Prove lawful, accountable AI under the GDPR.
For each AI system that touches personal data, Hael holds the lawful basis, the record of processing, the DPIA and the Art. 22 handling — generated from the record and kept current.
What the GDPR demands of AI processing.
The GDPR is not an AI law, but it governs every AI system that processes personal data. The substantive duties — lawful basis, purpose limitation, data minimisation, accuracy, security, accountability — apply unchanged.
Where AI makes decisions producing legal or similarly significant effects on people, Art. 22 adds explicit safeguards. Where the processing is high-risk, Art. 35 requires a DPIA before processing begins.
Three things Hael does for the GDPR.
The same record. Privacy alongside AI obligations.
A system entered once is governed against the GDPR and against the EU AI Act, ISO/IEC 42001 and NIST AI RMF — the same lawful basis, the same DPIA, the same record of processing, satisfying every regime that asks for them.
The DPIA, generated and sourced.
Each section of the DPIA cites the record entry, control or attestation it came from. Residual risks are stated honestly — and where the record is silent, the section is held open.
Govern this alongside everything else.
One system, one record, governed against every framework at the same time. Map an obligation once; satisfy it everywhere it recurs.
See where you stand on GDPR for AI, free.
Answer a few questions and get an indicative view of what GDPR for AI expects of your AI systems and where you stand today — no sign-up to see your result.