Legal Basis
Every AI processing activity needs a legal basis under Art. 6 GDPR. Most business AI use cases rely on contract, legitimate interest or consent. We determine the right basis and document it.
Contract, legitimate interest or consent — documented and reviewed before any data touches the model.
Which personal data is processed? Which can be excluded or pseudonymised?
High-risk processing triggers a mandatory DPIA. We assess together and document the outcome.
DPAs with all AI vendors. SCCs or adequacy decisions for non-EU processing.
Encryption, access control, audit logs, incident response plan.
Privacy notices, cookie banners and AI disclosure texts for users and employees.
Access, rectification, erasure, portability and objection — all technically enabled and process-supported.
Every significant AI decision is logged. Sensitive actions require human confirmation.
Automated deletion, documented retention periods, right to erasure enforced at model level.
Staff trained on AI data handling. Annual review of models, data sources and compliance docs.
Every AI processing activity needs a legal basis under Art. 6 GDPR. Most business AI use cases rely on contract, legitimate interest or consent. We determine the right basis and document it.
Minimal risk (content generators, spam filters) — light requirements. Limited risk (chatbots) — transparency obligations. High risk (HR, credit, safety) — full documentation and oversight required.
2-day assessment of your existing or planned AI use cases against GDPR and AI Act requirements. Deliverable: written gap analysis and prioritised action list.
Full DPIA process for a specific AI use case: risk assessment, mitigation measures, documentation. Ready for your DPO review.
Ongoing compliance monitoring as new AI features are added: quarterly reviews, updated docs and incident support. Optional retainer model.
I bridge the gap between your legal team (who knows GDPR but not AI architecture) and your IT team (who builds the AI but doesn't think about compliance). I translate between both worlds and deliver working solutions with documentation that auditors accept.
Based in Regensburg, Bavaria — working with SMEs, corporates and public-sector organisations across Germany.
Book a free compliance checkA DPIA is required when AI processing is likely to result in a high risk to individuals — for example when processing special categories of data, systematic monitoring or automated decisions with significant effects. We assess this together and document the outcome.
Yes, if the legal basis, Data Processing Agreement and transfer safeguards are in place. For sensitive data, on-premises models are the cleaner option. We help you choose the right architecture.
Most SME use cases fall into the minimal or limited risk category with light requirements. High-risk systems face stricter documentation and oversight. We assess your use case and prepare required documentation.
Under GDPR, your company (the data controller) remains responsible for automated decisions. We implement human-in-the-loop checkpoints, audit logs and clear escalation paths so responsibility is always traceable.