DataAigis Privacy & AI Governance
AI risk still lands on personal data, so GDPR and PIPL privacy operations run in the same system as AI governance — one asset register, one approval and audit trail, no reconciliation between two tools.
Discuss privacy and AI governanceMODULES
Eleven asset classes registered in full — models, datasets, agents, third-party AI services, prompts, knowledge bases, tools, MCP servers — with dependencies graphed (use case → agent → model / knowledge base / tool).
Automatic classification across two regimes: EU AI Act four tiers plus China's generative-AI filing test. Includes agent-specific checks — permission boundaries, data sensitivity ceilings, autonomy level, high-risk action allowlists.
Clause-level obligation registers: 27 EU AI Act articles and 12 Chinese provisions built in, each with applicability, the governing clause, evidence required, and a countdown to effect. Missing facts are marked "undetermined", not "not applicable".
Intake, tiered approval, admission decisions, and full lifecycle tracking.
Public intake portal, identity verification, routing and approval, encrypted data package delivery. Covers access, deletion, correction, portability, restriction, objection and opt-out, with statutory clocks started automatically.
Registration and approval under GDPR Article 30 and PIPL Article 21.
Inventory, flows and data elements recorded across three layers, supporting cross-border transfer analysis.
Collection and withdrawal of consent, with source, timestamp and evidence retained.
Contain, remediate, notify the regulator, notify individuals — four actions with a 72-hour countdown and a protected state machine.
DPIA, transfer impact assessment, and vendor assessment.
DataAigis Data Security & Compliance
Governs the data
Where is the data? What is it? How sensitive? Is anything leaving that should not?
DataAigis Privacy & AI Governance
Governs the obligations
Someone asked for their data — now what? Is this processing registered? Did we notify within 72 hours? Was this AI asset approved?
The two are delivered independently and wired together: the data assets and classification produced by DataAigis Data Security & Compliance feed the data map and AI risk assessment here.
IMPLEMENTATION PATH
01
Identify AI assets, use cases, data boundaries, and current ownership.
02
Establish intake, risk tiers, and exception rules appropriate to the enterprise.
03
Configure workflows, permissions, assessment templates, controls, and evidence requirements.
04
Monitor continuously, review changes, track remediation, and report governance outcomes.
Model inventories and risk records are themselves sensitive assets. Today we support a dedicated instance inside your environment with no data leaving it, including local model routing; a containerised one-click package is on the roadmap. The final architecture follows data sensitivity, existing systems, and governance scope.
Discuss your data security, compliance, or enterprise AI objectives with us and define the right implementation priority and next step.
Request a Project Discussion