A map of your data, not a policy binder
Every dataset traced to its source, its owner, its retention window and the systems it flows into. That map is what makes every later compliance question answerable in minutes.
Who owns which data, who may see it, how long you keep it, and what the GDPR and the EU AI Act require of every AI use. Set up so it does not stall your roadmap.
Governance starts with the data, not the model. We map where each dataset comes from, who owns it, who may see it, how long you are allowed to keep it and where it flows next. Most companies discover here that the same customer record lives in four systems under three different retention rules, and that is the finding that makes the rest of the work possible.
On top of that we classify your AI use cases under the EU AI Act, set up the risk assessments and documentation each class requires, and write the policies that matter for your exposure: personal-data handling and the GDPR basis for it, human oversight, model documentation, incident response. The engagement starts with an inventory of every AI system, use case and vendor tool in play, including the unofficial ones your teams already use. The checks are wired into your existing delivery process, not into a parallel bureaucracy.
What changes: your compliance and legal teams get evidence they can hand to auditors or to a data protection authority, and your engineers get clear rules instead of case-by-case escalation. New AI initiatives clear governance in days rather than weeks, because the gates, the data map and the templates already exist and everyone involved knows how to use them.
Every dataset traced to its source, its owner, its retention window and the systems it flows into. That map is what makes every later compliance question answerable in minutes.
Personal-data obligations and AI risk classification handled together, per use case, because in practice they land on the same systems and the same teams.
Model cards, data lineage and decision logs kept as living artifacts, produced during delivery rather than reconstructed later.
Third-party AI tools and APIs get the same classification and review as in-house systems, closing the most common blind spot.
Templates and gates make the tenth AI initiative as well governed as the first, without re-litigating policy each time.
Where each dataset comes from, who owns it, who has access, how long it is kept and which systems it flows into, including the spreadsheets nobody admits to.
Each item is classified under the EU AI Act and your internal risk appetite, with obligations mapped per class.
Policies, templates and review gates are written and wired into your delivery process, with owners assigned.
We train the people running the gates, run the first reviews together, and hand over a playbook your team maintains.
If you operate in the EU and use AI in products, hiring, credit, safety or anything customer-facing, parts of it almost certainly do. The inventory and classification give you a definitive answer per use case instead of a general worry.
Done badly, yes. That is why we wire the gates into your existing workflow and size them by risk. Low-risk uses get a lightweight checklist, and heavy review is reserved for the few systems that genuinely warrant it.
Because the obligations land in code: logging, oversight hooks, documentation, evaluation evidence. We translate legal requirements into technical controls your compliance team can verify, which is the part most policy documents skip.
Both, and separating them wastes your time. An AI use case almost always processes personal data, so it needs a lawful basis, a retention rule and an access model under the GDPR, and a risk classification with its documentation under the AI Act. We work through them together, per use case, and you end up with one set of evidence instead of two projects that contradict each other.
Book a call to scope the data map and the AI inventory. It is the fastest way to learn your real exposure under both the GDPR and the EU AI Act.
Scope the data map