Hael
Sign inRequest a demo
GDPR for AI

Prove lawful, accountable AI under the GDPR.

For each AI system that touches personal data, Hael holds the lawful basis, the record of processing, the DPIA and the Art. 22 handling — generated from the record and kept current.

app.hael.ai / registry / FRD-021
HAEL BANK · ISOLATED
GDPR · classified from the record
IN SCOPE
Fraud Scoring Model
Owner · CDO · S. Iqbal · System FRD-021
HIGH RISK
Obligations
Art. 5  Principles & accountability
MAPPED
Art. 6  Lawful basis for processing
MAPPED
Art. 22  Automated decision-making safeguards
MAPPED
Art. 30  Records of processing activities
MAPPED
Art. 35  Data protection impact assessment
HELD OPEN
Art. 13/14  Transparency to data subjects
PENDING
Generated · DPIA · v3SOURCED
What it demands

What the GDPR demands of AI processing.

The GDPR is not an AI law, but it governs every AI system that processes personal data. The substantive duties — lawful basis, purpose limitation, data minimisation, accuracy, security, accountability — apply unchanged.

Where AI makes decisions producing legal or similarly significant effects on people, Art. 22 adds explicit safeguards. Where the processing is high-risk, Art. 35 requires a DPIA before processing begins.

Obligations · 8 articles
MAPPED
Art. 5  Principles
Lawfulness, fairness, transparency, purpose limitation, minimisation, accuracy, storage limitation, integrity, accountability.
Art. 6  Lawful basis
A documented lawful basis for every processing operation — and Art. 9 conditions for special-category data.
Art. 13/14  Transparency
Plain information to data subjects, including the existence of automated decision-making and meaningful information about the logic.
Art. 22  Automated decisions
The right not to be subject to solely automated decisions with legal or similarly significant effects, with safeguards where it is permitted.
Art. 25  Data protection by design & default
Technical and organisational measures built into the system from the start.
Art. 30  Records of processing
An accurate, up-to-date record of processing activities, available to the supervisory authority.
Art. 32  Security of processing
Appropriate technical and organisational measures, considering risk to data subjects.
Art. 35  DPIA
A data protection impact assessment for high-risk processing — large-scale profiling, special-category data, public monitoring.
Closed vocabulary · sourced from the Act
What Hael does for it

Three things Hael does for the GDPR.

01
Classifies
Each system is screened for personal-data processing, lawful basis, special-category data, Art. 22 ADM scope and DPIA triggers — in plain language.
02
Generates
The DPIA, record of processing, Art. 22 handling notes, transparency disclosures and data-subject-rights records — produced from the record and sourced.
03
Keeps current
When the system, the data or the purpose changes, the DPIA and ROPA flag for review. Transparency notices update with the system, not after the complaint.
app.hael.ai / mapping / GDPR for AI
ONE CONTROL SET
GDPR for AI · obligation → control → record
MAPPED
Art. 6 · Lawful basis
Control · Lawful-basis record  ·  FRD-021
MAPPED
Art. 22 · ADM safeguards
Control · Human-in-loop control  ·  FRD-021
MAPPED
Art. 25 · By design & default
Control · Design & default record  ·  FRD-021
MAPPED
Art. 30 · ROPA
Control · Record of processing entry  ·  ROPA-118
MAPPED
Art. 35 · DPIA
Control · DPIA  ·  FRD-021
HELD OPEN
Art. 13/14 · Transparency
Control · Public notice & in-product  ·  PN-009
PENDING
One record · many regimes
The record through-line

The same record. Privacy alongside AI obligations.

A system entered once is governed against the GDPR and against the EU AI Act, ISO/IEC 42001 and NIST AI RMF — the same lawful basis, the same DPIA, the same record of processing, satisfying every regime that asks for them.

Artefact proof

The DPIA, generated and sourced.

Each section of the DPIA cites the record entry, control or attestation it came from. Residual risks are stated honestly — and where the record is silent, the section is held open.

app.hael.ai / documents / Data protection impact assessment
v3 · 09 Jun 2026
Data protection impact assessment · GDPR for AI
SEALED
§1  Description of the processing
Registry · FRD-021 · purpose, data, recipients
SOURCED
§2  Necessity & proportionality
Lawful-basis record · legitimate-interest assessment v2
SOURCED
§3  Risks to data subjects
Risk register · FRD-021 · 9 risks · v3
SOURCED
§4  Measures to address risks
Control register · 14 mitigating controls · live
SOURCED
§5  Residual risk & DPO opinion
Open — DPO consultation scheduled 28 Jun 2026; opinion held until file. The section will not be closed before consultation.
HELD OPEN
§6  Consultation with data subjects
Decision · not consulted · documented rationale v1
SOURCED
Every section cites the record entry behind it
Related frameworks

Govern this alongside everything else.

One system, one record, governed against every framework at the same time. Map an obligation once; satisfy it everywhere it recurs.

Free check

See where you stand on GDPR for AI, free.

Answer a few questions and get an indicative view of what GDPR for AI expects of your AI systems and where you stand today — no sign-up to see your result.

Indicative, not legal advice.
GDPR for AI · indicative readiness
HAEL FREE TOOLLIVE
Applicability
Applies to your AI use
MAPPED
What's expected
Risk classification · governance · documentation · oversight
4 PILLARS
Where you stand
Banded result · pointed to the gaps that matter most
SOURCED
Result
On-screen, free · optional PDF
FREE
Effort
Pre-scoped to GDPR for AI
~ 5 MIN
INDICATIVE · NOT LEGAL ADVICE
See it on a real record

See the DPIA generated, sourced and held.