AI Compliance

GDPR and the AI Act, without stalling your projects

We map your AI usage, identify what falls under GDPR and the AI Act, and bring you into compliance with defensible deliverables — without putting your projects on hold.

Personal data

GDPR

Your AI systems process personal data: legal bases, minimisation, retention periods, and data-subject rights all have to hold up under scrutiny.

  • Mapping of the processing activities behind your AI systems
  • Impact assessments (DPIA) on high-risk processing
  • Up-to-date register, policies, and privacy notices
  • Framework for transfers and AI sub-processors
EU AI regulation

AI Act

Every AI system falls into a risk tier that determines your obligations. We classify yours and build the documentation regulators expect, deadline by deadline.

  • Inventory and risk-tier classification of your AI systems
  • Technical documentation and risk management for high-risk systems
  • Transparency obligations and user-facing disclosures
  • Roadmap aligned with the regulation's phase-in calendar

How the engagement runs

Four steps, from the first assessment to ongoing oversight.

Assessment

We inventory your AI systems and the processing behind them, then measure the gap against GDPR and the AI Act.

Risk analysis

AI Act classification per system and GDPR impact assessments where required, each with a priority level.

Remediation

Policies, registers, technical documentation, and product adjustments — we produce the deliverables and coach your teams through them.

Ongoing oversight

Periodic reviews, regulatory watch, and team enablement so compliance holds up over time.