Data Protection Impact Assessment
Screening result today and the commitment to a full DPIA before any commercial launch. Available to customers on request under NDA.
Screening (Art. 35 criteria)
| Criterion | Assessment | Triggered |
|---|---|---|
| Evaluation or scoring | Companies are scored, not persons; scoring is advisory with a human gate. | Partially |
| Automated decisions with legal effect | None. No decision about a person is automated. | No |
| Systematic monitoring | Public company sources are monitored; persons are not tracked. | No |
| Sensitive data | None processed. | No |
| Large scale | Hundreds of companies per customer; contacts only when activated. | Low |
| Matching or combining datasets | Public evidence is combined with the customer's CRM and accounting context at company level. | Yes, company level |
| Innovative technology | LLM extraction with structured output and quote validation. | Yes |
Conclusion
Two criteria are met (combining datasets, innovative technology), so a full DPIA is required before commercial launch and is scheduled as part of the first paid pilot. During the hackathon demo, processing is limited to fictional and reviewed demo companies, with no professional contacts activated.
Risks identified and controls
- Fabricated or stale evidence → exact-quote validation against stored text, recency decay, freshness re-checks, Fact / Hypothesis labels.
- Misidentified company → identity by domain and registry ID; unconfirmed identity routes to research, never to action.
- Contacting a person without basis → LIA, role filter, suppression list checked before drafting, Art. 14 notice, human send.
- Prompt injection through a source document → documents get no tool permissions; acceptance test with a hostile page.
- Data leaving the EU → EU hosting, EU-resident model option, sub-processor list.
Consultation
DPO involved from design; customers' DPOs consulted in the pilot; supervisory authority consulted if residual risk stays high after measures (Art. 36).
Items highlighted like this are filled in per customer or before launch. We describe controls we operate; we do not present GDPR compliance, AI Act conformity or ISO certification as achieved results until verified.