Services

GDPR · EU AI Act · Advisory

Practical compliance, from data mapping to AI governance.

Hands-on support across data protection and the EU AI Act — mapping, impact assessments, documentation, outsourced DPO and AI governance, delivered end to end.

01

GDPR Services

Data protection compliance built to last, and maintained as your organisation changes.

01

Data processing mapping — new products and services

  • Hands-on support mapping the personal data your organisation holds and processes
  • Building the mapping so it stays maintainable — easy to update as activities change, rather than a one-off snapshot
  • Optionally delivered through a SaaS register, which also serves as a secure channel for exchanging documents
  • A written overview of what needs to happen and in what order, so gaps get closed by priority rather than all at once
02

Data protection impact assessment (DPIA)

  • Assessing how well existing data protection measures actually work
  • Evaluating processing activities against GDPR requirements
  • Reviewing software and databases against the technical and legal requirements
  • Producing DPIA documentation that meets the regulation’s standard
03

Data protection documentation

  • Records of processing activities, privacy notices and cookie notices
  • Consent forms drafted to fit the business model, not just the legal text
  • Internal policies, together with the processes that make them work in practice
  • Employment-related data protection documentation
  • Processing agreements — intra-group and external, controller and processor terms, technical and organisational measures, including international transfers
04

Outsourced DPO

  • Full external DPO service, or advisory support for an in-house DPO
  • Guidance and training for the organisation and its staff on their data protection obligations
  • Ongoing monitoring of compliance with GDPR and with your own internal policies and processes
  • Acting as the contact point for supervisory authorities, including breach notification
05

Risk management and data security

  • Advising R&D and product teams during development, while decisions are still cheap to change
  • Risk management and information security
  • Technical and organisational measures
  • Tooling recommendations — anonymisation, encryption, processing logs, consent management, cookies
  • Managing personal data breaches, including reporting to authorities
  • Incident response
06

Training

  • Tailored DPO training built around the client’s profile
  • Explaining which GDPR requirements actually apply to that specific organisation
  • Role-specific staff training — customer service, sales, marketing analytics, IT development, finance — including public sector specifics

Ready to get your GDPR house in order?

Get in touch
02

AI Act Services

EU AI Act readiness — from first inventory through to ongoing operation.

01

Assessment and orientation

  • AI system inventory — everything built, bought, or embedded in tools you already use, including shadow AI
  • Role determination per system — provider, deployer, importer, distributor
  • Risk classification — prohibited / high-risk / transparency-only / minimal, with written reasoning you can defend
  • Scope check — territorial reach, exemptions, overlaps with sector rules (medical devices, machinery, financial services)
  • Gap analysis and prioritised remediation plan
  • Compliance roadmap sequenced against the real deadlines
02

Near-term obligations

  • AI literacy programme — training tiered by role, with completion records
  • Prohibited practices screening
  • Transparency implementation — chatbot disclosure, deepfake and synthetic content labelling, machine-readable marking
  • Workplace notification — informing employees and works councils where AI is used
03

High-risk readiness — providers

  • Risk management system
  • Data governance — training, validation and test data quality, bias examination
  • Technical documentation package (Annex IV)
  • Logging and traceability design
  • Human oversight design with real intervention points
  • Accuracy, robustness and cybersecurity measures
  • Quality management system
  • Conformity assessment support, declaration of conformity, CE marking
  • EU database registration
  • Post-market monitoring and serious incident reporting
04

High-risk readiness — deployers

  • Deployer obligations — oversight assignment, input data relevance, log retention
  • Fundamental Rights Impact Assessment
  • Instructions-for-use review: are you using the system the way the provider intended?
  • Information and contestation processes for affected people
05

Governance and operating model

  • AI governance framework and policy set
  • Employee AI use policy
  • Ownership and accountability model, per system
  • Approval workflow for new AI use cases
  • Integration into existing processes — product scoping, procurement, release, change management
  • Interlock with ISO 42001, ISO 27001 or an existing management system
06

Vendor and contract work

  • AI vendor due diligence and assessment questionnaire
  • Contract review and clause drafting — obligation allocation, documentation and audit rights, indemnities
  • Procurement gate design, so the check happens before signature
  • Downstream obligations when building on general-purpose models
07

Ongoing

  • Fractional AI compliance officer / retainer
  • Register maintenance and periodic re-classification
  • Change triggers — when a modification makes you a provider or shifts your tier
  • Regulatory, standards and guidance monitoring
  • Incident response and regulator liaison
  • Internal audit and readiness testing
08

Training and enablement

  • Executive and board briefings
  • Product and engineering workshops
  • HR-specific training — recruitment and workforce AI sits in Annex III
  • Train-the-trainer so the client sustains it internally
09

Productised offers

  • AI Act Quick Scan — inventory, classification, one-page risk picture
  • Transparency Sprint — everything needed for the August 2026 duties
  • High-Risk Readiness Programme — provider or deployer track
  • Governance in a Box for small companies — register, policy, templates, training
  • Annual compliance health check

Getting ready for the EU AI Act?

Get in touch