Monitoring and audits

We continuously monitor the operation of AI models. Internal or external auditors may also periodically assess compliance with the AI policy.

8. Transparency towards clients and third parties

We inform our clients in the following ways:

  • Proposals and contracts: Our proposals and contracts may state that AI may be used during an assignment.
  • Requests and objections: Clients and other parties concerned may submit a request at any time for access to, correction of or deletion of their personal data, or object to the processing of data in AI systems.

9. Compliance and the future AI Regulation

9.1 Current legislation (GDPR)

We ensure compliance with the General Data Protection Regulation (GDPR) by, among other things:

  • Carrying out DPIAs for higher-risk AI projects.
  • Entering into data processing agreements with external parties that process personal data on behalf of the Public Affairs Academy.
  • Applying the principles of ‘data protection by design and by default’.

9.2 Forthcoming EU AI Act (AI Regulation)

The European Union is currently developing an AI Regulation that adopts a risk-based approach to safeguarding safety and fundamental rights in relation to AI applications. We closely monitor developments relating to this regulation and take the following steps:

  • Risk classification: We will classify existing and new AI systems within the risk categories of the AI Regulation.
  • Documentation: We keep accurate records of how our models work, what data has been used and what safeguards have been implemented.
  • Reporting obligations: Where applicable, we will comply with statutory notification and reporting obligations.

10. Incident management and reporting procedure

10.1 Incidents involving AI systems

In the event of an incident, such as a data breach or the unintended disclosure of sensitive information, the following Public Affairs Academy protocol will apply:

  • Immediate notification of the responsible manager and the privacy officer.
  • Rapid assessment of the impact on the parties concerned.
  • Notification of the Dutch Data Protection Authority and the parties concerned where required by law.
  • Evaluation and implementation of measures to prevent recurrence.

11. Exit strategy

As recommended by the KVK in relation to AI policies, it is important to have an exit strategy for terminating AI projects or contracts:

  • Return and deletion of data: When an AI application is discontinued, we ensure that all relevant data is securely deleted or, where agreed, returned to the client.
  • Accountability: We record in writing that the AI application is no longer in use and is no longer accessible to unauthorised individuals.

12. Evaluation and updates

This AI Policy document is evaluated at least once a year and amended where necessary to reflect new legal developments, technological innovations and organisational changes.

Questions or comments

For questions or comments about this AI policy, please contact us at info@publicaffairsacademie.nl.