Embed responsibility in technology and organisation

Data protection, AI governance & compliance

We help companies use data and AI systems in a controlled way, with clear responsibilities, traceable processes and appropriate technical measures.

Assess compliance needs

AI expands the data protection challenge

AI raises new questions: Which systems are used? What data goes in? Who decides on deployment? What risks and documentation and transparency duties apply?

evival combines privacy expertise with technical experience in software, data and AI, turning requirements into processes businesses can implement and maintain.

GDPRControl data processing
AI ActAssess roles and risks
GovernanceEstablish responsibility

Where businesses need direction

01

Unknown AI usage

Teams use AI tools without a central overview of systems, purposes, data flows and responsibilities.

02

Unclear roles

It is unclear whether the company is an AI provider or deployer and what duties follow.

03

Missing evidence

Decisions, checks, training and technical measures are not documented consistently.

From overview to sound governance

01

Data protection management

Maintain processing activities, technical and organisational measures, processor arrangements and privacy processes systematically.

02

AI inventory and roles

Record current and planned AI systems, purposes, data, responsibilities and provider and deployer roles.

03

Risk and classification

Assess use cases by their characteristics, prioritise risks and define required next steps.

04

AI governance

Define policies, approvals, responsibilities, human oversight, monitoring and escalation paths.

05

Documentation

Document decisions, checks, data sources, system boundaries and measures transparently.

06

AI literacy

Train employees according to their roles in opportunities, limits, data protection, security and responsible AI use.

Compliance as an ongoing process

01

Take stock

We record systems, data processing, use cases, providers, contracts and existing rules.

02

Assess roles and risks

Duties and risks are prioritised; open issues receive owners and realistic deadlines.

03

Develop the framework

Policies, approval processes, documentation requirements and controls are designed to fit the organisation.

04

Implement technically

Permissions, logging, data minimisation, system boundaries and other measures are incorporated into solutions and workflows.

05

Train and review

Employees are equipped with skills; systems, risks and rules are updated regularly.

Rules must work in everyday practice

Documents alone do not create compliance. We ensure requirements fit existing processes, owners understand them and technical systems support the rules.

Note: evival supports technical and organisational data protection and compliance tasks. Where binding legal advice is required, an appropriately authorised legal adviser should be involved.
  • Traceable responsibilities
  • Verifiable approval processes
  • Role-based training
  • Controlled data sources
  • Human oversight
  • Regular updates

AI compliance questions

Does the AI Act also affect companies that only use AI tools?

Depending on the system and use, a company may have duties as a deployer. Role, purpose and risk level should therefore be assessed for each relevant use case.

What belongs in an AI inventory?

System and provider, purpose, users, affected processes, data used, responsibilities, company role, risk level and existing measures, among other things.

Is a general AI policy enough?

A policy is an important component. Practical approvals, responsibilities, training, documentation and ongoing controls are also needed.

How do the GDPR and AI Act interact?

Both may apply in parallel. The AI Act does not replace data protection duties; both perspectives must be considered together, especially for personal data.

Is your AI usage already under control?

Together, we assess the current situation and identify the most important organisational and technical next steps.

Arrange a call