Kostenloses Live-Webinar: VergabeHero in Aktion erleben.

20260615_Pre-Assessment_Questionaire_BPO_Data_Protection_1.2.docx

Lieferung von zwei Ultraschallsystemen für die kardiologische und nephrologische Diagnostik

Extrahierter Dokumenttext · Stand: 07.10.2026, 10:33 (Europe/Berlin)

Herkunft: www.subreport-elvis.de

Tabellen, Layout und Zeichen können bei der Extraktion abweichen. Maßgeblich ist die Originaldatei.

Originaldatei öffnen
Information
Title document:AI Governance – Pre-assessment Data Protection
Version:1.2
Status:Live June 15, 2026
Document owner:Data Protection – Miriam Koch
Target group and purposeThis document is intended for Business Process Owners (BPO), Procurement Teams, AI System Developers as its primary users. Information and answers to the following questions are needed to start the Data Protection Assessment. If further information and documentation is needed, the responsible assessment giver contacts the BPO.
Initial Step – Determine your Scope
AI Tool Name & AI-REP No.:
BPO Name:
Date:
General information (please describe and answer below)
1. Which AI is used (short description of the AI model(s) and systems used (e.g. OpenAI, Google Gemini))? 2. Who is the provider and/or provider of the AI, and what are the data protection responsibilities (controller, processor)? 3. Should a cloud solution be used alongside the AI? If so, which one? 4. Is or was the AI trained with Fresenius personal data? 5. Is or was the AI trained with personal data of other customers or data subjects? 6. Will the AI run in Fresenius environment / on Fresenius servers? If so, please describe the IT environment in detail, taking into account the relevant Fresenius Group company. 7. Which data is processed by the AI? In terms of personal data, please list the different data categories. 8. Please describe the duration of data processing in the AI and in the (overall) use case. 9. In the event of processing sensitive data (Article 9 GDPR e.g. health data, information on religious beliefs and ethnic origin): Describe the specific security measures taken. 10. Is the transfer of personal data to countries outside Germany planned? If so, to which countries? 11. Is user data processed by the AI (prompts, logfiles, etc.) or is it only running in the background? 12. Is it technically safeguarded that no remnants of the processed information are incorporated into or retrievable from the AI tool? Please briefly describe such safeguards. 13. Is it possible to delete personal data processed within the AI? 14. Is it possible to restrict and correct the processing of personal data for specific data subjects within the AI? 15. Which agreement will apply for purchasing this AI? Will there be a new / dedicated agreement for the AI? 16. Are there direct interfaces to other systems/applications? If yes, please name them. 17. In which environment should the AI service be used (development/test/productive environment)? 18. Please describe the use-case, taking into account the data involved and the purpose of processing as well as the outcome. 19. Please provide a description of the legal basis for data processing (including documentation of the balancing of interests, where necessary). 20. How should the processing principles set out in Article 5 of the GDPR (in particular storage limitation and data minimisation) be complied with? 21. Please describe the typical risks associated with the planned data processing using AI. What measures have already been planned to address these risks? 22. Is the AI CE-marked (as a medical product under the MDR)? 23. Is the AI already listed with a Procurement department? 24. Only applicable if used within the business segment Helios: Has a departmental decision been made?
Alle Unterlagen dieser Ausschreibung