ai & data

AI, dataaivacy regulation

We advise on the design, development and exploitation of AI-based solutions and intensive data processing, integrating complianceirements from the start of the project.

AI Act · GDPR · Risk assessment · Data governance · Compliance

We review your AI system and help you comply with the European AI Regulation.

AI Act and AI Regulation

We advise on compliance with the AI Regulation (AI Act) and sector-specific regulations applicable to artificial intelligence systems, as well as in other types of activities or products.

Startups developing AI systems need to comply with the AI Act from day one. We help with both regulatory compliance and proper legal structure and incorporation.

AI compliance services:

  • Classification of AI systems according to risk level
  • Analysis of transparency and explainability requirements
  • Technical documentation and conformity assessment
  • Governance of training data and biases
  • Registration in EU databases for high-risk systems

GDPR and Data Protection

We implement GDPR compliance systems in digital products, mobile applications and SaaS platforms.

GDPR compliance:

  • Compliance audits and gap analysis
  • Record of processing activities (ROPA)
  • Data protection impact assessments (DPIA)
  • Privacy policies and information notices
  • Management of data subject rights (ARSULIPO: Access, Rectification, Erasure, Restriction, Portability, Objection)

International Data Transfers

We structure compliant mechanisms for personal data transfers outside the EEA, including standard contractual clauses and BCR.

Transfer mechanisms:

  • Standard Contractual Clauses (SCC) post-Schrems II
  • Binding Corporate Rules (BCR) for corporate groups
  • Transfer impact assessments (TIA)
  • Supplementary security measures
  • Data processing agreements (DPA)

Data Contracts

We draft processing, transfer and data licensing agreements that comply with GDPR and protect your data assets.

Types of contracts:

  • Data processing agreements (DPA)
  • Dataset transfer and licensing agreements
  • Data sharing agreements
  • Contracts with cloud and SaaS providers
  • Data protection clauses in commercial contracts

Data Governance

We design data governance structures that ensure quality, security and regulatory compliance throughout the organization.

To effectively implement data governance, team training is essential. Discover our data protection training programs.

Data governance services:

  • Data governance policies and responsibility roles
  • Data classification and sensitivity levels
  • Data lifecycle management
  • Data quality and lineage audits
  • Data protection training and awareness

Frequently asked questions about AI, GDPR and data protection

What is the AI Act and who does it apply to?

The AI Regulation (Regulation (EU) 2024/1689, known as the AI Act) is the European legislation regulating the development, placing on the market and use of AI systems. It applies to providers, deployers, importers and distributors of AI systems that are placed on the market or used in the EU, regardless of where they are established. It classifies systems into unacceptable, high, limited and minimal risk, with obligations proportionate to each level.

How do I know if my AI system is high-risk?

A system is high-risk if it is listed in Annexes I and III of the AI Act (biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration and justice) or if it is a safety component of regulated products. High-risk systems require conformity assessment, technical documentation, registration in the EU database, data governance and human oversight.

What is a DPIA and when is it mandatory?

A DPIA (Data Protection Impact Assessment) is a GDPR-mandated analysis required when processing poses a high risk to the rights and freedoms of individuals, for example systematic and extensive evaluation of personal aspects, large-scale processing of sensitive data, or systematic monitoring of public areas. It must be documented before processing begins and reviewed periodically.

Who is the Data Protection Officer (DPO) and when is one required?

The DPO is the figure responsible for ensuring GDPR compliance within an organisation. A DPO is required when carrying out large-scale processing of sensitive data, large-scale systematic monitoring, or when the processing is carried out by a public authority or body. We offer an external DPO service for companies that need compliance without an in-house profile.

What are international data transfers?

They are movements of personal data outside the European Economic Area (EEA). To be GDPR-compliant they must rely on an appropriate mechanism: a Commission adequacy decision, Standard Contractual Clauses (SCCs), BCRs or specific exceptions. Following Schrems II, a transfer impact assessment (TIA) and supplementary security measures are usually also required.

What penalties does the GDPR provide for?

The GDPR provides for administrative fines of up to €20 million or 4 % of the global annual turnover of the previous financial year, whichever is higher. The amount depends on severity, intentionality and the measures taken. The AI Act provides for even higher fines for prohibited AI systems (up to €35 million or 7 % of turnover). A compliance programme significantly reduces risk.

What is the ARSULIPO right?

It is the set of data subject rights recognised by the GDPR: Access, Rectification, Erasure, Restriction of processing, Portability and Objection. Controllers must enable mechanisms for individuals to exercise them easily and free of charge, and respond within one month.

Need to comply with GDPR or AI Act?

Tell us about your digital product or service and we'll help you implement the necessary compliance.

Let's talk
Contact us