Versatile AI Risk Assessment

Who it is for Data protection officers

Assessing AI systems for data protection

When AI is used, you need to review how personal data is handled and consider the EU AI Act. The application helps you collect information about the system, assess data protection risks and prepare an impact assessment where one is required.

The starting point

You know the data protection impact assessment. What is new is that the EU AI Act requires its own records, capturing the same facts from a different angle. Art. 26(9) of the Act states explicitly that deployers shall use the provider information for that assessment. Keeping both sets of records separately means writing down the same facts twice and keeping them current twice.

The second point concerns the role. You almost always assess as a deployer. But if a system is rebranded, substantially modified or put to a different purpose, the organisation moves into the provider role under Art. 25(1), and a different set of obligations applies. That change often goes unnoticed because nobody in the organisation reports it.

The provider information on performance limits and types of error belongs expressly in the data protection impact assessment. Keeping both records separately means writing the same thing down twice.

Art. 26(9)

Assessments step by step (3)

Each step links to the relevant features and information.

  1. Assess under data protection law 94 questions in ten sections, with a pre-check on the impact assessment.
  2. Assess the threats The eight threats mapped to the GDPR, four of them in the privacy group.
  3. Bring both assessments together The provider information on performance limits and types of error belongs in the impact assessment.

Questions and answers (12)

Answers with sources and links for further review.

Does an AI system require a data protection impact assessment?

The duty follows from Art. 35 GDPR and depends on the risk of the processing, not on whether artificial intelligence is involved. The data protection check guides you through 94 questions in ten sections and ends with a pre-check on whether an impact assessment is required. It runs as a single file in the browser, without any sign-up.

Does classification under the EU AI Act replace the data protection impact assessment?

No. The two assessments remain separate and rest on different legal bases. However, Art. 26(9) of the EU AI Act explicitly requires deployers to use the provider information on performance limits and types of error in that assessment. This is why both start from the same system context here.

Evidence
Impact assessment referencing the provider information

What role does my organisation have under the EU AI Act?

The Act knows seven roles: provider, deployer, importer, distributor, authorised representative, product manufacturer and provider of a general-purpose AI model. Anyone using a bought-in system in their own organisation is normally a deployer. For deployers the obligations compass lists 24 of the 62 obligations.

When does a deployer become a provider?

Under Art. 25(1) a deployer moves into the provider role when it puts the system on the market under its own name, substantially modifies it or changes its intended purpose. With that change the full set of provider obligations applies. This is the most frequently overlooked role change, because nobody in the organisation reports it.

Evidence
Note per modification with type of change, assessment and result

Which AI threats directly affect personal data?

The catalogue holds 52 threats, four of them in the privacy group: privacy attacks, disclosure of sensitive information, exfiltration from the machine learning application, and cross-tenant leakage in shared vector databases. Four further threats carry a mapping to the GDPR, eight in total. Each names its mitigations and its verified references.

What information must I require from the provider?

The instructions for use under Art. 13, the information on performance limits and types of error for the impact assessment, access to the logs, and the assurances on data processing. If any of these is missing, the impact assessment cannot be completed: record the gap and request the information from the provider.

Who must I inform about the use, and where?

Affected persons under Art. 26(11) and, for systems at the workplace, the workers and their representatives in advance under Art. 26(7). The information belongs where the decision is made, for example in the application process or the credit decision. A note in the general privacy policy usually does not reach the person concerned.

Evidence
Wording and placement of the notice per process

How long must the logs of a high-risk system be kept?

At least six months under Art. 26(6), unless Union or national law requires a longer period. For cloud services, access to those logs is a contractual matter, not a configuration matter: whoever has not agreed it does not have it when it is needed.

Evidence
Contractual assurance of log access

Must I carry out a fundamental rights impact assessment under Art. 27?

The duty does not apply to every deployer of a high-risk system, but to the group named in Art. 27. So check first whether you are covered. If your organisation is, the assessment must be carried out and notified to the market surveillance authority.

Evidence
Completed assessment and notification to the authority

From when do the obligations for high-risk systems apply?

Since Regulation (EU) 2026/1744, in force since 27 July 2026, the requirements for systems under Annex III apply from 2 December 2027 and for Annex I from 2 August 2028. Two new prohibitions already take effect on 2 December 2026. Many overviews still in circulation quote the earlier dates.

Do the assessment data leave my computer?

No. The application runs in the user’s browser. The working state is saved to a file and read back in; there is no transfer to any service run by the provider. This holds for the free edition, for the single modules and for the offline edition. What that means for your own professional or contractual obligations is for you to assess.

What does the application explicitly not do?

It replaces neither an assessment of the individual case nor legal advice. It keeps no record of processing activities, it notifies nothing to supervisory authorities, and it does not assess data processing agreements. The obligations compass classifies; it does not decide.

Limits of the application (4)

These tasks require additional tools or professional review.

Tasks outside the application

  • It replaces neither an assessment of the individual case nor legal advice. The obligations compass classifies; it does not decide.
  • It keeps no record of processing activities. Anyone who needs one continues to keep it where it is today.
  • It notifies nothing to supervisory authorities. Notifying the fundamental rights impact assessment under Art. 27 remains a separate route.
  • It does not assess data processing agreements. Reviewing the contract stays with you.

Suitable editions

€2,490 once

Professional Offline

For regular work across several systems: reports as PDF and workbook, machine-readable exports, extended evidence packages.

Open
free of charge

Live demo to get to know it

The complete Community Edition with example data, directly in the browser and without sign-up. For trying out the method; your own work inside a company or a public body is not covered by the Community licence.

Open

Compare the features, licence terms and prices of the Community, Professional and Enterprise editions. Compare editions

Other audiences (7)

Guidance for other responsibilities within your organisation or your clients’ organisations.

← Back to the overview