Compliance Services

Managing Data Protection, AI and Data Sharing Risk

Data Protection Risk

DigiTorc works with organisations to implement cost effective and streamlined data handling measures. Successful data privacy transformation requires strong governance and leadership.

Organisations that process and hold personal data in their care are required to publish particular information and have the following policy and procedure documentation in place:

  • Data Protection Policy.
  • Data Privacy Notice, listing the purposes and legal bases that the organisation relies upon to collect personal data.
  • Data Subject Rights Request Procedure.
  • Data Breach Handling Procedure.
  • Data Retention Policy.

In addition, organisations are obliged to undertake the following activities at various times and revisit later if necessary:

  • Carry out a Maturity Level Assessment (MLA) to measure and highlight the gap between an organisation's current data protection posture and GDPR compliance levels to be bridged. The MLA is an important Risk Management exercise to undertake from time to time.
  • Create and maintain a Record of Processing Activities (ROPA) when required by law.
  • Undertake a Data Protection Impact Assessments (DPIA) - a risk assessment - whenever a new processing activity could put the rights and freedoms of data subjects at risk.
  • Carry out a Transfer Impact Assessment (TIA) when it is planned to transfer personal data to entities in jurisdictions without Adequacy Agreements in place with the EU Commission.
  • Undertake a Legitimate Interest Assessment (LIA) when the organisation plans to rely on the legal basis "Legitimate Interest" to process personal data.

Our objective is to help organisations meet legal obligations without over-complicating matters. GDPR compliance is more than a mere tick-box exercise, the trustworthiness it imparts will enhance your brand; that's a key differentiator to help grow your business!

Our objective is to get your organisation compliant while not over complicating matters.  GDPR can be a strategic differentiator helping businesses to grow, not just another compliance matter. Besides putting in place the various technology solutions, strategies, policies and plans required to meet EU GDPR requirements, we also offer an outsourced Data Protection Officer service and  carry out any internal training or DPIAs that may be necessary.

AI Risk

Developers, manufacturers, importers, resellers and deployers of potentially High-Risk AI systems classified under the AI Act will be required to commission one or more of the following deliverables at various points throughout their AI Model Lifecycles.

  • Fundamental and Human Rights Impact Assessments (FRIA) to assess the impact of proposed AI developments on the rights and freedoms of individuals,
  • AI Impact Assessment (AIIA) to identify AI risks and mitigations, and
  • AI Conformity Assessment (AICM) to confirm  CE Mark readiness.

DigiTorc works with organisations to prepare for this new world of AI conformity obligations. In particular, we will help you:

  • Create an AI Governance Policy that articulates your AI strategy and business objectives.
  • Establish an AI Management System and supporting GRC tooling while providing guidance on emerging EU AI Act Implmentation Standards.
  • Undertake AI Maturity Level Assessments to track progress as your AI capabilities evolves.
  • Implement an explainability framework to meet the Transparency obiligations of providers under Article 13 of the AI Act and GDPR transparency obligations (Articles 13, 14 and 15).  AI Transparency artefacts that DigiTorc can help organisations prepare include:
    • Explainability Requirements Specification
    • Explainable AI (XAI) Tool Evaluation Matrix
    • End-User Transparency Notices
    • AI Decision Logging Templates
    • Explainability Validation Test Plan
    • User-Friendly AI Decision Disclosures
    • Regulatory-Grade Transparency Documentation
    • AI GRC SaaS software
  • Implement an AI Monitoring System to track AI incidents and algorithmic performance and drift post-release.

Trustworthiness is a key values for new AI brands to win approval in the marketplace. The ability to demonstrate responsible AI development practices will be a business differentiator.  In addition to ddeveloping AI policies and implementing the AI lifecycle tooling needed to meet EU AI Act requirements, we also offer an outsourced AI Officer (AIO) service and will deliver internal AI training and undertake AIIAs and other assessments as and when needed.

PersonalData
DigiTorcMLASpider
DPIAHeatMap
DP&AIStack
ROC
DPIAHeatMap
ROC

GDPR principles are already being applied and interpreted by regulators and courts across Europe with similar momentum and case history building behind the AI Act.  In both cases, findings & decisions may be appealed and overturned others will become settled law. Based on the application of data protection and AI laws (including the Digital Omnibus changes) across the EU, EEA and UK, it will be necessary to change ways of working,  policies and procedures. DigiTorc will be with you on your GDPR and AI compliance journeys.

If you would like to talk to someone about GDPR and AI compliance work please contact us

 

Scroll to Top