Requests from Affected People
When an AI system makes, or helps make, a decision about a person, that person may ask your organization about it. This register records each such request: what was asked, which AI system and decision it concerns, who is handling it, the response target your organization set, and what the person was told.
Recording a request here does not mean a law applies to it, and Backsplice never decides that. It is a record of what your organization received and did.
The types of request
- Explanation of a decision: the person asks how the AI system was used in a decision about them and what the main reasons for the decision were.
- Appeal or human review: the person asks for the decision to be looked at again by a person who can change it.
- Correction of data: the person says information about them that the decision used is wrong and asks for it to be corrected.
- Opt-out of automated decision-making: the person asks not to have decisions about them made with the AI system.
- Access to information about the decision: the person asks what information about them was used and how the system processed it.
- Complaint: the person complains about a decision or about how the AI system was used.
- Other: anything else about an AI-assisted decision.
The legal basis is recorded by a person
A request can carry one or more legal-basis tags: the EU AI Act's Article 86, the California CCPA regulations (including automated decisionmaking technology), Colorado's automated decision-making technology law, or another law or policy. Tick a basis only when your organization has decided the request falls under it. Leave it unticked (None recorded) otherwise.
When a basis is ticked, the request's page quotes the provisions of that law that correspond to the request type, word for word and with their citation, for reference. Whether and how a provision applies to your organization is for your organization and its counsel to decide; this is not legal advice.
The response target is your organization's
Every request has a Respond by date. A new request starts with your organization's default, a number of days after the date it was received (30 days until an administrator changes it on the register page), and the person recording it can change the date. It is your organization's own target, not a legal deadline. Where a law you record states a period, the request form lists those periods, quoted and cited, beside the date, so your team can set the target with them in view.
An open request past its target is marked Overdue in red on the register, on the AI system's page and in My Work. The handler, or the organization's admins when there is no handler, is reminded once when the target is 7 days away and once when it has passed. Changing the date sends the reminders again for the new one.
How a request moves
- Received: recorded, not yet worked on.
- In progress: someone is preparing the response.
- Responded: the response is recorded: what the person was told, the outcome, the date, and for an appeal the human reviewer who looked at the decision again. Where you can, choose a reviewer who did not make or own the original decision.
- Closed: done. A request is closed only after its response is recorded.
- Rejected: refused, with the reason recorded.
- Withdrawn: the person withdrew it.
A closed, rejected or withdrawn request can be reopened with a reason; it returns to In progress. Every move is written to your organization's audit log.
Who sees what
- Administrators record and edit requests, see every request, and can delete one recorded in error.
- Contributors see the requests they handle or review and, from the request's page, move them through every step: record the response, close, reject or mark withdrawn, and reopen with a reason. Recording and editing a request's details, and deleting one, are for administrators.
- Auditors with access to the AI system registry see every request and export the register, with the person's name and contact withheld: they see your reference for the person instead.
Personal data
The person's name and contact details are optional. Record them only if your team needs them here to respond. They are withheld from auditors, left out of reminders, notifications and the calendar, not searched, and deleted with your organization's data. Keep names out of the summary and the response: use your reference for the person instead.
How long to keep request records is your organization's decision. Some laws require records of requests and responses to be kept for a period, and the request page quotes those provisions where they are recorded. Backsplice keeps a request until an administrator deletes it or your organization's data is deleted.
Exporting
Export CSV downloads the requests the register is showing, with the same filters. An auditor's file withholds the name and contact columns.