Mnemonics
The AIGP has a lot of enumerated content — seven principles, six bases, four functions, four tiers, three bias types. These are for holding the lists steady so your working memory is free for the reasoning.
GDPR Art. 5 — the seven principles
Little Penguins Dance Around Seven Icy Arches
- Lawfulness, fairness, transparency
- basis + no unjustified harm + people understand
- Purpose limitation
- specified, explicit, legitimate; no incompatible reuse
- Data minimisation
- adequate, relevant, limited to what is necessary
- Accuracy
- including inferences and outputs about a person
- Storage limitation
- identifiable no longer than necessary
- Integrity and confidentiality
- appropriate security
- Accountability
- comply AND demonstrate compliance
Why it sticks: Seven arches for seven principles — the count itself is worth locking in, because "how many principles" appears as a distractor.
GDPR Art. 6 — the six lawful bases
Cool Cats Love Vanilla Pop Lollies
- Consent
- freely given, specific, informed, unambiguous, withdrawable
- Contract
- necessary for performance or pre-contractual steps
- Legal obligation
- required by EU or member-state law
- Vital interests
- life or death
- Public task
- official authority or public interest
- Legitimate interests
- the AI workhorse — needs a three-part LIA
Why it sticks: Legitimate interests sits last in the article and last in the mnemonic — and it is the one that needs documented work rather than a box tick.
GDPR Art. 9 — special categories
Three beliefs, three bodily, three identity
- Beliefs
- political opinions · religious or philosophical beliefs · trade union membership
- Bodily
- genetic · biometric (when used to uniquely identify) · health
- Identity
- racial or ethnic origin · sex life · sexual orientation
Why it sticks: A 3×3 grouping beats a nine-letter acronym. Remember biometric data is only special category when processed to uniquely identify someone.
GDPR Art. 22 — the four-step test
Solely? Significant? Exception? Safeguards!
- Solely automated?
- meaningful human involvement defeats it — rubber stamps do not
- Legal or similarly significant effect?
- credit, employment, insurance, benefits
- Which Art. 22(2) exception?
- Contract · Law · Explicit consent
- Art. 22(3) safeguards
- Intervene · Point of view · Contest
Why it sticks: Sub-mnemonic for the safeguards: "I Protest, Contest" — Intervention, Point of view, Contest.
GDPR Art. 35(3) — DPIA triggers
Profile · Sensitive · Surveil
- Profile
- systematic and extensive evaluation with legal or similarly significant effects
- Sensitive
- large-scale special-category or criminal-offence data
- Surveil
- systematic monitoring of a publicly accessible area on a large scale
GDPR Art. 35(7) — DPIA contents
Don't Neglect Risk Management
- Description
- systematic description of the processing and purposes
- Necessity
- necessity and proportionality assessment
- Risks
- risks to the rights and freedoms of individuals
- Measures
- measures to address those risks
GDPR fines — which tier?
4 for the Fundamentals, 2 for the To-dos
- 4% / €20M
- principles (5, 6, 7, 9), data subject rights (12–22), transfers (44–49)
- 2% / €10M
- process obligations — by design, DPIAs, records, security, processors, DPO
Why it sticks: Breach a principle or a right → the higher tier. Fail a process → the lower one. Always "whichever is higher" against global turnover.
GDPR transfers — order of preference
Always Seek Derogations last
- Adequacy (Art. 45)
- simplest route where a decision exists
- Safeguards (Arts. 46–47)
- SCCs, BCRs, codes, certifications — plus a transfer impact assessment
- Derogations (Art. 49)
- narrow, occasional, non-repetitive — genuinely a last resort
NIST AI RMF — the four functions
Govern is the hub; Map, Measure, Manage is the loop
- Govern
- cross-cutting culture, policy, roles, accountability
- Map
- establish context and identify risks
- Measure
- analyse, assess, benchmark, track
- Manage
- prioritise, respond, monitor
Why it sticks: The exam-relevant point is structural: Govern is not step one of four, it wraps the other three. "Find it, size it, fix it — all under Govern."
NIST — trustworthy AI characteristics
Very Safe Systems Are Explained, Private, Fair
- Valid and reliable
- the foundation the others build on
- Safe
- no endangerment of life, health, property, environment
- Secure and resilient
- withstands adversarial attack and adverse events
- Accountable and transparent
- who is answerable, and is information available
- Explainable and interpretable
- mechanism and meaning of output
- Privacy-enhanced
- anonymity, confidentiality, control
- Fair with harmful bias managed
- equality and equity, bias addressed
Why it sticks: Validity and reliability is described as the base condition — the others are meaningless without it.
NIST SP 1270 — the three bias categories
Society · Statistics · Self
- Systemic
- historical and institutional bias embedded in society and data
- Statistical / computational
- sampling, measurement and algorithmic artefacts
- Human-cognitive
- how people interpret and act on output — including automation bias
EU AI Act — the four risk tiers
Pyramids Have Lovely Masonry
- Prohibited
- social scoring, manipulation, untargeted face scraping, workplace emotion recognition…
- High-risk
- Annex III uses plus AI in regulated products
- Limited / transparency
- chatbots, deepfakes, synthetic content (Art. 50)
- Minimal
- everything else — voluntary codes
Why it sticks: Descending severity, like a pyramid narrowing at the top: very few systems are prohibited, most are minimal.
EU AI Act — penalty tiers
Ban, Break, Bluff — 7, 3, 1
- 7% / €35M — Ban
- breaching the prohibited practices in Art. 5
- 3% / €15M — Break
- breaching most other provider or deployer obligations
- 1% / €7.5M — Bluff
- supplying incorrect or misleading information to authorities
Why it sticks: Descending 7-3-1 is easy to hold, and the alliteration maps the concept: banned practices, broken duties, bluffing the regulator.
EU AI Act — Annex III high-risk domains
Big Cats Eat Every Evening, Lions Munch Jackals
- Biometrics
- remote identification, categorisation, emotion recognition
- Critical infrastructure
- safety components in traffic, utilities
- Education
- admission, assessment, proctoring
- Employment
- recruitment, promotion, termination, task allocation
- Essential services
- credit scoring, insurance pricing, benefits, emergency triage
- Law enforcement
- risk assessments, evidence evaluation
- Migration
- asylum, border control, visa
- Justice
- administration of justice and democratic processes
EU AI Act — roles
Providers Place, Deployers Do
- Provider
- develops or places on the market under its own name — the heavy obligations
- Deployer
- uses it under its own authority — oversight, instructions, monitoring
Why it sticks: And for when a deployer becomes a provider (Art. 25): Name, Modify, Repurpose — put your name on it, substantially modify it, or repurpose it to a high-risk use.
OECD AI Principles
Inclusive Humans Trust Robust AI
- Inclusive growth
- sustainable development and well-being
- Human rights and democratic values
- including fairness and privacy
- Transparency and explainability
- meaningful information, and the ability to challenge outcomes
- Robustness, security and safety
- systems function appropriately throughout their life cycle
- Accountability
- actors are answerable for proper functioning and for these principles
Why it sticks: Worth knowing because the EU AI Act adopted the OECD definition of an AI system.
Breach notification timing
72 to the regulator, ASAP to the person — but only if it hurts
- Art. 33
- supervisory authority within 72 hours of becoming aware, unless unlikely to result in risk
- Art. 34
- affected individuals without undue delay, but only where high risk
Why it sticks: The clock runs from awareness, not from the incident.
Making them stick
- Write them from memory, don’t reread them. Retrieval builds recall; recognition does not. Cover the expansion and reconstruct it.
- Space the repetitions. Day 1, day 3, day 7, day 21 beats four passes in one evening.
- Invent your own where mine don’t land. A mnemonic you generated is markedly stickier than one you were handed — the effort of making it is what encodes it.
- Attach a scenario to each item. "Legitimate interests" is inert; "the vendor that wanted to train on our support tickets" is not.
- Drop the ones you no longer need. Once a list is automatic, the mnemonic is scaffolding you can take down.
Test yourself
Five questions on what is above, with every option explained. Your score is kept in this browser and shown on your dashboard, and saved to your account if you are signed in.
How many principles does GDPR Art. 5 contain?
- ASix, since accountability is a separate article.
- BSeven, counting accountability under Art. 5(2).
- CEight, matching the OECD privacy principles.
- DFive, with security treated as an Art. 32 duty.