# Data Compliance Dojo

Whether you’re just getting started or a data master, get a hold on data protection and compliance with curated resources and tools:&#x20;

{% content-ref url="/pages/Zvukm7MAGL6ooitMTmpY" %}
[Data Compliance Dictionary](/dictionary/most-searched-terms)
{% endcontent-ref %}

{% content-ref url="/pages/xWx5E987Vsb4XSf1LqvB" %}
[What is the EU AI Act: The Ultimate Guide](/guides/what-is-the-eu-ai-act-the-ultimate-guide)
{% endcontent-ref %}

{% content-ref url="/pages/5WgUJlYoIaE9AoGhErlD" %}
[Free compliance assessment](/tools/free-compliance-assessment)
{% endcontent-ref %}

{% embed url="<https://www.assenteo.com/>" %}


# The GDPR

### Contents

* [1. What is the GDPR?](#id-1.-what-is-the-gdpr)
* [2. How do I know if GDPR applies to my business?](#id-2.-how-do-i-know-if-gdpr-applies-to-my-business)
* [3. UK Users](#id-3.-uk-users)
* [4. Penalties for GDPR non-compliance](#id-4.-penalties-for-gdpr-non-compliance)

### 1. What is the GDPR?

The **GDPR**, or General Data Protection Regulation, is the key piece of legislation governing the use of **personal data in the EEA** (EU, Iceland, Liechtenstein and Norway). Coming into force in **2018**, the GDPR’s final purpose was to achieve uniform rules for businesses collecting and/or processing users’ personal data.&#x20;

GDPR uses a **principles-based system** to regulate how individuals and organisations process data.&#x20;

These **principles** include:&#x20;

* lawful, fair and transparent processing;
* purpose limitation;
* data minimisation;
* accuracy;
* storage limitation;
* integrity and confidentiality; and&#x20;
* accountability. <br>

The GDPR introduces **some specific obligations** which coax businesses into alignment with these principles. For example, the regulation requires the appointment of a [Data Protection Officer (DPO)](/privacy-professionals-when-do-you-need-them/when-do-you-need-a-dpo) if your business meets certain conditions.&#x20;

However, many compliance mechanisms are left up to the business itself to choose how to implement. This allows businesses **some flexibility** with how they ensure GDPR compliance, but does not remove the need to comply with the data protection principles outlined above as well as the more specific obligations detailed in the legislation.&#x20;

### 2. How do I know if GDPR applies to my business?

In practice, GDPR is relevant to most startups.&#x20;

GDPR is the strictest data protection regulation in the world. Therefore, although it is an EU regulation, compliance with GDPR eases your business’s compliance with US data protection regulations since many compliance mechanisms fulfil both.&#x20;

Due to its multi-jurisdictional application and strictness, GDPR has also become a **golden standard**, often **expected by buyers and users**.

However, your business legally **must** comply with GDPR if:&#x20;

* It has users or employees in the EEA (EU, Iceland, Liechtenstein or Norway)/ UK.
* It actively targets users in the EEA/ UK. This is suggested by elements including:
  * Pricing services or products in the euro, pound or other european currency
  * Translating documents or website pages into a European language
* It monitors the behaviour of people in the EEA/ UK, for example through cookies.

Note that GDPR applies regardless of where your company has a physical presence. Unlike some US data protection regulations, the size or revenue of your business does not affect whether it is subject to GDPR.

Conversely, your business can **more reasonably deprioritise** GDPR compliance if:&#x20;

* It does not have users in the EEA/ UK.
* It does not actively target users in the EEA/ UK
  * It does not price services or products in a European currency.
  * It does not translate its documents or website into a European language.
* It does not monitor the behaviour of people in the EEA/ UK.

However, even in such instances, one-off sign-ups or purchases from EEA or UK residents technically pulls your business into the scope of GDPR. Therefore, most founders who we work with still choose to adopt GDPR-aligned working practices and data flows as a starting point.

### 3. UK Users

When the UK left the EU after Brexit, it adopted the GDPR into its own national law, the UK GDPR. Therefore, if your company processes the personal data of any UK residents, it will also be subject to the **UK GDPR**.&#x20;

In practice, complying with EU GDPR will make your business compliant with UK GDPR in the majority of cases. However, since Brexit, the UK GDPR has been supplemented by the [Data Protection Act 2018](https://www.legislation.gov.uk/ukpga/2018/12/contents) and amended by the [Data (Use and Access) Act 2025](https://www.legislation.gov.uk/ukpga/2025/18/contents) (DUAA). Therefore, it is wise to keep an eye on the differences between these jurisdictions as the reforms of DUAA increasingly take effect.&#x20;

### 4. Penalties for GDPR non-compliance

The penalties for not complying with GDPR are significant.&#x20;

Fines for non-compliance go up to **4% of global turnover** or **€20 million**, whichever is higher.&#x20;

* In line with this, in 2021 Luxembourg’s privacy regulator CNPD, imposed a fine of €746 million on Amazon and, in 2022, France’s regulator CNIL imposed a fine of €150 million on Google.

Penalties also extend beyond regulatory fines. Not complying with GDPR means a **lack of access to the EU market** for your business; you will not be able to sell to EU or EEA citizens.

Public non-compliance can also result in **severe reputational damage** and **loss of trust** for users and investors, due to public coverage of fines or non-compliance.

<br>


# What is data processing?

**Processing** refers to **any operation performed on personal data**. This broad definition covers **collection**, **recording**, **organisation**, even **storage** of personal data.&#x20;

This remains the case whether your business is processing the data of its own employees or external users.&#x20;

Some **examples** of data processing include:&#x20;

* Monitoring behaviour (through cookies & analytics)
* Sending transactional or marketing emails
* Offering products
* Offering services
* Processing the personal data of your business’s own employees
* Storing data (e.g. keeping backups (even if in cold storage))


# Is your business a data controller or a data processor?

### Contents

* [1. What is a data controller?](#id-1.-what-is-a-data-controller)
* [2. What is a data processor?](#id-2.-what-is-a-data-processor)

### 1. What is a data controller?

If your business is **making decisions** about **what** personal data is processed, **why** it is processed, and **how** it is processed, then it is likely a **data controller** under the [GDPR](/key-legislation/the-gdpr).

* For example, if your business runs an app which collects patient symptoms to provide health recommendations, you decide **what** data to collect, **why** to collect it and **how** to collect it. This makes your business a **data controller**.&#x20;

### 2. What is a data processor?

If your business performs operations on personal data **on behalf** of a data controller (who has made the decisions about the whys and hows of that processing), it is a **data processor** under the [GDPR](/key-legislation/the-gdpr).&#x20;

* For example, if hospitals use your platform to store patient records, your business is processing personal data **on their behalf**. This makes your business a **data processor**.&#x20;

In practice, given the broad definition of processing, if your business is a data controller it is likely also a data processor. However, the processor role under the GDPR is really designed to capture a separate entity that processes personal data on the controller’s behalf.

* For example, if your app analyses patient symptoms using a third-party AI system, that AI system provider is working as your data processor.&#x20;

Data processors might also engage third parties to assist with data processing on behalf of the originaln controller. These entities are known as **subprocessors** under the GDPR. [Here](/key-legislation/the-gdpr/subprocessors-and-vendors), we explore the role and obligations of subprocessors and their linked controllers.&#x20;


# How can you implement GDPR data subject rights in your business?

Chapter 3 of **GDPR** sets out certain rights which individuals have over their personal data. They are not principles or guidelines, but **legally enforceable rights** which your business must fulfil if a user or employee chooses to exercise them.&#x20;

The table below lays out the **eight core rights** detailed by GDPR and **how your business can help implement** **them** in day-to-day practice.

<table><thead><tr><th width="207.9921875">Right</th><th>How your business can implement it</th></tr></thead><tbody><tr><td><strong>Right to be informed</strong> [Art. 13, 14&#x26;19]</td><td>• Ensure that your privacy policy is clear, detailed and easily accessible.<br>• In your privacy policy, ensure you explain:<br>• Provide your privacy policy at the point of data collection.<br>• Regularly update your privacy policy to reflect any changes.</td></tr><tr><td><strong>Right of access</strong> [Art. 15]</td><td>• Provide users with an easy mechanism, such as a webform, to request access to their personal data.<br>• Consider implementing DSAR portals for scalable and efficient rights management.<br>• Respond within a month to any DSAR requests.<br>• Keep detailed logs of requests and responses.</td></tr><tr><td><strong>Right to rectification</strong> [Art. 16]</td><td>• Respond to correction requests within a month.<br>• Have procedures for correcting inaccurate personal data and informing sub-processors of any corrections.</td></tr><tr><td><strong>Right to erasure (‘right to be forgotten’)</strong> [Art. 17]</td><td>• Implement processes allowing individuals to request deletion of their data.<br>• Respond within a month to any erasure requests.<br>• Make sure you have systems to identify and remove all data from your platforms and any sub-processor platforms in this instance.</td></tr><tr><td><strong>Right to restriction of processing</strong> [Art. 18]</td><td>• Ensure you have technical mechanisms for temporarily stopping data processing when a data subject requests restriction.</td></tr><tr><td><strong>Right to data portability</strong> [Art. 20]</td><td>• Provide data in a common, machine-readable format upon request, unless technically not feasible.</td></tr><tr><td><strong>Right to object</strong> [Art. 21]</td><td>• Communicate objection rights upfront.<br>• Allow objections to processing based on legitimate interest or public task.<br>• Allow objections to direct marketing.<br>• Implement opt-out systems for making these objections in practice.</td></tr><tr><td><strong>Rights in automated decision making (ADM)</strong> [Art. 22]</td><td>• Notify users if ADM with legal or similarly ‘significant’ effects is taking place. Tell them why, how, and the consequences of the use of ADM.<br>• Require them to consent to ADM before proceeding.<br>• Inform them of the right to human intervention, contestation, and explanation and provide channels to access this.</td></tr></tbody></table>

These are all tasks with which a [**Privacy Partner**](/privacy-professionals-when-do-you-need-them/when-do-you-need-a-privacy-partner) can advise on and assist in setting up.


# Subprocessors and Vendors

### Contents

* [1. What is a subprocessor?](#id-1.-what-is-a-subprocessor)
* [2. What is a vendor?](#id-2.-what-is-a-vendor)
* [3. Disclosing your subprocessors](#id-3.-disclosing-your-subprocessors)
  * [What should you disclose about your subprocessors?](#what-should-you-disclose-about-your-subprocessors)
* [4. Engaging a new subprocessor?](#id-4.-engaging-a-new-subprocessor)
* [5. What can you do today to improve your approach to subprocessors?](#id-5.-what-can-you-do-today-to-improve-your-approach-to-subprocessors)

### 1. What is a subprocessor?

A **subprocessor** is a third party that a data processor engages to help process personal data on behalf of the original data controller.

Imagining your business is an SaaS startup, the data flow might look something like this:

1. Your business collects the name, email address and payment details of a new user. You are the data controller, deciding what data to collect and why (to bill the user).
2. Your business uses a cloud hosting provider to store your users’ personal data. The cloud hosting provider is acting on your instructions and so functions as the data processor.
3. The cloud hosting provider uses various third parties to help deliver its service. For example, it contracts a data monitoring service. This data monitoring service is still processing your business’s users’ personal data, but as a subprocessor. Importantly, your business remains responsible for these subprocessors’ data processing.

You have obligations to carefully monitor the processing activities of your subprocessors.

### 2. What is a vendor?

A vendor is any third party provider which provides goods or services to your business.&#x20;

Vendors which process the personal data for which your business is responsible are also [processors](/key-legislation/the-gdpr/what-is-data-processing)/ [subprocessors](/key-legislation/the-gdpr/subprocessors-and-vendors) under GDPR.

Let us take the use of Motion, for instance. Motion is a vendor that your company may use for internal scheduling.

* If your startup uses Motion for scheduling between team members, it is likely processing personal data such as employee names and email addresses. Your startup is the data controller, Motion is the data processor, and any third party Motion uses to assist with data processing is a **subprocessor** for your startup’s purposes.
* If your startup uses Motion to schedule tasks which do not reference the names or personal data of any individuals, it is simply a **vendor**, not a data processor under GDPR.

### 3. Disclosing your subprocessors

#### Internal disclosure

Your business should keep **careful internal records** of processors and subprocessors linked to the business.

This is for the **purpose** of:

* **Regulatory compliance**
  * If your business decides to process any kind of personal data, it has obligations around ensuring the compliance of entities which help carry out that processing ([processors](/key-legislation/the-gdpr/what-is-data-processing) and [subprocessors](#id-1.-what-is-a-subprocessor)).
    * For example, you must only use processors that provide guarantees to implement certain technical and organisational data protection safeguards.
* **Data location**
  * Your business may contractually only be able to process data in certain jurisdictions in which case it must be particularly attentive to the location of subprocessors.
* **Security**
  * In case of data breaches, it is important to know the subprocessor will inform you within 72 hours of discovery and will cooperate with you on remediation.
  * They must also keep records of the incident which they can disclose to you.
  * These will help you conduct risk assessments and reduce security breach potential.

#### Public disclosure

Your business should also **publicly disclose** details of your processors and subprocessors on your website.

This is for the **purpose** of:

* **Regulatory compliance**
  * [GDPR](/key-legislation/the-gdpr) and other data protection regulations require disclosures of linked subprocessors to employees and users (as data subjects).
* **Trust**
  * Publishing clear records of your subprocessors also constitutes part of your commitment to transparency and helps maintain trust from users and investors.

#### What should you disclose about your subprocessors?

* A list of all subprocessors your company is using to help process customer data and customer personal information
* You should consider also answering the following questions for each subprocessor:
  * In which country does this processing take place?
  * What service does the subprocessor provide? (e.g. email deliverability metrics)
  * What type of data is processed (personal health information, personal information, customer data)
* Confirmation of the typical notice period users can expect before changes to subprocessors and integrations take place (usually 30 to 60 days).

### 4. Engaging a new subprocessor?

You must notify consumers in advance of any changes to the data flows e.g. additions of subprocessors. This is in order to give them the opportunity to object within a time period. If your business has a separate data controller (i.e., an outside party determines the purposes of your business’s processing), you must also inform this controller of any new subprocessors in order to give them the chance to object.<br>

When you engage a new subprocessor, there may be a significant change to the flow of personal data; therefore, you must notify controllers, employees and users before processing begins.<br>

### 5. What can you do today to improve your approach to subprocessors?

* Make sure your business has clear internal records of the processors and subprocessors with access to the employee and user data you collect or process.
* Ensure clear public disclosure of processors and subprocessors on your business’s website for users, investors and other potential stakeholders to consult.
* Investigate appointing a [DPO](/privacy-professionals-when-do-you-need-them/when-do-you-need-a-dpo)/ [Privacy Partner](/privacy-professionals-when-do-you-need-them/when-do-you-need-a-privacy-partner). Having a DPO/ Privacy Partner on board can be really helpful for ensuring regulatory compliance with subprocessor obligations whilst easing the workload for your team.


# The Data (Use and Access) Act

### Contents

* [1. What is the Data (Use and Access) Act?](#id-1.-what-is-the-data-use-and-access-act)
* [2. DUAA's Notable Changes](#id-2.-duaas-notable-changes)
  * [A. Automated Decision Making](#a.-automated-decision-making)
  * [B. Smart Data Schemes](#b.-smart-data-schemes)
  * [C. Research](#c.-research)
  * [D. Legitimate Interests](#d.-legitimate-interests)
  * [E. Digital Verification Services](#e.-digital-verification-services)
  * [F. Data Subject Rights](#f.-data-subject-rights)
  * [G. International Data Transfers](#g.-international-data-transfers)
* [3. What now? Action points for your business](#id-3.-what-now-action-points-for-your-business)

### 1. What is the Data (Use and Access) Act?

**This regulation is applicable if your business has UK users.**

In June 2025, the first major post-Brexit reform in the UK was passed by Parliament: The Data (Use and Access) Act (DUAA). The Act works to amend UK GDPR and the Data Protection Act 2018. The DUAA applies to all companies incorporated within the UK. In addition, it governs organisations incorporated elsewhere that process the personal data of individuals within the UK.

The Act’s purpose is to promote innovation and ease, particularly for SMEs and charities. The hope is to make GDPR feel less risk-ridden to work with through rule clarification and simplification. In tandem, some of the compliance burdens of GDPR are eased to facilitate research and innovation, and to smooth the way for the use of AI.

For AI startups, its provisions are particularly relevant. AI-driven tech, smart data frameworks, digital verification services and cookie compliance are all preoccupations of the Act.

### 2. DUAA's Notable Changes

The DUAA makes notable changes to the laws around:

A. Automated Decision Making (ADM)

B. Smart Data Schemes

C. Qualifying ‘research’ (and accompanying exemptions)

D. Qualifying ‘legitimate interest’

E. Digital Verification

F. Data Subject Rights

G. International Data Transfers

#### A. Automated Decision Making

For tech startups, perhaps the most significant reforms made by the DUAA are those around Automated Decision Making (ADM), where a significant decision about an individual is made solely by automated processing, without meaningful human involvement in that decision.

Under GDPR, business’s use of ADM is tightly restricted. Its use is prohibited in the majority of cases, for instance in recruiting or credit checks.

The DUAA introduces four new articles (22A-D) to replace Article 22 of UK GDPR. These stipulate that:

* ADM is no longer restricted unless ‘special category’ data is being processed.
* This removes the need for one of the three previous conditions (explicit consent; contractual necessity; or authorisation by law) in order to apply ADM in many more cases.
* Certain safeguards are integrated. Data controllers must:
* inform the individual of the automated decision;
* allow individuals to make representations;
* offer the right to seek human intervention; and
* enable them to challenge the decision.

These reforms are likely to allow accelerated deployment of AI-driven products and services. Since the new Act is less strict than GDPR, the ADM reforms could allow for more flexibility for startups that fall under the UK DUAA.

#### B. Smart Data Schemes

The DUAA also introduces an empowering provision which lays the ground for secondary legislation to facilitate ‘smart data schemes’. Looking ahead, we can prepare for how these schemes allow traditional barriers between sectors to become permeable. Initially, it’s targeting financial services, energy, telecoms, transport, retail loyalty programmes and homebuying services, but this will likely develop to include more sectors.

The new framework allows greater intersector portability of personal data and non-personal data (such as usage data and business data). This is great news for SMEs in particular since they can benefit from easier access to business data held by service providers and reduced switching costs - no big tech overheads or overhauls required. There is also plenty of room for new products and services which make the most of this interoperability between sectors.

Open banking illustrates the potential here. By allowing start-ups and non-bank providers access to previously siloed data, open banking not only motivates innovative fintech solutions but gives SMEs more immediate agency over their finances with the ability to aggregate accounts, access real-time insights and streamline payment processes.

#### C. Research

The DUAA also clarifies that ‘scientific research’ may include commercial research. Exemptions can therefore apply to data used in this research. In certain contexts where data is further processed downstream, where providing a notice would involve 'disproportionate effort’, the act permits researchers to not provide transparency info. It also clarifies that individuals can give ‘broad consent’ to the use of their data in an area of scientific research.

#### D. Legitimate Interests

The DUAA gives businesses new lawful bases for processing personal data through clarifying and broadening recognised legitimate interests (LIs). An established list of recognised LIs removes the need for organisations to carry out LI assessments/ balancing tests in many scenarios.

This list includes: intra-group personal data transfers; processing for IT and network security; and public task interests, such as safeguarding, preventing crime and public security and defence.

#### E. Digital Verification Services

The DUAA’s reforms around digital verification services (DVS) ease the way for platforms needing fast, secure verification (during, for example, customer onboarding or security checks). The press release tells us: the reforms will give DVS services ‘the ability to get certified against the government's stringent trust framework of standards, and receive a 'trust mark' to use as a result.' This certification aligns with the UK Digital Identity and Attribute Framework and clearly signals the trustworthiness and compliance of the DVS to any business who uses its services.

#### F. Data Subject Rights

A number of clarifications and changes are introduced in terms of data subject rights. Individuals have the right to complain to a data controller directly, before ICO involvement. The DUAA also heralds a series of new child-specific protections, particularly relevant for any startup working with educational or child-focused tech.

DSARs have also had their timescale relaxed. Businesses may 'stop the clock'. This allows them to pause the one month deadline for responding to a DSAR if they need to await necessary clarifications from the requester. The response period resumes once the required information is provided.

#### G. International Data Transfers

The act establishes a new test for assessing the adequacy of data protection overseas. Rather than requiring that the other jurisdiction’s data protection measures be ‘essentially equivalent’ to UK standards (as is the measure in EU GDPR), the DUAA asks that the other jurisdiction’s protections are ‘not materially lower’ than those of the UK. Accordingly, the Secretary of State has greater discretionary power to determine which countries are adequate for data transfer. The less stringent bar may facilitate more transfers, but also more blacklisting.

Existing transfer mechanisms (standard contractual clauses) remain valid but they are not mandatory if this new test is met. In practice, this means one less contract that parties need to agree on. That said, the DUAA’s reforms show a potential divergence from EU Adequacy rules which begs close attention. Businesses may well want to make sure to align with both GDPRs in order to skirt the fallout of any consequences of UK-EU misalignment here.

Overall, the DUAA introduces relaxing measures which are designed to support innovation and stimulate growth in the startup space. ADM in particular is an exciting and fertile space. Excitement though, as so often, comes with volatility and careful attention to ICO guidelines and parliamentary factsheets as the fresh legislation settles in is certainly worthwhile.

### 3. What now? Action points for your business

* [ ] Explore new areas where ADM could add value such as automating routine decisions.
* [ ] Keep an updated inventory of all existing ADM systems used in your products or services for quick referral and compliance checks.
* [ ] Consider the potential which data sharing schemes could hold in your organisation
* [ ] Explore new products that utilise shared data (e.g. personalised financial advice, market comparisons and automated switching services)
* [ ] Keep an eye on government consultations. This way you can influence policy and move with the market.
* [ ] If your business uses personal data in research and development, it qualifies for research exemptions. Review data processing plans to determine any benefits from the new data protections under the research bracket.
* [ ] Investigate whether your data usage features on the established LI list - if it is covered, streamline or remove the balancing test per DUAA provisions.
* [ ] Keep an eye on changes made to the LI list through secondary legislation
* [ ] Explore the landscape of different DVS providers, considering whether using one would be worthwhile for your business.
* [ ] Fortify a careful, centralised process for handling complaints from individuals. Practically, this could involve an online complaint form. Also perhaps, a process for informing an individual about the trajectory of their complaint.
* [ ] Make sure you have a clear record of how personal data currently crosses borders: intra-group transfers, cloud services, partner relationships etc…
* [ ] Keep an eye on evolving adequacy decisions and ICO guidance
* [ ] Make sure your safeguarding measures are kept up (e.g. human-in-the-loop processes and mechanisms to properly engage with user challenges to data processing/ ADM)
* [ ] Update privacy policies, DPIAs and transparency mechanisms to reflect altered data flows as a result of the above changes.
* [ ] Consider appointing a DPO/ Privacy Partner to assist with the above tasks and ongoing smart privacy protection.


# HIPAA

### Contents

* [1. What is HIPAA?](#id-1.-what-is-hipaa)
* [2. Does HIPAA apply to you?](#id-2.-does-hipaa-apply-to-you)
* [3. What are HIPAA's key provisions?](#id-3.-what-are-hipaas-key-provisions)
* [4. HIPAA compliance checklist](#id-4.-hipaa-compliance-checklist)
* [5. What are the penalties for non-compliance?](#id-5.-what-are-the-penalties-for-non-compliance)
* [6. What counts as Protected Health Information (PHI)?](#id-6.-what-counts-as-protected-health-information-phi)
  * [What determines ‘identifiability’?](#what-determines-identifiability)

### 1. What is HIPAA?

The **Health Insurance Portability and Accountability Act**, or **HIPAA**, was enacted on 21 August 1996, signed by President Bill Clinton. This law sets national standards for protecting the sensitive health information of individuals. It calls this data ‘protected health information’, or ‘PHI’.

HIPAA is largely designed to protect patient privacy, prevent fraud and improve healthcare portability in the US.

The national standards set out in HIPAA are enforced by the Department of Health and Human Services’ Office for Civil Rights (HHS).<br>

### 2. Does HIPAA apply to you?

HIPAA applies to any entity operating in the US which handles protected health information (PHI) in the following contexts:

* Healthcare providers
* Health plans, e.g. insurance companies, health maintenance organisations and government programs such as Medicare.
* Healthcare clearinghouses.
* These are organisations that process nonstandard PHI into standard formats (or the other way around). They often act between healthcare providers and insurers.

It also applies to any third parties that perform services for the entities above involving the use or disclosure of PHI. Under HIPAA, these third parties must sign a Business Associate Agreement (BAA) with the HIPAA-bound healthcare entity. This details how the associated business must also safeguard PHI.

### 3. What are HIPAA's key provisions?

HIPAA operates around **several key rules**:

* **Privacy** rule
  * Standards for how PHI can be used and disclosed
  * Including the ‘minimum necessary standard’. This dictates that PHI must only be used and disclosed to the minimum degree it is needed to achieve the intended purpose.
    * Patient rights, including the right to amend and the right to access
* **Security** rule
  * Details various safeguards which should be implemented to achieve PHI security
* **Transaction and code sets** rule
  * Standards for healthcare information electronic processes (e.g. billing)
* **Enforcement** rule
  * Sets out procedures for investigations and penalties for non-compliance
* **Breach notification** rule
  * Entities must notify affected individuals and organisations (and in certain cases the media) if PHI is compromised/ breached
* **Omnibus** final rule (issued in 2013)
  * Updates and clarifies HIPAA provisions, including implementing HITECH Act provisions and expanding patient rights

### 4. HIPAA compliance checklist

HIPAA compliance can feel like an overwhelming task, but appoint a [Privacy Partner ](/privacy-professionals-when-do-you-need-them/when-do-you-need-a-privacy-partner)and the rest will follow in no time. A [Privacy Partner](/privacy-professionals-when-do-you-need-them/when-do-you-need-a-privacy-partner) will help develop and implement HIPAA compliance procedures.

This includes helping draft and review BAAs and setting up systems which implement a range of administrative, hardware and software safeguards detailed in HIPAA. These safeguards include:

Documentation demonstrating:

* [ ] An ongoing training program educating employees on responsible handling of PHI
* [ ] A clear set of privacy procedures available for government access
* [ ] Checks to ensure that any relevant business associates are also HIPAA compliant
* [ ] A clear contingency plan and protocol for responding to security breaches
* [ ] Frequent and comprehensive audits
* [ ] Careful disposal of PHI-related equipment
* [ ] Monitored access to PHI-related equipment, e.g. visitor sign-ins. Access controls allow PHI access only to those employees who require it to complete their jobs. Documentation of who these employees are.
* [ ] PHI is encrypted in transit and at rest
* [ ] Technical measures and policies to ensure data integrity

### 5. What are the penalties for non-compliance?

Civil penalties of HIPAA non-compliance are tiered by degree of negligence: unknowing violations, reasonable cause, corrected wilful neglect and uncorrected wilful neglect.&#x20;

The minimum and maximum fines vary for each category but can currently reach **up to $2.1 million annually**. However, state attorneys may also assess their own penalties on top of federal ones.

* The HHS imposed a penalty of **$1.19 million** on a Florida pain management clinic for failing to terminate an employee’s access rights at the end of 2024.

**Criminal penalties** range from fines of up to $50,000 for knowingly obtaining or disclosing PHI, to fines of up to $250,000 and imprisonment up to 10 years if the intent was to sell, share or use PHI for personal gain or malicious harm.

Non-compliance, of course, significantly **erodes the trust of your users and investors**. In this sense, there is also a **huge reputational risk**.

### 6. What counts as Protected Health Information (PHI)?

The [Health Insurance Portability and Accountability Act (HIPAA)](https://www.hhs.gov/hipaa/for-professionals/index.html) works to protect individuals’ health data, or **‘protected health information’ (PHI)**. PHI is generally recognised as any individually identifiable health information.

This generally encompasses information regarding:

* Past, present or potential future **health status** (e.g. medical records)
* Healthcare **services accessed** (e.g. communication records)
* **Payment** for healthcare related matters (e.g. billing and insurance information)

Genetic information, demographic information and biometric data are also common examples of PHI.

PHI is PHI regardless of whether it exists in an electronic, paper or spoken format.

#### What determines ‘identifiability’?

Under HIPAA, information is considered ‘identifiable’ if it either directly identifies an individual or if there is reasonable basis to believe it could be traced back to an individual if manipulated and cross-referenced in a certain way.

To qualify as de-identified, information must have been de-identified by one of two methods:

1. **Safe Harbour** (removal of the 18 identifiers)
2. **Expert Determination**

Under the **‘safe harbour’** method, all 18 identifiers listed in the relevant section of the Act must be removed. Among other identifiers, this provision requires names, geographic subdivisions smaller than a state, all elements of dates (except year) related to an individual, phone numbers and emails be removed.

Otherwise, under the **‘expert determination’** method, a qualified expert must determine and document that the risk of any individual being identified from the information is ‘very small’. They must determine and document that this remains the case when the information is used in combination with other reasonably available information.

Unless one of the above requirements has been met, if your company is processing any information connected to an individual’s health, it qualifies as PHI under HIPAA.

<br>


# CCPA

### Contents

* [1. What is CCPA?](#id-1.-what-is-ccpa)
* [2. Does CCPA apply to you?](#id-2.-does-ccpa-apply-to-you)
* [3. What counts as PI?](#id-3.-what-counts-as-pi)
* [4. CCPA data subject rights](#id-4.-ccpa-data-subject-rights)
* [5. What are the penalties for non-compliance?](#id-5.-what-are-the-penalties-for-non-compliance)
* [6. A basic CCPA compliance checklist](#id-6.-a-basic-ccpa-compliance-checklist)

### 1. What is CCPA?

The **California Consumer Privacy Act (CCPA)** is a state privacy law introduced on **1 January 2020**. The Act grants California residents rights over their personal information (PI). In order to do so, it imposes obligations on companies which collect and/or process individuals’ PI.

In comparison to GDPR, the Controller and Processor terminology is replaced by ‘Business’ and ‘Service Provider’. E.g If you collect PI in California to send a newsletter you are the Business and an email sender is the Service Provider.

Users are also referred to as ‘Consumers’.

### 2. Does CCPA apply to you?

To determine if the CCPA applies to your company you must consider:

* Does your company collect the personal information (PI) of California residents OR do business in California?
* Is your company a for-profit business?

Note that, ‘doing business’ should be interpreted broadly; operating a website accessible to California residents or offering goods to Californians is included.

If the answer to both the above questions is yes, your company may be subject to CCPA. You must consider if it meets one or more of the following thresholds:

* Annual gross revenue in excess of $25 million; or
* Processes the personal information of 100,000 or more California residents/ households; or
* Derives 50% or more of annual revenue from selling or sharing personal information<br>

If your business meets any of these criteria, it is subject to CCPA. You must ensure it remains compliant with the requirements of the CCPA in order to avoid severe penalties.<br>

If however, it is not possible to determine if your business meets one of the criteria in Step 2, you should assume CCPA is applicable to your business.

### 3. What counts as PI?

The CCPA understands personal information (PI) to be any information that identifies or can be reasonably linked to a particular individual or household (unless a specific statutory exception applies). It is important to note that information can be PI even if it is not tied to a named individual, but rather to a specific family or residence, understood as a ‘household’.

However, unlike GDPR, information is not considered PI if it is publicly available.

### 4. CCPA data subject rights

Californian consumers have **six key data subject rights** under the CCPA.<br>

These are:

<table><thead><tr><th width="180.42578125">Right</th><th>What it covers</th></tr></thead><tbody><tr><td>Right to <strong>know</strong></td><td><p>Consumers can request disclosure of:</p><ul><li>the PI collected about them, including specific PI</li><li>categories of data sources</li><li>purposes for collecting, processing or sharing PI</li><li>categories of third parties the business shares PI with</li><li>categories of PI disclosed to those third parties.</li></ul></td></tr><tr><td>Right to <strong>delete</strong></td><td>Consumers can request deletion of most PI collected about them, subject to certain exceptions such as legal obligations.</td></tr><tr><td>Right to <strong>opt out of sale or sharing</strong></td><td>Consumers can request that a business stop selling or sharing their PI.</td></tr><tr><td>Right to <strong>non-discrimination</strong></td><td>Consumers cannot be treated differently for choosing to exercise their rights under the CCPA.</td></tr><tr><td>Right to <strong>correct</strong></td><td>Consumers may request correction of inaccurate PI held about them.</td></tr><tr><td>Right to <strong>limit use and sharing of sensitive PI</strong></td><td>Consumers can require businesses to restrict the use and sharing of sensitive PI for limited purposes. Sensitive PI can include precise geolocation, genetic data, or financial account information.</td></tr></tbody></table>

### &#x20;5. What are the penalties for non-compliance?<br>

Fines reach $2,500 for each unintentional violation and up to $7,500 for each intentional violation. However, each affected customer counts as a separate violation, so fines increase rapidly. In 2025, Healthline Media faced a fine of $1.55 million for failing to allow consumers to opt out of targeted advertising and for sharing sensitive health PI with third parties without the protections required under the CCPA.

Significant reputational damage can also occur through CCPA non-compliance; customers and investors may lose trust in your company. Furthermore, if your business chooses not to put in the measures necessary to be CCPA compliant, you risk the loss of business and profits resulting from the lack of access to the Californian market.

### 6. A basic CCPA compliance checklist

**Opt-out Procedures**

* [ ] Framework for informing data subjects before you collect data
  * [ ] Notices explaining privacy practices
  * [ ] Provide an accessible link where customers can opt out

**Consumer Transparency**

* [ ] Publish a comprehensive privacy policy in an accessible location such as on your business website
* [ ] Secure processes (portals/ phone lines) where consumers can easily access, delete or correct PI. Also where they can retroactively opt out of sale.
  * [ ] Including, maintenance of at least two methods for consumers to submit data subject access requests
* [ ] Respond to consumer requests within 45 days
  * [ ] Keep records of these consumer requests for 2 years

**Third Party PI Monitoring**

* [ ] Communicate your business incentives for sharing consumer PI with third parties
* [ ] Make sure that contracts with third parties require them to also comply with CCPA

**Appointing a** [**Privacy Partner**](/privacy-professionals-when-do-you-need-them/when-do-you-need-a-privacy-partner)

* [ ] Assists with all of the above and more.


# GDPR vs. CCPA

### Contents

* [Key differences](#key-differences)
* [Comparison table](#comparison-table)

### Key differences

* The [GDPR](/key-legislation/the-gdpr) also **applies to individuals** who process data, whereas the [CCPA](/key-legislation/ccpa) only applies to for-profit businesses.
* The [GDPR](/key-legislation/the-gdpr) is **stricter** and has far greater penalties for non-compliance
* The [GDPR](/key-legislation/the-gdpr) **requires consumers to consent** to their personal data being used **at the time**, whereas the [CCPA](/key-legislation/ccpa) informs consumers how their personal data has been used for business purposes retroactively.

### Comparison table

|                                                             | GDPR                                                                                                                                                                                                                                           | CCPA                                                                                                                                                                                                                                                                                                                                                                                     |
| ----------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Primary regulator**                                       | European Data Protection Board (EDPB)                                                                                                                                                                                                          | California Privacy Protection Agency (CPPA)                                                                                                                                                                                                                                                                                                                                              |
| **Data subjects**                                           | EU residents                                                                                                                                                                                                                                   | California Residents                                                                                                                                                                                                                                                                                                                                                                     |
| **Who must comply?**                                        | <p>Any business or individual handling the data of EU residents.</p><p><br></p><p>The business may be incorporated outside the EU.</p>                                                                                                         | <p>For-profit businesses trading in California which either:</p><ul><li>Have gross annual revenue in excess of $25 million; OR</li><li>Buy, sell, or share the PI of 100,000 or more California residents/ households; OR</li><li>Derive 50% or more of their annual revenue from selling California residents’ PI.</li></ul><p>The business may be incorporated outside California.</p> |
| **How is ‘personal data’/ ‘personal information’ defined?** | <p>Personal data:</p><p><br></p><p>“Any information relating to an identified or identifiable natural person (‘data subject’)” (GDPR)</p>                                                                                                      | <p>Personal information:</p><p><br></p><p>“Information that identifies, relates to, or could reasonably be linked with you or your household.” (CCPA)</p><p><br></p><p>It does not include publicly available information.</p>                                                                                                                                                           |
| **How is ‘sensitive’ personal data/ information’ defined?** | <p>Full list in legislation</p><p><br></p><p>Includes genetic, biometric and health data, as well as personal data revealing racial and ethnic origin, political opinions, religious or ideological convictions or trade union membership.</p> | <p>Full list in legislation.</p><p><br></p><p>Includes certain government identifiers (such as social security numbers)’ and contents of mail, email, and text messages.</p>                                                                                                                                                                                                             |
| **Approach to consent**                                     | Opt-in system                                                                                                                                                                                                                                  | Opt-out system                                                                                                                                                                                                                                                                                                                                                                           |
| **Penalties**                                               | Up to €20 million or 4% of global annual turnover                                                                                                                                                                                              | <p>Up to $2,500 per violation; and $7,500 per ‘intentional’ violation.</p><p><br></p><p>private rights of action for consumers with damages $100-$750 per incident</p>                                                                                                                                                                                                                   |
| **Enforcement agencies**                                    | National data protection authorities (DPAs) in each EU member state                                                                                                                                                                            | California Privacy Protection Agency (CPPA) and California Attorney General (CAG)                                                                                                                                                                                                                                                                                                        |

<br>


# User Rights Cheat Sheet

User rights (both Data Subject and Consumer rights) vary across jurisdictions and how you can think about effective ways to ensure compliance.

A more specific comparison of the GDPR and the CCPA can be found [here](/key-legislation/gdpr-vs.-ccpa).

### 1. Key legislation/ frameworks to know

Although by no means an exhaustive list of the legislation and frameworks governing user rights, below you can find a useful overview of some of the most likely to crop up when considering your business’s data protection regimes.

#### If your users are in Europe:

| Jurisdiction(s) | Regulation                                    | This regulation applies to you if you are …                                                                                                                                                                                                                                                                   | Core data subject rights                                                                                                                                                                                                                                                                                                                                                                                                           |
| --------------- | --------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **EU and EEA**  | **General Data Protection Regulation (GDPR)** | <p>An organisation or individual established in the EEA/ EU processing any personal data; or</p><p>An organisation or individual established outside the EEA/ EU that</p><p>(a) offers goods or services to individuals in the EEA/ EU; or</p><p>(b) monitors the behaviour of individuals in the EEA/EU.</p> | <ul><li>the right to be informed \[Art. 13, 14&19]</li><li>the right of access \[Art. 15]</li><li>the right to rectification \[Art. 16]</li><li>the right to erasure (‘right to be forgotten’) \[Art. 17]</li><li>the right to restriction of processing \[Art. 18]</li><li>the right to data portability \[Art. 20]</li><li>the right to object \[Art. 21]</li><li>Rights in automated decision making (ADM) \[Art. 22]</li></ul> |
| **UK**          | **UK GDPR**                                   | <p>An organisation or individual established in the UK processing any personal data; Or</p><p>An organisation or individual established outside the UK that</p><p>(a) offers goods or services to individuals in the UK; or</p><p>(b) monitors the behaviour of individuals in the UK.</p>                    | <p>The core data subject rights in the UK GDPR are very similar to those of the EU GDPR.</p><p>A notable difference is the amendment made to rights in automated decision making in art. 22 UK GDPR, in comparison to GDPR, permitting automated decisions except if on sensitive data.</p>                                                                                                                                        |
|                 | **The Data Protection Act 2018**              | The same as above.                                                                                                                                                                                                                                                                                            | <p>Allows certain exemptions to</p><ul><li>the right of access for law enforcement purposes</li><li>the right of rectification for law enforcement purposes and research integrity purposes</li><li>the right to erasure for purposes including freedom of expression, research, law enforcement and legal claims</li></ul>                                                                                                        |

#### If your customers are in the US:

It is a misconception that there is almost no data protection framework in the US. A patchwork of state laws lies across the US. Since state laws vary across the US, as a business, it is important to be aware of which states you are operating in and the various demands of specific states’ legislation.

Three particularly relevant state regulations are those in **California**, **Virginia** and **New York State**.

| Jurisdiction(s)    | Regulation                                                       | This regulation applies to you if you are …                                                                                                                                                                                                                                                                                                                                                               | Core data subject rights                                                                                                                                                                                                                                                                                                                                                                                                       |
| ------------------ | ---------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **California**     | **California Consumer Privacy Act (CCPA)**                       | <p>A for-profit business that:</p><ul><li>collects the personal information (PI) of California residents</li></ul><p>AND</p><ul><li>meets certain thresholds (e.g. revenue over $25 million; or data on 100K+ consumers; or 50%+ revenue from selling data.)</li></ul>                                                                                                                                    | <ul><li>the right to delete personal information (PI)</li><li>the right to correct inaccurate PI</li><li>the right to know what PI is being collected, sold, shared and to whom</li><li>the right to access PI</li><li>the right to opt out of sale or sharing of PI</li><li>the right to limit use and disclosure of sensitive PI</li><li>the right to no retaliation following opt out or exercise of other rights</li></ul> |
| **Virginia**       | **Virginia Consumer Data Protection Act (VCDPA)**                | <p>A for-profit business that:</p><ul><li>conducts business in Virginia; Or</li><li>targets Virginia residents</li></ul><p>AND</p><ul><li>controls or processes personal information of at least 100,000 consumers in a calendar year; Or</li><li>controls or processes personal information of at least 25,000 consumers and derives over 50% of gross revenue from the sale of personal data.</li></ul> | <p>Similar to the CCPA.</p><p>With the addition of a more explicit:</p><ul><li>right to data portability</li></ul>                                                                                                                                                                                                                                                                                                             |
| **New York State** | <p>SHIELD Act</p><p><strong>Proposed NY Privacy Act</strong></p> | A person or business that owns or licences the personal information of New York residents.                                                                                                                                                                                                                                                                                                                | <p>No formal data subject rights as there are in the GDPR, CCPA and VCDPA. The act focuses on data security and breach notification</p><ul><li>Requires businesses to implement reasonable safeguards for personal information</li><li>Mandates breach notification procedures</li><li>More data subject rights, similar to the CCPA, are proposed in the pending NY Privacy Act.</li></ul>                                    |

#### If your customers are in the Asia-Pacific Region:

| Scope                 | Framework              | This framework applies to you if you are …                                                                                                                                                                                                           | Core data subject rights                                                                                                                                                                        |
| --------------------- | ---------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| APEC member economies | APEC Privacy Framework | <p>A business operating in the Asia-Pacific region.</p><p>The framework is not legally binding, but many countries (including Australia, Japan, China) have incorporated its principles into their national privacy laws, which are enforceable.</p> | <p>Non binding principles promoting:</p><ul><li>the right to be informed</li><li>the right of access</li><li>the right to rectification</li><li>the right to limit use and disclosure</li></ul> |

### 2. GDPR as the standard?

Whilst national laws vary in scope and enforcement, many take inspiration from the data subject rights set out in the GDPR. Since the GDPR is currently the strictest data protection regulation in the world, complying with its provisions can be a straightforward way to facilitate international compliance. With secure GDPR compliance, your personal data processing is likely to be compliant wherever your data subjects reside.


# Sensitive Data Collection

### Is your business collecting sensitive data?

Certain types of data afford special protections under data protection legislation such as the GDPR, HIPAA, FERPA and COPPA.&#x20;

If your business collects health data or children’s data it is very likely to be subject to additional legal obligations.&#x20;

Data about racial or ethnic origins, political opinions, religious or philosophical beliefs, genetics, biometrics and sex life or sexual orientation also hold additional protections under the GDPR. Careful attention to these is necessary in order to maintain regulatory compliance and avoid penalties.&#x20;

### Why does this matter?

The principles of GDPR apply significantly more strictly if your business is processing sensitive data, or ‘special category data’. There are also more limited grounds for the legal processing of special category data. For example, it is far more likely your business will need to get explicit consent from your user before it processes their data if that data is special category data. It is a good idea to seek advice from your DPO or a Privacy Partner before performing any action on the personal data of your users. <br>

Non-compliance also presents financial ramifications. For example, if you collect special category data in the EEA and your business without additional technical and organisational safeguards for special category data, it could be fined up to €20 million, or 4% of worldwide annual turnover (whichever is higher). For example, in the Netherlands in 2024, Clearview AI was fined €30.5 million for unlawfully collecting and processing biometric data without explicit consent. Penalties can also include a ban on processing, regular data protection audits and liability damages to affected users.&#x20;

<br>


# Health Data

If your business is processing **health data**, it is processing sensitive data which carries additional compliance obligations across the globe.&#x20;

For example, health data is understood as ‘special category data’ by [GDPR](/key-legislation/the-gdpr), and as ‘protected health information’ collected by covered entities (healthcare providers who transmit data electronically) by the [HIPAA](/key-legislation/hipaa) in the US.&#x20;

Different, often stricter, obligations apply to the processing of health data than to other forms of personal data under these regulations.&#x20;

Your business must take care to process this health data in accordance with the relevant legislation in order to protect its trustworthiness and avoid significant financial penalties.


# Children's Data

**Children’s data** is treated differently in some jurisdictions.&#x20;

For example, in the US, FERPA applies to educational records of students under 18, giving parents the right to access and control those records. Similarly, COPPA (the Children’s Online Privacy Protection Act) requires online services directed at children under 13 in the US to obtain parental consent before collecting their personal information. Moreover, the DUAA amends UK GDPR to require that where services are likely to be accessed by children, businesses (as data controllers) must implement stronger data ‘by design and by default’ mechanisms.

Therefore, if your business processes children’s data you must perform additional checks to ensure compliance with the regulations in your jurisdiction.&#x20;

<br>


# Other Sensitive Data

[**Health**](/sensitive-and-large-scale-data-processing/sensitive-data-collection/health-data) and [**children’s data** ](/sensitive-and-large-scale-data-processing/sensitive-data-collection/childrens-data)are not the only type of data to which special obligations apply.&#x20;

Under **Article 9** [**GDPR**](/key-legislation/the-gdpr), the following categories of data also receive special protections:&#x20;

* racial or ethnic origin data;
* political opinions data;
* religious or philosophical beliefs data;
* genetic data;
* biometric data; and
* sex life or sexual orientation data.


# Large Scale Data Collection

### Contents

* [1. What is large-scale data collection?](#id-1.-what-is-large-scale-data-collection)
* [2. Requirements for large-scale data collection](#id-2.-requirements-for-large-scale-data-collection)

### 1. What is large-scale data collection?

Certain data protection requirements only apply if your business collects data on a ‘large scale’.

Unlike the numerical thresholds set in some US data regulations, the [GDPR](/key-legislation/the-gdpr) does not set out a particular threshold for when processing becomes ‘large scale’. Rather, it is assessed based on several factors. These include:&#x20;

* the **number** of data subjects concerned (although no number is given);
* the **variety** of data;&#x20;
* the **duration** of the processing; and
* &#x20;the **geographical spread** of the processing.

Based on suggestions from regulators (such as the ICO) and what we see in practice, the following categories are **common** **examples** of large scale processing:

* hospitals;
* insurance companies;
* banks;
* AI infrastructure companies; and
* businesses tracking individuals’ real-time locations.

### 2. Requirements for large-scale data collection

1. **DPO:** If your business conducts ‘large scale’ sensitive data collection or ‘large scale’ regular and systematic monitoring of customers, it is required (under the GDPR) to engage a [DPO](/privacy-professionals-when-do-you-need-them/when-do-you-need-a-dpo).
2. **DPIA:** Separately, where your business is deemed to be engaging in high-risk data processing, it must complete a data protection impact assessment (DPIA) before that processing begins. A [DPO](/privacy-professionals-when-do-you-need-them/when-do-you-need-a-privacy-partner) will help your business determine if a DPIA is necessary in your individual case.

<br>


# When do you need a DPO?

Your company may need to appoint a [DPO, or Data Protection Officer](https://docs.assenteo.com/dictionary/dpo), to be compliant with data protection laws.&#x20;

The term ‘DPO’ derives from the [General Data Protection Regulation](https://docs.assenteo.com/dictionary/gdpr) (GDPR). Under the GDPR, a registered DPO is likely mandatory if your company targets users in the EU (under the GDPR, referred to as ‘Data Subjects’) and is one of the following:&#x20;

* A business collecting sensitive user data on a ‘large-scale’
* Monitoring individuals through measures such as online tracking or location collection on a ‘large-scale’
* A public authority or body

Under GDPR, a DPO is independent, and acts as:

* a public point of contact for the European Commission in case of complaint
* a public point of contact for users to communicate with; and
* an advisor identifying privacy and data handling gaps in your business

### Penalties

If your business does not appoint a DPO when it should have, it may incur penalties for not fulfilling administrative duties. These penalties can include fines of up to €10 million or 2% of global annual turnover (whichever is higher).

## What does an Assenteo DPO do?

At Assenteo, your DPO will work simultaneously as:

* the external contact point for data protection authorities
* the external contact point for customers
* an advisor to your C-suite on data protection.&#x20;

\
Assenteo provides an independent DPO as a virtual DPO (vDPO) service.  A vDPO is a more streamlined service than having an in-house DPO, while meeting your obligations under GDPR.  Rather than hiring a full time DPO, a vDPO provides you with a contact for authorities and external data questions and meets your DPO requirement. Your vDPO will also be available for advisory calls as well as available via email and Slack. As a point of contact for your C-suite, your DPO will advise your company on how to collect and process the data of your internal team and employees, as well as of your customers.&#x20;

DPOs act from the position of protecting data subjects interests under data protection laws, so their work is more risk identification and mitigation based. If you need someone to help you both protect and enable your business an Assenteo Privacy Partner may be a better fit.<br>

{% embed url="<https://www.assenteo.com/>" %}

***


# When do you need an EU/ UK Representative?

### What is an EU/ UK Representative?&#x20;

If your business targets consumers in the EU or UK but does not have a business entity there, you must appoint an EU or UK representative. This representative will serve as a local point of contact for both data subjects and supervisory authorities. The same individual can (and most often does) act as both your company’s DPO and your company’s EU/ UK representative.&#x20;

In practice, this means that it should be possible for data protection authorities and customers to be able to get in touch with the EU/ UK representative to discuss any concerns around data processing. This is most often facilitated through providing an email to the EU/ UK representative.

Where a DPO acts as an advisor identifying privacy and data handling gaps in your business, an EU/ UK Representative only acts as a contact point.

Assenteo is able to provide your business with an EU/ UK Representative who also acts as a DPO, or only acts as a Representative, depending on your needs.

### Penalties

Not appointing an EU Representative when you are supposed to is regarded as an infringement of administrative obligations under GDPR. This can carry fines of up to €10 million or 2% of your business’s annual turnover (whichever is higher).

<br>

{% embed url="<https://www.assenteo.com/>" %}

***


# When do you need a Privacy Partner?

[#id-1.-what-is-a-privacy-partner](#id-1.-what-is-a-privacy-partner "mention")

[#id-2.-when-do-you-need-a-privacy-partner](#id-2.-when-do-you-need-a-privacy-partner "mention")

[#id-3.-what-does-an-assenteo-privacy-partner-do](#id-3.-what-does-an-assenteo-privacy-partner-do "mention")

[#id-4.-privacy-partner-in-action-upheal](#id-4.-privacy-partner-in-action-upheal "mention")

### 1. What is a Privacy Partner?&#x20;

At Assenteo, we use the term **Privacy Partner** to describe the professional who can support all your data protection and compliance needs, beyond those needs which fall within the typical remit of a DPO.

Under GDPR, DPOs must maintain independence from your business and focus on protecting European user interests (and thereby ensuring your business’ GDPR compliance).&#x20;

Privacy Partners do this essential work but also focus on **your business’ commercial interests**. They put your commercial interests into an optimal balance with data subject rights, ensuring compliance is matched by competitiveness.&#x20;

While a DPO is primarily a risk management role, a Privacy Partner encompasses both **risk management** and **business enablement**. Assenteo's Privacy Partner can fulfil both functions. However, since a DPO must remain independent from the business, we have built strong safeguards to keep these two functions distinct. In practice, your Privacy Partner will know when to wear their "DPO hat" and when to wear their "Privacy Partner hat."

With a Privacy Partner onboard, privacy compliance is matched by privacy as strategy.

#### <mark style="background-color:$primary;">**Risk management**</mark>

Taking on the role of a **DPO**.&#x20;

For example:&#x20;

* Acting as public **point of contact** for the European Commission in case of complaint.
* Acting as a public point of contact for users to communicate with.
* Advising on internal company compliance, e.g. **handling employee data.**
* Advising on product compliance, e.g. **handling user data**.&#x20;
* Ensuring data compliance reaches across relevant jurisdictions (including CCPA and other US data protection regulations).

#### &#x20;<mark style="background-color:$primary;">Business enablement</mark>

This is the part of the role which ensures **compliance is matched by competitiveness.**

* Ensuring that compliance is ongoing and **efficient** (e.g. integrating privacy into product design, monitoring vendor agreements and handling any incidents)
* Navigating grey areas in the regulation smartly.&#x20;
* Helping your company secure new business by **signalling trust i**n sales processes.
* Much more …<br>

### 2. When do you need a Privacy Partner?

A Privacy Partner helps your business with ongoing privacy steering, product privacy integration, vendor governance and drafting privacy documents, a valuable service which moves beyond the contact-point role of the DPO. In this way, a Privacy Partner helps you build a product which signals trustworthiness to current users, prospective users and stakeholders. A Privacy Partner also takes on much of the compliance work, easing day-to-day management and freeing you up to focus on business growth.

\
A Privacy Partner is not a GDPR mandated role in the same way as that of a DPO or EU/ UK Representative. Therefore, your business does not legally need a Privacy Partner in the same way it might a DPO or an EU/ UK Representative. However, appointing a Privacy Partner can be a huge asset, facilitating a better balance of risk management and company enablement. This, in turn, improves business efficiency and scalability.&#x20;

Further details of the services offered by an Assenteo Privacy Partner can be found here.

### 3. What does an Assenteo Privacy Partner do?

#### **Ongoing Privacy Steering**&#x20;

* Answer slack questions on HIPAA, FERPA, consent, tracking, etc.
* Interpreting law changes and translating into action
* Judgment calls on edge cases&#x20;
* Data incident handling and notification decisions

#### Product and Feature Privacy Integration

* Working with product teams on new features before release
* Running privacy assessments as part of product lifecycle
* Identifying privacy risks early
* Identifying privacy opportunities (trust signals, better design)

#### &#x20;Vendor and Tool Governance

* Vendor security assessments
* Reviewing new tools
* Data tracking/ cookie setup

#### Document and Policy Engine

* DPIAs, ROPAs, DPAs
* Privacy policy updates as product evolves
* Internal policies
* Playbooks for handling incoming DPAs

#### Incident, Regulator and Customer Handling

* Data Incidents
* Regulatory responses
* SPA redlines
* Customer privacy questionnaires
* Protecting the company from over-committing

### 4. Privacy Partner in Action: Upheal

Upheal is an AI-powered automated clinical note-taking platform which serves US mental health providers. You can see the details of [Assenteo’s work with Upheal](https://www.assenteo.com/upheal) for further insight into how a Privacy Partner has helped a real business with simultaneous risk management and company enablement.&#x20;

{% embed url="<https://www.assenteo.com/>" %}

***


# DPO vs. Privacy Partner

<table data-header-hidden><thead><tr><th width="133.58203125"></th><th>DPO</th><th>Privacy Partner</th></tr></thead><tbody><tr><td></td><td><strong>Data Protection Officer (DPO)</strong></td><td><strong>Privacy Partner</strong></td></tr><tr><td><strong>Jurisdictional focus</strong></td><td>EEA and the UK.</td><td>All jurisdictions.</td></tr><tr><td><strong>End goal</strong></td><td><p>Risk monitoring.</p><p><br><br></p></td><td><p>Risk monitoring and business enablement.</p><p><br><br></p></td></tr><tr><td><strong>Interests</strong></td><td><p>Data subject interests.</p><p><br></p></td><td>Balancing data subject interests with commercial interests.</td></tr></tbody></table>

{% embed url="<https://www.assenteo.com/>" %}

***


# How should you name your DPO or Privacy Partner?

[#id-1.-where-should-you-disclose-your-dpo](#id-1.-where-should-you-disclose-your-dpo "mention")

[#id-2.-why-should-you-disclose-your-dpo](#id-2.-why-should-you-disclose-your-dpo "mention")

[#id-3.-what-should-you-disclose-about-your-dpo](#id-3.-what-should-you-disclose-about-your-dpo "mention")

[#id-4.-does-this-change-in-the-case-of-other-types-of-privacy-professionals](#id-4.-does-this-change-in-the-case-of-other-types-of-privacy-professionals "mention")

### 1. Where should you disclose your DPO?

Once you appoint a DPO, it is important to disclose their name and contact details. The process is relatively simple but important to get right to avoid confusion and regulatory penalties.&#x20;

You should disclose your DPO:&#x20;

* In **internal company records**
  * This is a requirement under Article 30(1) of the GDPR&#x20;
* In a **letter to your national supervisory body**
  * Someone - oftentimes the DPO themselves - must inform the relevant supervisory authority (e.g. the UK Commission in the UK) of the DPO’s appointment and details.
  * There isn’t an official public register of companies and DPOs. Therefore, it is essential that the company/ company DPO gets in touch with the supervisory board via email.&#x20;
  * Some member states have specific forms you must submit.&#x20;
* In your **privacy policy** and **terms and conditions.**

### 2. Why should you disclose your DPO?

Beyond it being **mandatory under GDPR**, disclosing information about your DPO demonstrates ready compliance with data protection practices to your consumers and potential investors. The UK Information Commissioner’s Office (ICO) notes, appointing a DPO is ‘a vehicle for you to build compliance as a long-term sustainable activity across your business’. Therefore, disclosing information about your DPO helps showcase your business’ commitment to consistent, trustworthy data compliance measures, or ‘long-term sustainable activity’. <br>

Moreover, Article 24(1) of the UK GDPR states that ‘the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation’. Appointing a DPO is a useful example of one such ‘technical and organisational measure’.&#x20;

### 3. What should you disclose about your DPO?&#x20;

In **internal company records** and your letter to your supervisory authority, your business should disclose the following information about your DPO:

* DPO’s name
* (if applicable) Company name
* Contact details (normally company address and email)
* (If applicable) Address of the DPO’s company

\
Your **public disclosure** (e.g. in privacy policy) can be a little less specific:

* Can be role based. e.g. simply ‘Data Protection Office rather than their full legal name
* Can be anonymised contact details - <dpo@x.com>
* Address of the DPO’s company

### 4. Does this change in the case of other types of privacy professionals?&#x20;

While the regulatory guidance around DPOs is relatively established, the same clarity does not exist for other types of compliance leads such as privacy partners and AI compliance leads.<br>

Nevertheless, the DPO regulatory guidance might be taken as a model for privacy partners and AI compliance leads whilst regulation and guidance on AI compliance leads continues to find its feet. Communicating the existence of your AI compliance lead and/ or privacy partner clearly on your website and in company records signals a **commitment to transparency** and thoughtful innovation to your customer base and potential investors. Communication of the effort and thought your business has invested in data compliance **invites trust** and trust invites growth. <br>

{% embed url="<https://www.assenteo.com/>" %}

***


# Free compliance assessment

Is Your Company a Data Protection Pioneer?

In today’s digital world, data protection isn’t just about compliance - it’s a competitive edge. Yet, many companies overlook its impact on sales, customer trust, and product capabilities.

That’s where [Assenteo](https://www.assenteo.com/) comes in. **We offer a free data protection assessment** to help you understand where your company stands.&#x20;

## Why does compliance matter?&#x20;

* In some industries, **compliance is mandatory**. But even where it’s not, strong data compliance can:&#x20;
  * accelerate sales cycles
  * improve customer confidence, and&#x20;
  * enhance your product’s market appeal.
* Forward-thinking businesses use data protection as a **selling point** to differentiate themselves from competitors.

We provide a complimentary data protection screening - a customized report showing exactly how compliance can support your growth and position you as a leader in your industry.

&#x20;

**Sound like the tool you need? Get your** [**free assessment today her**](https://www.assenteo.com/)[**e**](https://www.assenteo.com/)**.**&#x20;

{% embed url="<https://www.assenteo.com/>" %}

***


# What is the EU AI Act: The Ultimate Guide

Does your startup rely on LLMs or NLP? The European Parliament has officially approved the European AI Act, and the Law came into force in 2024.

This is a living guide to help you navigate and learn more about the EU AI Act. \
\
[#id-1.-how-did-the-eu-ai-act-come-to-be](#id-1.-how-did-the-eu-ai-act-come-to-be "mention")\
[#id-2.-what-is-classified-as-an-ai-system-under-the-act](#id-2.-what-is-classified-as-an-ai-system-under-the-act "mention")\
[#id-3.-how-does-the-eu-ai-act-work](#id-3.-how-does-the-eu-ai-act-work "mention")\
[#id-4.-which-sections-of-the-ai-act-are-currently-in-force](#id-4.-which-sections-of-the-ai-act-are-currently-in-force "mention")\
[#id-5.-what-is-the-timeline-for-enforcement-of-other-sections-of-the-ai-act](#id-5.-what-is-the-timeline-for-enforcement-of-other-sections-of-the-ai-act "mention")\
[#id-6.-what-does-this-mean-for-companies](#id-6.-what-does-this-mean-for-companies "mention")

{% hint style="info" %}
**Looking to find out if the EU AI Act applies to your company?** Get your [free assessment her](https://www.assenteo.com/)[e](https://www.assenteo.com/). &#x20;
{% endhint %}

## 1. How did the EU AI Act come to be?&#x20;

In response to the potential of advancements in how AI-driven technologies will be used, the European Commission shared recommendations through whitepapers. Most notably in 2020, a white paper on trustworthy AI was released by the Euorpean Commission, \
\
In April 2021, the European Commission published a [legal framework on artificial intelligence](https://digital-strategy.ec.europa.eu/en/library/proposal-regulation-european-approach-artificial-intelligence) plus a [coordinated plan with member states](https://digital-strategy.ec.europa.eu/en/library/coordinated-plan-artificial-intelligence-2021-review) to implement it.  Subsequently, in 2023, likely in response to the popularity of models such as GPT-3, the European Parliament officially approved the text of the European AI Act based on this framework.&#x20;

The Law then begun enforcement in 2024.

## 2. What is classified as an AI System under the Act?&#x20;

Under the framework, the definition of Artificial Intelligence is reduced to an 'AI System'. This is defined as:

> a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.&#x20;
>
> [Article 3(1) ](https://artificialintelligenceact.eu/article/3/)

#### Let's break it down:&#x20;

#### a. Machine based system

The system is machine run, basing decisions on clearly defined goals set by the maker or deployer.

#### b. operates with levels of autonomy&#x20;

AI systems covered by the act include systems of varying levels of independence. AI systems that function independently fully or partially, and perform tasks with or without direct human intervention are included.

#### c. adapts after deployment&#x20;

The AI must continues to improve how and what outputs are generated based on the system's learning capabilities.

#### d.  infers how to generate outputs&#x20;

AI systems covered by the Act use techniques that enable inference during their development. \
\
These include logic/knowledge-based approaches, which derive conclusions from inputs.&#x20;

Unlike basic data processors, AI systems can learn, reason, and model complex scenarios, enhancing their decision-making capabilities.

#### e. that can influence physical or virtual environments&#x20;

In the Act, "environments" refer to the context where AI systems operate. This differs to "outputs" which are the results the AI systems produce, such as predictions, content, recommendations, or decisions.

This definition covers a number of different use cases of LLMs, and addresses the techniques to develop and build AI (machine learning models, logic based approaches and statistical approaches).&#x20;

## 3. How does the EU AI Act work?&#x20;

Now we've addressed who the EU AI Act is designed to regulate, how has t determine the level of regulation of AI products and companies?&#x20;

### A risk based approach&#x20;

> “The new AI regulation will make sure that Europeans can trust what AI has to offer. Proportionate and flexible rules will address the specific risks posed by AI systems and set the highest standard worldwide”
>
> [The European Commission Press Release](https://ec.europa.eu/commission/presscorner/detail/en/ip_21_1682)

The framework proposes a risk-based model, with a different level of protection depending on the potential risk level of an AI’s usage.&#x20;

Under the regulation, AI is categorised into four different categories:&#x20;

* prohibited
* high
* limited and,&#x20;
* minimal risk

#### Prohibited AI systems

At the top of the scale, any AI that is seen as a threat to human life, rights or wellbeing will be considered an unacceptable risk and therefore **banned**. This includes:&#x20;

1. **Manipulative or deceptive techniques**: Prohibited if they distort behavior, impair informed decision-making, and cause significant harm. &#x20;
2. **Exploiting vulnerabilities**: Banned when related to age, disability, or socio-economic circumstances and results in significant harm. &#x20;
3. **Biometric categorization**: Restricted for inferring sensitive attributes like race, religion, or sexual orientation, except in specific lawful cases. &#x20;
4. **Social scoring**: Prohibited if it evaluates individuals based on behavior or traits, causing unfavorable treatment. &#x20;
5. **Criminal risk profiling**: Banned when solely based on profiling or personality traits, except as part of verifiable, fact-based assessments linked to criminal activity. &#x20;
6. **Facial recognition databases**: Prohibited if created via un-targeted scraping of online or CCTV facial images. &#x20;
7. **Emotion detection**: Restricted in workplaces or educational settings, except for medical or safety purposes.  <br>

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXffDoElxi-7bGUKij8pGOSMgw2aKTxRy4T7WCmNONU582-P4YqwhjDD0uH9zIru8OWRfmYOOBa4hrzwoojRHtAyNPq3Jb8eBJOCFZf7R3plKuV5XtPKiJLRuqerHzoNaa51NceMBg?key=1nqQ6hkKKFXFL8R-DaohKtK9" alt=""><figcaption><p>Remember this episode of Black Mirror? Like in Black Mirror where people rated each other, using AI enabled social scoring (on a government level) which may affect the livelihood of individuals is now considered an ‘unacceptable risk’ and is prohibited.</p></figcaption></figure>

#### High-risk AI

High risk AI is then categorized as AI used in less risky but still vital systems.&#x20;

The list features industries where the safety of the software is vital, including critical infrastructures, healthcare robots. It also includes  where the incorrect outcome or lack of transparency would be unfair or unjust, including law enforcement, employment, migration and private and public services.&#x20;

If a product utilises a high risk AI, it will be subject to risk assessments, documentation and even human oversight before being released to the public. The prohibited and high-risk categories in particular agree with the European Commission’s previous guidelines on trustworthy AI, where it was proposed AI needs to be[ lawful, ethical and robust. ](https://digital-strategy.ec.europa.eu/en/library/ethics-guidelines-trustworthy-ai)

#### Limited-risk AI

The use of AI which isn’t as hazardous has a lower threshold of oversight.&#x20;

Limited risk then covers AI which is used in products and services such as chatbots and requires transparency that AI is used.&#x20;

#### Minimal risk&#x20;

Any other products are considered to be in the minimal risk category, with the example of AI-enabled video games or spam filters given by the European Commission.&#x20;

## 4. Which sections of the AI Act are currently in force? &#x20;

The EU AI Act came into force on August 1, 2024 however implementation is in stages.&#x20;

### AI Act sections currently in force

* **(From February 2025) AI literacy:** Providers and deployers of AI systems should be educating individuals in their team who operate their AI systems. This includes training their team to understand how AI works,  the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used.
* **(From February 2025)  Prohibited systems:** The prohibited AI systems are banned.&#x20;

{% hint style="info" %}
Unsure if your company needs to go through AI Literacy training? Our team can help you - just email <hello@assenteo.com>&#x20;
{% endhint %}

## 5. What is the timeline for enforcement of other sections of the AI Act? &#x20;

### In force from August 2025

* **Notifying authorities:** Notifying authorities in European countries will notify non-compliance. &#x20;
* **General-purpose AI models:** Providers of general purpose AI models must ensure that their models comply with the Act's standards, of  transparency, safety, and ethics.&#x20;
* **Governance:** The European Artificial Intelligence Board will be established, responsible for facilitating the consistent application of the AI Act across member states.&#x20;
* **Penalties:** Fines for non-compliance will be enforced.&#x20;
* **Confidentiality:** Rules for the transfer and processing of data including proprietary information and personal data are safeguarded against unauthorized disclosure.&#x20;

### In force from August 2026

* The AI Act will be effective as a whole except for articles concerning high-risk AI systems.

### In force from August 2027

* Rules for high risk AI-systems will be effective.&#x20;

## 6. What does this mean for companies?

Technology companies and startups who develop AI will need to pay attention to how the regulation will be implemented across the European Union.&#x20;

In particular the following types of companies should be aware of their EU AI Act obligations: &#x20;

* Any LLM-powered product, whether the LLM is third party or proprietary,
* Companies building and training their own proprietary LLM,&#x20;
* Companies who ensure product safety mechanisms function, healthcare products, and companies that ensure the working of critical infrastructure.&#x20;

However, this is only the beginning for the framework: it is yet to be shown how local jurisdictions react and how other legal areas will intersect with the Act.

{% hint style="info" %}
**Looking to find out if the EU AI Act applies to your company?** Get your [free assessment her](https://www.assenteo.com/)[e](https://www.assenteo.com/). &#x20;
{% endhint %}

{% embed url="<https://www.assenteo.com/>" %}

***


# Does the EU AI Act Apply to Your Business?

Does your startup rely on LLMs or NLP? The European Parliament has officially approved the European AI Act, and the Law came into force in 2024.

*This article has been updated and written based on our Founder's article with* [*Sparring*](https://sparring.io/the-ai-act-what-does-the-act-mean-for-startups/)*.*&#x20;

In a landmark decision in 2023, the European Parliament established its stance on AI regulation. The Act itself was designed designed to mitigate risks associated with AI technologies while ensuring their ethical and responsible use for European consumers. &#x20;

{% hint style="success" %}
**Looking to find out if the EU AI Act applies to your company?** Get your [free assessment her](https://www.assenteo.com/)[e](https://www.assenteo.com/). &#x20;
{% endhint %}

{% embed url="<https://www.assenteo.com/>" %}

If your company integrates AI into its tech stack or builds revenue models around AI, here are the key takeaways you need to know.

### 1. Is the technology you are creating a prohibited or high risk AI system?

The AI Act follows a risk-based approach, banning AI applications that pose harm to people’s safety or are discriminatory. Certain systems that [are strictly prohibited include](https://www.europarl.europa.eu/news/en/press-room/20230505IPR84904/ai-act-a-step-closer-to-the-first-rules-on-artificial-intelligence) those that ‘deploy subliminal or purposefully manipulative techniques, exploit people’s vulnerabilities or are used for social scoring (classifying people based on their social behaviour, socio-economic status, personal characteristics)’. Furthermore, individuals will have more rights to be protected from the negative risks of using ‘high-risk’ systems, including AI that handles people’s health, safety, fundamental rights, the environment, influencing voters in political campaigns and in recommendation systems used by social media platforms.&#x20;

By taking this approach, the European Parliament aims to safeguard individuals and organizations from the adverse effects of AI systems. Furthermore, it should provide certainty for businesses. It will however, result in certain additional disclosures and documentation for startups who are creating technology in specific verticals such as healthcare.

### 2. Does your technology use Remote Biometric Identification?

During the parliamentary committee-level discussions, one of the main points of contention was the real-time use of Remote Biometric Identification. While some wanted exceptions for specific circumstances like terrorist attacks or locating missing individuals, the ban on real-time use mostly prevailed.

### 3. Do you utilise generative AI?

Perhaps the question most influential to societal AI use: how does the AI Act impact generative AI? The European Parliament introduced a tiered approach for AI models, with a focus on foundation models and generative AI systems.

To address concerns regarding transparency and accountability, the European Parliament has proposed mandatory labeling for AI-generated content and the disclosure of generative AI models containing training data protected by copyright. This requirement will apply to models such as ChatGPT and Bard for example.

### 4. Are you developing models?

Providers and developers of foundation models are to be held to a higher standard and would need to assess if their model falls within a high-risk category. Builders of models should also be aware they will need to register their models in the EU database prior to release on the EU market.<br>

{% hint style="success" %}
**Unsure if the EU AI Act applies to you?** Get your [free assessment her](https://www.assenteo.com/)[e](https://www.assenteo.com/). &#x20;
{% endhint %}

{% embed url="<https://www.assenteo.com/>" %}

***


# Test

test


# Why You Should Budget for a vDPO or Data Advisor in 2025

As the seasons shift, so do priorities. Have you planned for your 2025 data needs?

Setting budgets in your company can be a stressor for many. Legal, product and research teams the like, in particular struggle at this time of year in conversations concerning budgets, especially if that department does not have a revenue stream.

Data protection may bring to mind rules, regulations and restrictions. The good news is that allowing for data protection and compliance can be a business investment rather than simply a risk management tool. Instead, working with a data advisory professional can bring dividends in return for new business opportunities, sales and customer loyalty.

In this article we discuss what is a DPO and the benefits of budgeting for a DPO in 2025.

## What is a DPO/vDPO?&#x20;

A DPO stands for a [Data Protection Officer](/dictionary/dpo). Under the [General Data Protection Regulation](/dictionary/gdpr), a registered DPO is required for certain companies and provides:

* A designated point of contact for the European Commission in case of complaint
* A contact for data subjects to communicate with
* A contact for the business to discuss privacy and data handling and protection topics with

Typically a DPO is a role directly in the team of the company and is a full time of contractor depending on the needs and requests on the company. A Virtual Data Protection Officer (or vDPO) is a more streamlined service than having an in-house DPO, while meeting your obligations under GDPR. Rather than hiring a full time DPO, a vDPO provides you with a contact for external data questions while meeting your DPO requirement.<br>

## Why budget for a DPO/vDPO?&#x20;

Many companies appoint a vDPO/DPO as they they have a compulsory legal requirement. However some companies instead identify this contact would be helpful for the company and choose to cooperate with a vDPO/DPO.

Notably, the main reason is that the individual can help grow the company and prevent distraction of teams on privacy topics. Some examples of this help are communications and support, PR and customer trust, future planning and growth opportunities. Let’s deep dive into each.

### 1. Communications for Support and Sales&#x20;

If you are receiving a high amount of data related questions or data access requests (SARs) from customers, partners or clients your support team may feel overwhelmed. A privacy professional can instead assist on these email chains or calls.\
\
Having a vDPO on hand can ease work load on other teams from the questions of sales in closing a deal.

### 2. PR and Customer trust&#x20;

If your business does not actually handle personal information due to the infrastructure of the service you may face scrutiny due to the nature or complexity of the business. In these cases businesses sometimes need assistance in communicating how they collect and process data to prevent confusion.\
\
Having a DPO on call can also help in demonstrating the maturity needed in order to work with enterprises as a B2B company, even for new companies.

### 3. Unlock Market Opportunities&#x20;

A team may recognise that privacy is a USP in their sector. Already having a DPO on board can help them scale the business faster and identify opportunities early on.\
\
Multi-disciplinary teams also work best. If you are mostly a technical team, having the eyes of a legally educated vDPO can bring a new perspective to potential opportunities. We can work directly with product teams to help identify missed opportunities of features that would cater to enterprise and unlock new revenue.<br>

### 4. Future Planning

The team may know they will grow the business in a way that they will eventually need a DPO. The cost of not engaging a professional early can mean other teams become distracted trying to find workarounds which have been solved countless times by a DPO.

If you are facing questions or receive multiple privacy related support requests, we offer both standard vDPO and advisory privacy services, and a hybrid Privacy Partner vDPO service which combines the two.

{% hint style="success" %}
**Interested in learning more? Get in touch with the Assenteo team at <hello@assenteo.com> or complete our form for a free assessment** [**here**](https://www.assenteo.com/)**.**&#x20;
{% endhint %}

{% embed url="<https://www.assenteo.com/>" %}

***


# Does the EU AI Act Apply to Your Business?

Does your startup rely on LLMs or NLP? The European Parliament has officially approved the European AI Act, and the Law came into force in 2024.

*This article has been updated and written based on our Founder's article with* [*Sparring*](https://sparring.io/the-ai-act-what-does-the-act-mean-for-startups/)*.*&#x20;

In a landmark decision in 2023, the European Parliament established its stance on AI regulation. The Act itself was designed designed to mitigate risks associated with AI technologies while ensuring their ethical and responsible use for European consumers. &#x20;

{% hint style="success" %}
**Looking to find out if the EU AI Act applies to your company?** Get your [free assessment her](https://www.assenteo.com/)[e](https://www.assenteo.com/). &#x20;
{% endhint %}

{% embed url="<https://www.assenteo.com/>" %}

If your company integrates AI into its tech stack or builds revenue models around AI, here are the key takeaways you need to know.

### 1. Is the technology you are creating a prohibited or high risk AI system?

The AI Act follows a risk-based approach, banning AI applications that pose harm to people’s safety or are discriminatory. Certain systems that [are strictly prohibited include](https://www.europarl.europa.eu/news/en/press-room/20230505IPR84904/ai-act-a-step-closer-to-the-first-rules-on-artificial-intelligence) those that ‘deploy subliminal or purposefully manipulative techniques, exploit people’s vulnerabilities or are used for social scoring (classifying people based on their social behaviour, socio-economic status, personal characteristics)’. Furthermore, individuals will have more rights to be protected from the negative risks of using ‘high-risk’ systems, including AI that handles people’s health, safety, fundamental rights, the environment, influencing voters in political campaigns and in recommendation systems used by social media platforms.&#x20;

By taking this approach, the European Parliament aims to safeguard individuals and organizations from the adverse effects of AI systems. Furthermore, it should provide certainty for businesses. It will however, result in certain additional disclosures and documentation for startups who are creating technology in specific verticals such as healthcare.

### 2. Does your technology use Remote Biometric Identification?

During the parliamentary committee-level discussions, one of the main points of contention was the real-time use of Remote Biometric Identification. While some wanted exceptions for specific circumstances like terrorist attacks or locating missing individuals, the ban on real-time use mostly prevailed.

### 3. Do you utilise generative AI?

Perhaps the question most influential to societal AI use: how does the AI Act impact generative AI? The European Parliament introduced a tiered approach for AI models, with a focus on foundation models and generative AI systems.

To address concerns regarding transparency and accountability, the European Parliament has proposed mandatory labeling for AI-generated content and the disclosure of generative AI models containing training data protected by copyright. This requirement will apply to models such as ChatGPT and Bard for example.

### 4. Are you developing models?

Providers and developers of foundation models are to be held to a higher standard and would need to assess if their model falls within a high-risk category. Builders of models should also be aware they will need to register their models in the EU database prior to release on the EU market.<br>

{% hint style="success" %}
**Unsure if the EU AI Act applies to you?** Get your [free assessment her](https://www.assenteo.com/)[e](https://www.assenteo.com/). &#x20;
{% endhint %}

{% embed url="<https://www.assenteo.com/>" %}

***


# How to Build a B2B Sales Data Strategy

Unsure how to use privacy and data protection to build trust with customers and partners?

**Rewatch Annabel Pemberton, DPO and**[ **Assenteo**](https://www.linkedin.com/company/assenteo/)**’s Founder, for a discussion on building a data protection strategy in 2025 that builds trust with current and future clients.**

{% embed url="<https://www.youtube.com/watch?v=VeR5khie55E>" %}

In this session Annabel discusses several methods for B2B companies to employ to help secure enterprise clients. She also explores the evolving landscape of data risks and shares insights drawn from her work with organizations at every stage of maturity.\
\
Here are some of the top takeaways.&#x20;

## What is on a Risk department's mind?&#x20;

When selling to enterprises, one overlooked element is asking or understanding how Risk or Legal see your company. \
\
In particular, one question you should be asking is ***"Will my product pass the vendor test?"*** \
\
Before working with a new provider, enterprises will ensure it meets their security standards. This includes questions such as:&#x20;

* how a third party LLM processes their company data
* where data is stored
* whether data processed by the tool is used for model training&#x20;
* how the product complies with regulations such as the EU AI Act&#x20;

## How do startups leverage privacy as a sales advantage? &#x20;

Some examples are covered in the session including:&#x20;

* winning trust of key stakeholders through teaching them how to use privacy and security tools in online academies
* creating a dedicated privacy FAQ page for product and support teams to direct customers to, and build trust with
* working with dedicated [DPO (Data Protection Officer)](/dictionary/dpo) support

## Actionable insights to refine your data protection strategy

***Check, collaborate, and communicate -*** we recommend to use the three C's to define and implement your data strategy for enterprise sales.&#x20;

### 1. Check

Take a stock check of your company’s data protection strategy. This includes asking:

* Is data protection currently a feature we present in our demo?
* Is data protection considered by our Product team when prioritizing new features?
* How are competitors featuring the privacy of their product to build customer trust?&#x20;

### 2. Collaborate

You should also check your customer’s risk appetite and be ready to work with multiple stakeholders.&#x20;

* Do you know how your potential customer is working with Legal and Risk in their team?&#x20;
* At what stage of the deal will Legal or Risk be involved?&#x20;
* If you can meet Legal or Risk, take the opportunity - this is a gift as you can learn the requirements that may be blocking a sale closing.

Remember when pitching data protection or security, customers don’t buy features - they buy solutions to painful, expensive problems.&#x20;

### 3. Communicate&#x20;

Something missing in how you are communicating the privacy or security benefits of the product? \
\
The next step is to work with your Marketing and Product teams to create a Privacy Hub page or implement a privacy training course for your product.&#x20;

{% hint style="info" %}
[Assenteo](https://www.assenteo.com/) helps companies through their DPO services in helping you build a privacy hub or customer-facing training.&#x20;
{% endhint %}

You should also work with Product on [privacy-by-design](/dictionary/privacy-by-design) for technical infrastructure fixes&#x20;

## Strategies to help build trust with potential buyers and partners

By now, you likely have an idea of strategies and steps you can take to implement privacy into your sales strategy. \
\
The below strategies can also help you in the B2B sales process through building customer trust:&#x20;

1. Have a [DPO](/dictionary/dpo) or Risk Manager ready to represent you on calls, or debrief before speaking with enterprises.&#x20;
2. Gain certifications to show your commitment and resource allocation to compliance. This includes ISO 27001, SOC 2, or EU AI Act readiness which you can display a badge for on your website. For enterprise customers make sure to offer a watermarked SOC 2 report to answer security questions.&#x20;
3. If you are too early for SOC 2, show your commitment to getting there. This can mean showing your security and privacy measures are 'up to' the standard of SOC 2.&#x20;
4. Demonstrate your privacy commitment through having a dedicated privacy FAQ page, on your website.
5. Work internally in the company to encourage the Product team to consider privacy by design when building and prioritising new product features in the roadmap.&#x20;

{% hint style="success" %}
**Interested in learning more? Get in touch with the Assenteo team at <hello@assenteo.com> or complete our form for a free assessment** [**here**](https://www.assenteo.com/)**.**&#x20;
{% endhint %}

{% embed url="<https://www.assenteo.com/>" %}

***


# Does the EU AI Act Apply to Your Business?

Does your startup rely on LLMs or NLP? The European Parliament has officially approved the European AI Act, and the Law came into force in 2024.

*This article has been updated and written based on our Founder's article with* [*Sparring*](https://sparring.io/the-ai-act-what-does-the-act-mean-for-startups/)*.*&#x20;

In a landmark decision in 2023, the European Parliament established its stance on AI regulation. The Act itself was designed designed to mitigate risks associated with AI technologies while ensuring their ethical and responsible use for European consumers. &#x20;

{% hint style="success" %}
**Looking to find out if the EU AI Act applies to your company?** Get your [free assessment her](https://www.assenteo.com/)[e](https://www.assenteo.com/). &#x20;
{% endhint %}

{% embed url="<https://www.assenteo.com/>" %}

If your company integrates AI into its tech stack or builds revenue models around AI, here are the key takeaways you need to know.

### 1. Is the technology you are creating a prohibited or high risk AI system?

The AI Act follows a risk-based approach, banning AI applications that pose harm to people’s safety or are discriminatory. Certain systems that [are strictly prohibited include](https://www.europarl.europa.eu/news/en/press-room/20230505IPR84904/ai-act-a-step-closer-to-the-first-rules-on-artificial-intelligence) those that ‘deploy subliminal or purposefully manipulative techniques, exploit people’s vulnerabilities or are used for social scoring (classifying people based on their social behaviour, socio-economic status, personal characteristics)’. Furthermore, individuals will have more rights to be protected from the negative risks of using ‘high-risk’ systems, including AI that handles people’s health, safety, fundamental rights, the environment, influencing voters in political campaigns and in recommendation systems used by social media platforms.&#x20;

By taking this approach, the European Parliament aims to safeguard individuals and organizations from the adverse effects of AI systems. Furthermore, it should provide certainty for businesses. It will however, result in certain additional disclosures and documentation for startups who are creating technology in specific verticals such as healthcare.

### 2. Does your technology use Remote Biometric Identification?

During the parliamentary committee-level discussions, one of the main points of contention was the real-time use of Remote Biometric Identification. While some wanted exceptions for specific circumstances like terrorist attacks or locating missing individuals, the ban on real-time use mostly prevailed.

### 3. Do you utilise generative AI?

Perhaps the question most influential to societal AI use: how does the AI Act impact generative AI? The European Parliament introduced a tiered approach for AI models, with a focus on foundation models and generative AI systems.

To address concerns regarding transparency and accountability, the European Parliament has proposed mandatory labeling for AI-generated content and the disclosure of generative AI models containing training data protected by copyright. This requirement will apply to models such as ChatGPT and Bard for example.

### 4. Are you developing models?

Providers and developers of foundation models are to be held to a higher standard and would need to assess if their model falls within a high-risk category. Builders of models should also be aware they will need to register their models in the EU database prior to release on the EU market.<br>

{% hint style="success" %}
**Unsure if the EU AI Act applies to you?** Get your [free assessment her](https://www.assenteo.com/)[e](https://www.assenteo.com/). &#x20;
{% endhint %}

{% embed url="<https://www.assenteo.com/>" %}

***


# TO ADJUST: What is Responsible Artificial Intelligence And How Do We Achieve It?

Artificial Intelligence (AI) is an incredibly powerful technology that already is and will continue to influence, change and advance almost every aspect of our lives, businesses and governments.&#x20;

&#x20;On the other hand, AI can also be incredibly disruptive and raise a number of concerns, including workplace displacement, algorithmic bias, lack of data privacy or AI black box problems. Alongside these concerns, AI systems act autonomously in our world and make their own decisions. If we are to leverage the positive power of AI, we ought to do so responsibly. We must ensure that what we teach the technology really reflects our values. But which values should be considered and prioritized? Whose values? And how do we deal with unavoidable dilemmas?&#x20;

## Who is we?&#x20;

[In her podcast episode](https://open.spotify.com/episode/02nXKFxMNTKyGNWXFoaIFy?si=mVznd3JpQ4GC7Bk-g-Hhpg), Erika Ly shares her belief that this “we” is all of us. From governing authorities to software developers, down to the users themselves.&#x20;

“All of us have some sort of individual responsibility role to play in our everyday life.”

She says that we each have a responsibility to think about what we are doing and whether or not we think that aligns with our values. Are we taking responsibility for our own actions? Ultimately, the goal is to develop technology solutions and enhance our human potential and experience, which means that as customers and users, we should also be a part of the feedback loop.&#x20;

## How?

Solid frameworks or binding guidance on the responsible use and development of AI have not been introduced so far. In its absence, ambiguity and misconceptions arise. Recently however, various stakeholders have come together in an effort to close this gap. [The Partnership on Artificial Intelligence](https://www.partnershiponai.org/about/) is a good example. This organization brings together academics, companies, organizations and other groups to better understand the impacts of AI and to study and develop best practices. Another example is the European Commissions’ recent publication of [Ethics guidelines for trustworthy AI](https://ec.europa.eu/digital-single-market/en/news/ethics-guidelines-trustworthy-ai) in the European Union.&#x20;

## What else?&#x20;

The establishment of strong communities like the one directed by Erika, [The Legal Forecast](https://www.thelegalforecast.com/), is another way to responsibly advance technology and innovation. This is specifically impactful in the conservative and risk averse legal space. &#x20;

“This mindset makes lawyers very good at what they do but not very good at changing themselves”.&#x20;

The creative and entrepreneurially minded members of The Legal Forecast believe in the power of technology in the legal practice and access to justice. They work on finding the sweet spot in which lawyers can innovate and responsibly push the profession forwards, whilst still feeling comfortable.&#x20;

&#x20;

&#x20;

<br>


# Privacy by Design strategies: Zero-party data

It is one of the hottest buzzwords in marketing right now. Zero-party data. And it’s all about asking instead of inferring.&#x20;

Customers are becoming increasingly wary of how their data is being collected and used. And legislation like the General Data Protection Regulation (GDPR) are starting to be more strictly enforced. [A recent lawsuit was brought against Oracle and Salesforce](https://tcrn.ch/30VOg8l) for their use of third-party tracking cookies, which if successful could end up with fines in excess of €10BN.

At the same time, customers demand a more personalized experience, with 66% of shoppers saying [a poorly personalized experience would stop them from purchasing](https://cmo.adobe.com/articles/2018/1/adobe-2018-consumer-content-survey.html#gs.deb7am).&#x20;

**What is Zero-Party Data?**

Zero-party data is information that customers voluntarily share with a company. Unlike data tracked and inferred from user behavior, it is explicitly provided by the customer often in exchange for a more personalized and improved shopping experience.

Zero-party data is collected through questions such as:&#x20;

* “How often do you want to receive emails from us?”&#x20;
* “What type of content do you like to watch?”
* “How was your most recent experience in our store?”

The answers to questions like these are all **zero-party data**, and brands can use that information to create better experiences for their customers.

Zero-party data differs from first, second and third party data types because it is **provided by the customer**, not inferred from their behavior. It’s information **a customer wants a company to know**. It doesn’t have the creepy, invasive nature that some other forms of data collection can have.&#x20;

And it’s always given with full consent.

Zero-party data presents marketers with an opportunity to collect valuable, actionable, and ethically-gathered information about customers in a time where data collection and usage is fraught with challenges.

We’ll take a look at some of the ways brands can collect zero-party data, and then see some of the [use cases](https://www.bloomreach.com/en/library/use-cases) that can be implemented with it.

#### How to Collect Zero-Party Data

Since zero-party data is given freely by a customer in return for a more personalized experience, it doesn’t make sense to collect it for anonymous customers. Zero-party data only makes sense for **identified customers.**

This means the first place you can start to collect zero-party data, is during the new user registration process (or when they sign up to receive your newsletter).

**Zero-Party Data Collection Upon Registration**

The exact type of information you ask for at registration will depend on your particular business. Let’s see some examples for inspiration.

Bloomreach customer [baby-walz collects zero party data](https://www.bloomreach.com/en/case-studies/baby-walz-uses-bloomreach-engagement-to-deliver-incredible-customer-experiences) when users register for its mailing list. baby-walz specializes in products for expectant parents, infants, and young children. So when a user registers for its mailing list, the company asks for some information about the child.

<img src="https://www.bloomreach.com/wp-content/uploads/2024/05/zero-party-data-registration.png" alt="Zero Party Data Registration" height="483" width="974">

*Source:* [*baby-walz*](https://www.baby-walz.de/)

New customers are often happy to provide this information because they know they’ll get more relevant information from baby-walz. And baby-walz gets higher quality data that they can use to create improved customer experiences online.

Stores that sell pet food use a similar strategy, asking new subscribers to give a little bit of information about the pet they’re shopping for.&#x20;

It’s important to **not overwhelm customers with questions** when they register their accounts. You need to maintain a careful balance between getting enough information to improve the customer experience and keeping the experience relatively friction-free.

Another important note: **only ask for data that you will actually use to improve the customer experience.** If you ask your customer about what type of pet they have, then send them totally irrelevant offers, **you’re going to annoy them.** You might even lose them as a customer. So only ask for what you can actually use.

**Collecting Zero-Party Data on Your Site**

Collecting zero-party data upon customer registration is an obvious choice, but it’s not the only one. Zero-party data can be collected during any interaction with customers, including while they’re on your site.

You can collect zero-party data from category pages. An example below shows how a clever choice of button copy can turn a simple “see more” button into an opportunity to collect zero-party data.&#x20;

Some companies have even dedicated entire sections of their site into a zero-party data experience. Take a look at this example from Victoria’s Secret.&#x20;

<img src="https://www.bloomreach.com/wp-content/uploads/2024/05/zero-party-data-custom-page.png" alt="Zero Party Data Custom Page" height="498" width="625">

*Source:* [*Victoria Secret*](https://www.victoriassecret.com/)

Customers are willing to share information because they’ll get a wardrobe that’s tailored to them. In return, Victoria’s Secret gets valuable zero-party data about its customers, which can be used to further improve its communications and customer experiences.

**Collecting Zero-Party Data from Social Media**

Another powerful way to collect zero-party data is by using social media. Polls, surveys, and engaging posts can all offer the opportunity for customers to share their preferences and intentions. This requires thoughtful execution, but the results can be great.&#x20;

L’Oreal lets customers virtually try on their products via their camera, then lets users share their photos directly to their social accounts.&#x20;

<img src="https://www.bloomreach.com/wp-content/uploads/2024/05/zero-party-data-social-media.png" alt="Zero Party Data Social Media" height="1024" width="680">

*Source:* [*L’Oréal*](https://www.loreal.com/en/)

In theory, such an application lets a brand like L’Oreal see what types of products specific customers are interested in, which can be used to improve their future communications. It also has the added benefit of creating social proof for L’Oreal when users share photos with their networks.

#### Collecting Zero-Party Data from Other Channels

In theory, zero-party data can be collected from any channel that a customer interacts with. We don’t have examples for every channel, since many brands are just starting to realize the value of zero-party data. But we can walk through some hypotheticals.

**Customer Service.** An interaction with customer service is a direct link to the customer, and provides a valuable opportunity to collect first-party data. The problem, however, is that CRM systems are often not connected with marketing systems. This means that whatever zero-party data you collect from a customer service call won’t be used to improve the customer experience.

**Email.** Most brands ask for feedback from a customer after they’ve had some interaction with them. This feedback can be considered zero-party data.

Again, if you have a [single customer view](https://www.bloomreach.com/en/blog/single-customer-view-scv-overview), you can use the zero-party data collected from email campaigns to improve the customer experience across all channels.

**In-store.** In-store and online experiences are starting to blend together, and most retailers want to find a way to connect the physical shopping experience with the virtual one.

It’s not uncommon to see tablets in stores, letting customers register an account, browse through a shop’s catalog, or even set up an appointment.

These can also offer a chance to collect zero-party data. Bloomreach client [Sofology](https://www.bloomreach.com/en/blog/sofology-and-bloomreach-a-one-year-retrospective-how-to-get-the-most-out-of-bloomreach), a popular furniture retailer in the United Kingdom, uses tablets in its store to help customers design their dream sofa. The information collected from an in-store visit is added to their customer profile and used to create more relevant messaging.

Watch this video below to see how Bloomreach makes it possible to connect online and offline interactions into one seamless shopping experience:&#x20;

**Any Other Channel.** Again, wherever there’s customer interaction, there’s the chance to collect zero-party data. As long as you can connect it with a unified customer profile, you can use it to create impressive customer experiences.

#### Zero-Party Data Principles

One of the major differences between zero-party data and first, second, and third-party data is its focus on customer centricity, transparency, and respect for the wishes of the customer.

In the spirit of respecting those differences, we recommend a few principles for collecting and working with zero-party data.

**Triple Transparency.** GDPR requirements demand transparency when collecting data. But that transparency often takes the form of an incomprehensible cookie banner that’s displayed when you visit a site. Many of these banners are so unclear or hard to navigate that it’s impossible to tell if a customer has opted in to data tracking or not.&#x20;

On the contrary, zero-party data collection should be **clear, transparent, and easy to understand** from the very beginning.

The principle of triple transparency means being clear when you’re:

* **Collecting data**
* **Utilizing zero-party data**
* **Letting customers change their data**

Maintaining this transparency helps ensure you’re using zero-party data in a customer-centric manner.

**Transparency When Collecting Data**

Thanks to legislation like the GDPR, many companies are already transparent about when they’re collecting data. Nevertheless, it’s important to maintain that transparency when you’re collecting zero-party data as well.

For example, when a customer is signing up for your newsletter and you’d like to ask them for some additional information, be sure to clearly tell them exactly what information you will keep, and how you want to use it.

If you want to be truly customer centric, then just linking to a privacy policy isn’t enough. You should be clear about the data you’re collecting directly where you’re collecting it.

This level of transparency helps generate trust in your business, and gives the customers an incentive to share their information with you.

**Transparency When Utilizing Data**

Being transparent about when you’re using zero-party data can help reinforce a customer’s decision to share that data with you. It doesn’t need to be anything excessive, a simple message is often enough.

**Letting Customers Change Their Data**

Preferences change. Tastes change. Interests and budgets change. All of these changes are reflected in what customers want and expect. It’s important to allow customers to alter the zero-party data that they share with you.

A customer might love your emails and want to receive more of them. Maybe they recently moved, and their preferences for furniture have changed. Or maybe they’ve discovered a favorite new brand, and want to see more from them on their homepage.

A company with a sophisticated zero-party data strategy will **let customers change their zero-party data.** This is often handled from a preference center, connected to their account with your business.

Amazon provides an excellent example of such a preference center, as shown below.&#x20;

An excellent preference center will show the data that’s been collected so far, how that data is used, and will let the customers update their preferences directly.

####

#### Zero-Party Data Use Cases: From Simple to Advanced

You don’t need to jump straight into complex [use cases](https://www.bloomreach.com/en/library/use-cases) to start seeing value from zero-party data. You can start simple and build from there. The most basic use cases can most likely be accomplished with the tools you already have. More advanced use cases will require sophisticated technology, but the rewards for your business and your customers are worth it.

We’ll take a look at some sample use cases here.

**Simple: Product Discovery via Quiz**

**Requirements:** Developer capacity, creativity.

A quiz can be an easy way to collect zero-party data while also helping your customers to find the right products for them.

You could make a short personality quiz that recommends products based on your customers personality. That info could then later be used to personalize communications with your customers (provided you gathered it with the right consent).

These types of quizzes can work for all types of verticals. A bank could use a personality quiz to understand spending habits and then recommend the right type of credit card. A travel agency could use a quiz to recommend destinations. And a clothing company could use a quiz to recommend the right styles.

All you need to execute this use case is some developer skill and some creativity. But if you want to use the data you collect for future campaigns, you will need to store it in a single customer view.

[Bloomreach customer My Jewellery had incredible success](https://www.bloomreach.com/en/case-studies/myjewellery-gets-creative-with-zero-party-data-and-bloomreach-engagement) with this strategy. It created the [style profile test](https://www.my-jewellery.com/nl-nl/stijlprofiel-test) to collect zero-party data from customers. It increased email open rates by 20% because of the creative campaign.&#x20;

**Intermediate: Personalized Newsletters**

**Requirements:** Zero-party data collection upon customer registration, email marketing tool.

The most simple way to start using zero-party data is to start personalizing your newsletters. Collect relevant information when customers subscribe to your mailing list. That could be things like their favorite brands, their gender, birthday, info about their pets…anything that’s pertinent to both them and your business.

Then, use the information you’ve collected to personalize your marketing emails. If you’re collecting only basic information (e.g. gender), you can then segment your mailing list and create different emails for each segment.

If the information you’re collecting is more varied (e.g. favorite brands), you can either use a recommendations engine to help create your email, or use another type of [personalization tool](https://www.bloomreach.com/en/products/engagement/web-personalization) to fill your emails with relevant information.

[BrewDog](https://www.bloomreach.com/en/case-studies/how-brewdog-increased-revenue-using-personalized-email-campaigns-with-bloomreach), a Bloomreach customer, used [personalized email campaigns](https://www.bloomreach.com/en/blog/email-personalization-your-guide-to-better-email-marketing-campaigns) to increase revenue from email 13.8% and conversion rate from emails 11.5%.&#x20;

**Advanced: Personalized Homepage**

**Requirements:** [On-site personalization](https://www.bloomreach.com/en/blog/2019/07/digital-commerce-explained) capabilities, single customer view with zero party data.

A completely personalized homepage or storefront is perhaps the pinnacle of zero-party data usage. It means curating the page a user see when they visit your site, based on the information they’ve provided to you.

Accomplishing this means you need the ability to completely personalize your website based on the information you have about your customers. Tools like Bloomreach or other marketing automation tools make this possible.

A personalized homepage can significantly speed up product discovery and customer satisfaction, leading to increased average order values, reduced time between repeat purchases, and lower cart abandonment rates.

Jenson USA used [Bloomreach Discovery](https://www.bloomreach.com/en/products/discovery) and [Bloomreach Engagement](https://www.bloomreach.com/en/products/engagement) to increase revenue per visitor (RPV) 8.5% thanks to [optimizing search results based on customer segments.](https://www.bloomreach.com/en/case-studies/jenson-usa-sees-increased-rpv-with-bloomreach-engagement-and-discovery) The strategy also led to a 26% increase in RPV for segmented searchers on mobile devices.&#x20;


# AI system location

What should your startup disclose about where your data is stored?

### Why does data location matter to startups? (penalties money/licensing; reputation)

It is likely that much of the data controlled by your company is stored in the cloud, by services such as AWS or Google Cloud, or in virtual data rooms. These services are brilliant tools but their use also asks for a little bit of time and attention to secure regulatory compliance (hark GDPR) as well as user trust.&#x20;

### What do your customers need to know?

There’s a lot of emphasis on transparency and disclosure in the data handling space. While this is very important in terms of building trust and remaining compliant, publicising company information is, of course, not without its pitfalls.&#x20;

Your company does not want to give so much information as to leave itself vulnerable to security issues. There are, of course, also questions of secure IP, exposing backend infrastructure and proprietary algorithms and staying competitive. Generally, you want to be careful about exposing information which isn’t already in the public domain or published.&#x20;

This said, there are certain things you want to make sure you are communicating to clients. This includes: <br>

1. **Which vendors you use**&#x20;
   1. Cloud processing such as Amazon Web Services or Google Cloud Platform
   2. LLMs such as OpenAI or Anthropic&#x20;
   3. Email providers such as Loops or Mailchimp
2. **Where the data is being stored and processed**
   1. Name the country where data physically resides in a data center&#x20;
3. **How you have verified your trust for this vendor**
   1. A statement in your privacy policy or trust page on how you assess vendors you use
   2. A window of opportunity for customers be notified of new vendors and if they so choose reject their usage

You’re ensuring you are communicating enough to your customers for them to have confidence in your data use and processing; for example, that their data isn’t being sold onwards without their knowledge or consent. Explaining that your company knows its own data flows, does a lot to comfort clients, showing that you maintain control and the ability to step in to protect their privacy.&#x20;

### Industry considerations

Choosing a location for your contracted data processing unit becomes a particularly acute issue in certain industries. Healthcare services, financial services and legal services, for instance, are industries which often require personal data to remain in data centers in a certain country.&#x20;

### Customer (and jurisdictional) considerations

The location of data subjects is also crucial. The jurisdiction in which they reside will have its own demands as to where their data may or may not be stored. For instance, if you handle the personal data of EU residents, the personal data can only be transferred outside of the EEA with certain safeguards in place.<br>


# AI system disclosure

How much should your startup disclose about its AI system?


# Most Searched Terms

Discovery our most searched terms below, or select a term on the left.

{% content-ref url="/pages/KiKev5l8jSVGPVQiSN0z" %}
[Privacy by Design](/dictionary/privacy-by-design)
{% endcontent-ref %}

{% content-ref url="/pages/4yNwj8jzAg6pRhIn7vs5" %}
[Personal Identifiable Information (PII)](/dictionary/pii)
{% endcontent-ref %}

{% content-ref url="/pages/gMIeRWDWYJnAlqKvTvjE" %}
[Data Protection Officer (DPO)](/dictionary/dpo)
{% endcontent-ref %}

{% content-ref url="/pages/HpCWPbMFJqpoWZpmlCm2" %}
[Data Protection Impact Assessment (DPIA)](/dictionary/dpia)
{% endcontent-ref %}


# Privacy by Design

An approach where privacy and data protection are considered throughout the product or system development process.

This is an approach that Assenteo interweaves into all consulting, in particular for sensitive data and consumer focused companies. For us, the aim of privacy by design is ensuring the collection and processing of [PII](/dictionary/pii) works for both the company and its users.

Success of privacy by design is indicated if how the company is processing user’s personal data is transparently communicated, rather than avoided by the company.<br>

{% hint style="success" %}
Privacy by Design is a core principle of how Assenteo works with companies. \
\
You can learn if implementing a Privacy by Design approach to your product development would help supercharge your business with a free assessment from us here: <https://www.assenteo.com/>
{% endhint %}

<br>

<br>


# Data Protection Officer (DPO)

An individual appointed to ensure a company's compliance (as a [Controller](/dictionary/data-controller) or [Processor](/dictionary/data-processor)) with data protection laws.&#x20;

The DPO acts as a point of contact for data subjects and supervisory authorities. In their role they are independent and act in the interests of the company from a data protection perspective.<br>

### Looking for a DPO?&#x20;

Assenteo provides an independent DPO as a virtual DPO (vDPO) service. \
\
A vDPO is a more streamlined service than having an in-house DPO, while meeting your obligations under GDPR. Rather than hiring a full time DPO, a vDPO provides you with a contact for external data questions and meets your DPO requirement. \
\
If you are facing questions or receive multiple privacy related support requests, we also offer a Privacy Partner vDPO for more support.\
\
Get in touch to work with an Assenteo vDPO:&#x20;

{% embed url="<https://www.assenteo.com/vdpo>" %}


# Aggregated PII

Information that is not [PII](/dictionary/pii) alone but becomes [PII](/dictionary/pii) if processed together.&#x20;

{% hint style="info" %}
Example:&#x20;

Blood type, last name and postal city taken individually alone do not identify an individual.\
\
O+

Harris

Edinburgh&#x20;
{% endhint %}

However, when combined, these data points can be used to identify a specific individual.&#x20;

{% hint style="info" %}
Example:&#x20;

Blood type, last name and postal city together may identify an individual.<br>

A person with the last name Harris, with O+ blood of Edinburgh. <br>
{% endhint %}


# Consent (legal basis)

Under the [GDPR](/dictionary/gdpr), [PII](/dictionary/pii) can only be collected and/or processed under a ‘legal basis’ (or simply, only if there is a reasoning for the processing).&#x20;

A [Processor](/dictionary/data-processor) or [Controller](/dictionary/data-controller) can rely on gaining the customer’s consent as a reasoning for data processing.&#x20;

For consent to be compliant, it must be:

* Freely given by the individual;
* Specific of what PII will be processed, how and why;&#x20;
* Communicated to the individual so they understand what, how and why PII will be processed (informed); and,
* A clear approval (an unambiguous indication of an individual's agreement) to the processing of their PII.

<br>

<br>


# Data Breach

A security incident that leads to the accidental or unlawful:

* access,
* destruction,
* loss,
* alteration or
* unauthorized disclosure

\
of [PII](/dictionary/pii).

<br>

<br>

<br>


# Data Collection

Is when a [Controller](/dictionary/data-controller) or [Processor](/dictionary/data-processor) recieves [PII](/dictionary/pii) from an individual ([data subject](/dictionary/data-subject)).&#x20;

{% hint style="info" %}
Examples:

* Collecting name and email for an email newsletter.&#x20;
* Collecting postal details to deliver a product.&#x20;
* Collecting personal attributable user iterations within your product (e.g clicks, time on page).
  {% endhint %}


# Data Controller

An entity that collects [PII](/dictionary/pii) and sets the purposes and means of processing.&#x20;

As the Controller is setting the instructions, they hold the highest responsibility in adhering to data protection laws.


# Data Processing

Is the storage, transmission, synthesis, training, use, disclosure or any other process of [PII](/dictionary/pii).&#x20;

{% hint style="info" %}
Example:&#x20;

* Collecting name and email for an email newsletter using a provider like HubSpot. HubSpot is the data processor.
  {% endhint %}


# Data Processor

An entity that processes [PII](/dictionary/pii) on behalf of the data [Controller](/dictionary/data-controller).&#x20;

The data Controller provides instructions to the data Processor for the [processing](/dictionary/data-processing).

{% hint style="info" %}
As the Processor is acting on behalf of the Controller, **they are responsible for having organisational and technical security measures in place**.&#x20;

The data Controller is responsible if a data breach or event occurs. However they may claim from the Processor, if they acted below data protection standards agreed contractually or under the relevant law.
{% endhint %}

<br>


# Data Protection Impact Assessment (DPIA)

A process to identify and mitigate risks associated with data [processing](/dictionary/data-processing) activities.&#x20;

A DPIA is sometimes requested by a customer (in particular enterprises) before signing terms to work with a provider. This is typically driven by the need to demonstrate the company understands and has considered data flow risks.&#x20;

<br>

<br>


# Data Subject

A data subject is an individual whose [PII](/dictionary/pii) is processed by a company (who is a [Controller](/dictionary/data-controller) or [Processor](/dictionary/data-processor)).

{% hint style="success" %}
Example:&#x20;

*BestSkin has an app that helps users reach their optimum skin health.*\
\
*The user becomes a data subject when they download the app and provide their* [*PII*](/dictionary/pii) *and/or health data to BestSkin.*
{% endhint %}


# General Data Protection Regulation (GDPR)

The GDPR is the primary source of law for data protection regulation in the European Union. With the primary purpose of ensuring the free flow of information within the EU, the GDPR grew to be the law to unify protection of EU citizen’s data.\
\
The law governs the processing of [PII](/dictionary/pii) of individuals when in Europe, and is applicable to companies and individuals who are [collecting](/dictionary/data-collection) or [processing](/dictionary/data-processing) PII of individuals in Europe. \
\
Your business will be required to comply with GDPR if:&#x20;

* your business is incorporated in Europe,
* you are not incorporated in Europe, but you target or process the data of individuals in Europe. This includes having customers/users in Europe.&#x20;

{% hint style="info" %}
Looking for a DPO? Assenteo provides external DPO and European/UK GDPR Representative services. Learn more here: <https://www.assenteo.com/vdpo>&#x20;
{% endhint %}


# Personal Identifiable Information (PII)

Information that can be used to identify a person. <br>

{% hint style="info" %}
**Examples:**\
\
First and last name\
Email\
ID number
{% endhint %}


# AI DPO: Lovable

Hi! This is Assenteo's AI DPO, providing data protection reviews of AI startups to showcase best practices. In these reviews, we assess basic compliance and transparency signals from public sources.

<figure><img src="/files/fVTzjSuQVrTitNnw9Ns4" alt=""><figcaption></figcaption></figure>

Lovable has been the talk of the tech community since launching earlier this year, whether for the speed of its custom UX or the company’s rapid growth - honestly, impressive.

As non-technical, literature-educated individuals, [Assenteo](https://www.assenteo.com/) is a big fan of non-technical tools, and we’re particularly excited by developments in this space over the past few months.<br>

***We are currently reassessing Lovable! Please check back soon for an update.***&#x20;

<br>

{% hint style="info" %}
At **Assenteo**, we help AI builders turn data protection into a product strength through providing data protection professional services. While this review focused on basic compliance and public transparency, our core service supports full compliance, strong UX practices, and competitive advantage through trust. **If you're a serious builder,** [**let's chat**](https://www.assenteo.com/)**.**
{% endhint %}

<figure><img src="/files/vFbwveTuCVpCDsccCo0m" alt=""><figcaption></figcaption></figure>


# AI DPO: ElevenLabs

Hi, this is AI DPO, providing data protection reviews of AI startups to showcase best practices. In these reviews, we assess basic compliance and transparency signals from public sources.

<figure><img src="/files/NGeFHX2uknYGbaFWifxA" alt=""><figcaption></figcaption></figure>

[ElevenLabs](https://elevenlabs.io/) has been a main player in the text to speech space since launching in 2022. The company recently raised $180m at Series C, having raised nearly $300m to date.\
\
With that amount of funding, it’s no surprise the company has an enterprise arm and has worked with the likes of Nvidia, Perplexity and Time.\
\
Here’s a privacy-first look at ElevenLabs to celebrate what’s working and suggest easy wins to build even more trust.<br>

## I) How We Review Companies

Through AI DPO, we’re here to help AI companies build data protection practices that are both compliant and customer-friendly.

When we review a company, we follow three simple principles:

{% hint style="success" %}

1. **We stick to what’s public**: Our reviews focus only on public-facing privacy practices, not private strategies, product features, or confidential details (those deeper insights are reserved for Assenteo users).<br>
2. **We’re here to raise the bar, not rank companies**: Our goal isn’t to criticize. It’s to lift the overall standard of data protection across the AI space and help everyone build stronger, more trusted products.<br>
3. **We’re a snapshot in time**: Our reviews reflect what we see on the date we publish. Companies change and grow, and so will their privacy practices.
   {% endhint %}

We believe good data protection is good business and we’re excited to be part of helping AI companies get it right.

## 1. Assenteo’s Take

As a speech to text solution, data protection becomes part of the technology’s design because of needs of two types of users:

* **End user:** The end user of a product utilizing ElevenLabs may share personal data and may need clarity around how this data is processed. They may also want to know why their data is processed or sent to other companies.
* **Enterprise**: As ElevenLabs work with enterprises, more stringent data protection practices need to be in place. This is especially the case when sensitive data, such as health data is collected and processed by the product.

We won’t comment on AI guardrails in this review, but ElevenLabs has a specific page on [AI Safety](https://elevenlabs.io/safety) on their website.

**ElevenLabs is mature in data protection and shows practices that other US AI companies could model on.** They are meeting most expectations for a data-compliant business in managing their own operations, and are providing pages on data safety in AI. However, there is an opportunity to improve transparency to users concerning how their data is used for LLM training and sale, and how to opt out.

## 2. AI DPO Assessment

| Category                               | Assessment           | Notes                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| -------------------------------------- | -------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Privacy Policy and other Documentation | ✅                    | <p>ElevenLabs hosts a <a href="https://elevenlabs.io/privacy-policy">privacy notice</a> for the personal data collection of their users. Last updated February 2025.<br><br>It’s worth saying the policy applies to individual users and when ElevenLabs directly provides their service. A different policy governs enterprise cooperation.<br><br>ElevenLabs also provides information on data protection and HIPAA compliance in their <a href="https://elevenlabs.io/docs/conversational-ai/customization/hipaa-compliance">Docs</a>. </p> |
| Data Collection                        | ✅                    | <p>The Privacy Policy clearly lists the data categories collected:<br>Personal data provided (including audio input), personal data automatically collected (trackers and cookies), and third-party information about the user. </p>                                                                                                                                                                                                                                                                                                           |
| Data Processing                        | ✅                    | <p>Data sharing with third-party service providers is disclosed. Specifics about which companies and storage locations are also provided.<br><br>The purposes of data processing are also shared, including a caveat that data used for training is not used to profile or target consumers.</p>                                                                                                                                                                                                                                               |
| User Controls                          | ✅                    | <p>Users are informed of their GDPR and CCPA rights.<br><br>An email address is provided for rights requests and ElevenLabs has a Data Protection Officer for users to get in touch with. </p>                                                                                                                                                                                                                                                                                                                                                 |
| AI-Specific Disclosures                | ✅                    | <p>Model training use is disclosed in the Privacy Policy. ElevenLabs uses third party personal data, and data collected in several of their products to train, develop and improve their own AI models.<br><br>By becoming a user you allow access to your personal data to train the company's AI models by default. However, you may opt out at any time through your account.</p>                                                                                                                                                           |
| Cookie Handling and Data Sale          | <p>⚠️</p><p><br></p> | <p>Website and app users are tracked. There is a cookie notice that also displays all cookie and tracker information, where users can reject all or accept cookies. Cookies are not dropped until accepted.<br><br>ElevenLabs has also sold data in the past 12 months to advertisers. They clearly state which data (IP address; unique identifier), however the link to opt out is missing. </p>                                                                                                                                             |

ElevenLabs currently stands at Level 2 🤙: Privacy engineered.

## 3. Highlights

* **Personal data transparency**: ElevenLabs demonstrates transparency in their collection and processing of customer personal data. Their Privacy Policy and Docs indicate privacy goes beyond compliance, and is a customer need.
* **Customer-centered privacy information**: ElevenLabs’ [HIPAA page](https://elevenlabs.io/docs/conversational-ai/customization/hipaa-compliance) showcases how to use their product in a compliant way when collecting health data of US persons. This page is a great example of how to help your customers stay compliant, in the use of your product.
* **Control over personal data in LLM training**: Making model training a feature of your product can be okay if communicated transparently. However, ElevenLabs does allow opt out even on free plans.&#x20;

## 4. Where Trust Can Grow

* **Clarify data used for model training**: There’s an opportunity to strengthen user trust by clearly highlighting in-app that personal data is used for model training, and give that choice to the user. Especially as ElevenLabs sells this data, this could be a major trust lever.
* **Improve discovery of privacy pages**: ElevenLabs hosts a [compliance page](https://compliance.elevenlabs.io/) with Drata, and privacy and [HIPAA compliance](https://elevenlabs.io/docs/conversational-ai/customization/hipaa-compliance) Docs pages. However, I had to know what I was looking for to find these resources.

{% hint style="info" %}
At **Assenteo**, we help enterprise-focused AI builders turn data protection into a product strength through providing data protection professional services. While this review focused on basic compliance and public transparency, our core service supports full compliance, strong UX practices, and competitive advantage through trust. **If you're a serious builder,** [**let's chat**](https://www.assenteo.com/)**.**&#x20;
{% endhint %}

<figure><img src="/files/vFbwveTuCVpCDsccCo0m" alt=""><figcaption></figcaption></figure>


# AI DPO: PostHog

Hi, this is AI DPO, providing data protection reviews of AI startups to showcase best practices. In these reviews, we assess basic compliance and transparency signals from public sources.

<figure><img src="/files/xRVRspQFyJq7No0YieSW" alt=""><figcaption></figcaption></figure>

*First things first,* [*PostHog*](https://posthog.com/) *is not an AI company. However, as they are a technology company with excellent data protection communication we thought it still was a great fit for this series.*&#x20;

PostHog is a platform for open-source product analytics to help software teams understand user behavior. Having started in 2020, the company has become a Product and Dev go-to, with a community 250k strong.&#x20;

**But can we just comment on PostHog’s branding and community focus?** While I have assessed PostHog as a vendor for a few companies now over the years, what keeps the brand front of mind is that **they're fun and don’t take themselves too seriously.**\
\
Thinking that means privacy goes out of the window? Well.. you’re in for a surprise.\
\
Here’s a privacy-first look at PostHog to celebrate what’s working (and suggest easy wins to build even more trust).<br>

## I) How We Review Companies

Through AI DPO, we’re here to help AI companies build data protection practices that are both compliant and customer-friendly.

When we review a company, we follow three simple principles:

{% hint style="success" %}

1. **We stick to what’s public**: Our reviews focus only on public-facing privacy practices, not private strategies, product features, or confidential details (those deeper insights are reserved for Assenteo users).<br>
2. **We’re here to raise the bar, not rank companies**: Our goal isn’t to criticize. It’s to lift the overall standard of data protection across the AI space and help everyone build stronger, more trusted products.<br>
3. **We’re a snapshot in time**: Our reviews reflect what we see on the date we publish. Companies change and grow, and so will their privacy practices.
   {% endhint %}

We believe good data protection is good business and we’re excited to be part of helping AI companies get it right.

## 1. Assenteo’s Take

As a data analytics suite, data protection is essential during the collection and processing of data, especially when personal information is involved. \
\
In the analytics world, there are typically two stakeholders:

* **The end user** – the individual being tracked. This person will have preferences about how their data is used, and whether it can be used at all.
* **The tracker** – the person or organization paying for the product. When granting access to a company for analytics, the customer must ensure the security and protection of the data they share.

Companies like PostHog have a direct interest in ensuring data protection practices are transparent. This is particularly important for enterprise customers, who must demonstrate that they meet their compliance obligations to their own end users.

At the same time, customers expect a certain level of data protection and reassurance before sharing their data with an analytics provider. PostHog addresses this by taking on responsibility (as the Data Controller under GDPR) for processing when they access a customer account’s data - for example, when using customer data to improve one of PostHog’s tools.

Overall, **PostHog is a leader in data protection practices and should serve as a model for B2B AI companies.** In addition to meeting data compliance expectations in their own operations, they are also integrating features that help their customers stay compliant. It is hard to imagine that their Legal and Product teams are not working closely together.

## 2. AI DPO Assessment

| **Category**                               | **Assessment** | **Notes**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| ------------------------------------------ | -------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Privacy Policy and other Documentation** | ✅              | <p>PostHog hosts a <a href="https://posthog.com/privacy">Privacy Policy</a> for the personal data and data collection of website visitors and app users. However, the Privacy Policy is not dated. <br><br><a href="https://posthog.com/dpa">A Data Processing Agreement (DPA)</a> is also available. PostHog provides this through a document generator, making it easy to complete. <br><br>PostHog also provides information on data protection and HIPAA compliance on their <a href="https://posthog.com/">website</a> and in their <a href="https://posthog.com/docs/privacy/hipaa-compliance">documentation</a>.</p> |
| **Data Collection**                        | ✅              | The Privacy Policy clearly lists the data categories collected: personal data provided during account creation, data automatically collected (e.g., cookies), and account usage data. PostHog explains how they collect and process aggregated data from accounts, but this can be disabled.                                                                                                                                                                                                                                                                                                                                |
| **Data Processing**                        | ✅              | Data sharing with third-party service providers is disclosed, including which companies are involved. The purposes of data processing are also clearly explained.                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| **User Controls**                          | ✅              | Users are informed of their GDPR rights. An email address is provided for rights requests, and PostHog has a Data Protection Officer users can contact.                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| **AI-Specific Disclosures**                | N/A            | PostHog does not include any AI-specific disclosures in its policy.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| **Cookie Handling and Data Sale**          | ⚠️             | <p>PostHog states that it does not use third-party trackers to collect information about users. </p><p></p><p>However, tracking still occurs via PostHog itself, as explained in the Data Collection section. The simplicity of this setup is inspiring, but there is an opportunity to explain it more clearly to end users.<br></p><p>PostHog does not refer to whether they sell personal data.</p>                                                                                                                                                                                                                      |

PostHog currently stands at Level 3 🌊 : Privacy Leader.

## 3. Highlights

* **Personal data transparency**: PostHog demonstrates transparency in their collection and processing of customer personal data. In general, they are trying to keep the collection of personal data to a minimum. PostHog also highlights data protection practices on their home page, such as in-app privacy controls and hosting location choice.
* **Customer-centered privacy information**: PostHog have created their own features and pages to support data protection implementation, such as their [DPA builder](https://posthog.com/dpa). Visiting PostHog serves as a reminder that excellent privacy-by-design does not need to come at the expense of customer focus, and is actually **very much essential to it.**
* **Prevention of third-party trackers**: PostHog makes tracking really simple for users. They do not use third-party trackers and only collect information as a first-party cookie and using their own product. &#x20;

## 4. Where Trust Can Grow

* **Clarify how first party data is tracked**: There’s an opportunity to strengthen user trust by clearly highlighting how users are still tracked, just not by third party tools.

{% hint style="info" %}
At **Assenteo**, we help enterprise-focused AI builders turn data protection into a product strength through providing data protection professional services. While this review focused on basic compliance and public transparency, our core service supports full compliance, strong UX practices, and competitive advantage through trust. **If you're a serious builder,** [**let's chat**](https://www.assenteo.com/)**.**&#x20;
{% endhint %}

<figure><img src="/files/vFbwveTuCVpCDsccCo0m" alt=""><figcaption></figcaption></figure>


# AI DPO: Flo

Hi, this is AI DPO, providing data protection reviews of AI startups to showcase best practices. In these reviews, we assess basic compliance and transparency signals from public sources.

<figure><img src="/files/YWVMa1Z7rlTgLdqMT8LA" alt=""><figcaption></figcaption></figure>

*Flo is not an AI company. However, as they are a technology company that handles sensitive personal information, we thought it still was a great fit for this series to show best practices.*\
\
[Flo](https://flo.health/) is a wellness platform for people seeking to track their menstrual cycle, when they may get pregnant and their pregnancy journey. Over 420 million people use the app.\
\
Inside the app users can track their cycle and symptoms, understand their fertility better, follow their pregnancy week by week, and share Flo with their partner.\
\
Here’s a privacy-first look at Flo to highlight what’s working (and suggest easy wins to build more trust with their users).

<br>

## I) How We Review Companies

Through AI DPO, we’re here to help AI companies build data protection practices that are both compliant and customer-friendly.

When we review a company, we follow three simple principles:

{% hint style="success" %}

1. **We stick to what’s public**: Our reviews focus only on public-facing privacy practices, not private strategies, product features, or confidential details (those deeper insights are reserved for Assenteo users).<br>
2. **We’re here to raise the bar, not rank companies**: Our goal isn’t to criticize. It’s to lift the overall standard of data protection across the AI space and help everyone build stronger, more trusted products.<br>
3. **We’re a snapshot in time**: Our reviews reflect what we see on the date we publish. Companies change and grow, and so will their privacy practices.
   {% endhint %}

We believe good data protection is good business and we’re excited to be part of helping AI companies get it right.

## 1. Assenteo’s Take

As a female menstrual wellness tool, data protection is essential for Flo. Users are aware that they are choosing a provider to share their menstrual patterns with and therefore need to be reassured of their practices for their privacy.\
\
Under EU and US laws, menstrual data is health care data, as it:&#x20;

* relates to the user’s health,
* can reveal sexual health or reproductive health status, and
* may indirectly reveal sexual orientation or intentions to conceive.

Companies like Flo therefore must ensure data protection practices are transparent as they have a higher responsibility under law. Outside of Law land however, highly sensitive data categories are also the areas that matter the most to people and society. To not protect these data types could damage customer trust giving rise to the social responsibility Flo has.\
\
**Flo has emerged as a leader in privacy-first design and should serve as an example for AI companies managing similarly sensitive data, such as health information.**\
\
In addition to meeting expectations for a data-compliant business in managing their own operations, Flo are adding **features to put their users at ease** such as Anonymous Mode and gaining **certifications like ISO 27001**. It’s clear that their Legal and Product teams are working closely together to embed privacy into the user experience.

## 2. AI DPO Assessment

| Category                               | Assessment           | Notes                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| -------------------------------------- | -------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Privacy Policy and other Documentation | ✅                    | <p>Flo hosts a <a href="https://flo.health/privacy-policy">Privacy Policy</a> for the personal data and data collection of Flo website visitors and app users. The Privacy Policy was last updated in September 2024.<br><br>Flo has highlighted the key data takeaways of each section in a visual format, to provide users with clarity on their data use.<br><br>Flo also provides a <a href="https://flo.health/flo-privacy-faqs">FAQ page</a> and <a href="https://flo.health/privacy-portal">privacy portal</a>. </p> |
| Data Collection                        | ✅                    | <p>The Privacy Policy clearly lists the data categories collected:<br>personal data provided for account creation, health metrics that the user inputs into the app, and account usage. Flo also collects data automatically for platform improvement.<br><br>Flo offers an anonymous mode to avoid data collection altogether. This means no email, name, or technical identifiers are associated with the account. </p>                                                                                                   |
| Data Processing                        | ✅                    | <p>Data sharing with third-party service providers is disclosed for the app’s functioning. In particular Flo includes specific on how non-personal data is shared for their advertising purposes, including a diagram. <br><br>Specifics about which companies receive application data for the functioning of the product are also provided.<br><br>The purposes of data processing are also shared.</p>                                                                                                                   |
| User Controls                          | ✅                    | <p>Users are informed of their rights and are able to request access, deletion, correction and other rights despite where they live<br><br>An email address is provided for rights requests and Flo has a Data Protection Officer for users to get in touch with.</p>                                                                                                                                                                                                                                                       |
| AI-Specific Disclosures                | N/A                  | <p>Flo does not comment on AI-specifics.<br><br></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Cookie Handling and Data Sale          | <p>✅ </p><p><br></p> | <p>Flo uses cookies on their website to track users. Marketing, analytics and personalization cookies are dropped only when a user opts in.<br><br>Flo states in their Privacy Policy that they do not sell user information for monetary gain. They also do not sell Apple HealthKit or Google Health Connect framework data to advertising platforms, data brokers, or information resellers. </p>                                                                                                                        |

**Flo currently stands at Level 3: Privacy Leader**

## 3. Highlights

* **Customer-centered privacy information**: Flo’s current privacy stance positions them as taking a proactive approach to their customer’s personal data. This includes the ease of accessibility of information concerning how they collect and process personal data and new features such as Anonymous Mode providing options to users.
* **Protection of customers in data sharing:** Flo only shares non-personal data when promoting the app using AppsFlyer. This allows Flow to still grow and reach more users, but not at the sacrifice of user trust.
* **Opt-in tracking**: Users will only be shown tailored content and materials if they opt in. Flo still does track browsing trends in the app by default, however product customisation only occurs with user consent. This approach places control over the use of personal data back into the hands of the user.

## 4. Where Trust Can Grow

* **Show health data coverage**: Currently Flo does not mention health data protection regulations on their website such as HIPAA, however they do refer to collecting and processing health data. While Flo is not mandated to have a HIPAA specific Privacy Officer, having a HIPAA expert as part of their advisory would further strengthen trust.
* **Clarity on AI usage**: In a world where the mention of AI is commonplace, it was surprising it did not appear in our analysis of Flo. It is perhaps the case that AI is simply not used by the company or to process customer data, however there is an opportunity here to have clarity on this with an AI Transparency Policy.&#x20;
* **Customer data privacy feedback**: Flo features who internally is building privacy functions at Flo. To give users the power to influence how their data is used, an opportunity lies in community-driven privacy feedback.

{% hint style="info" %}
At **Assenteo**, we help enterprise-focused AI builders turn data protection into a product strength through providing data protection professionals.  While this review focused on basic compliance and public transparency, our core service supports full compliance, strong UX practices, and competitive advantage through trust. **If you're a serious builder,** [**let's chat**](https://www.assenteo.com/)**.**&#x20;
{% endhint %}

<figure><img src="/files/vFbwveTuCVpCDsccCo0m" alt=""><figcaption></figcaption></figure>


# AI DPO: Whoop

Hi, this is AI DPO, providing data protection reviews of AI startups to showcase best practices. In these reviews, we assess basic compliance and transparency signals from public sources.

<figure><img src="/files/XkhH91J3oL7vNUBsrvqq" alt=""><figcaption></figcaption></figure>

*Whoop is not an AI company but offers AI features. However, as they are a technology company that handles health information (sensitive personal information), we thought it still was a great fit for this series to show best practices.*\
\
If you are an Apple Watch or Garmin user, you’ve likely heard of [Whoop](https://www.whoop.com/gb/en/). With a screen-less bracelet and subscription model, Whoop provides insights into your movement, and health condition. With the latest version of the bracelet, users can gain insights into their sports performance recovery quality, sleep quality, stress, and body efficiency (e.g VO2 max, heart rate, ECG and blood pressure). Whoop can also be used for menstrual tracking.   &#x20;

Here’s a data protection-first look at Whoop to highlight what’s working (and suggest easy wins to build more trust with their users).

## I) How Assenteo Reviews Companies

Through AI DPO, we’re here to help AI companies build data protection practices that are both compliant and customer-friendly.

When we review a company, we follow three simple principles:

{% hint style="success" %}

1. **We stick to what’s public**: Our reviews focus only on public-facing privacy practices, not private strategies, product features, or confidential details (those deeper insights are reserved for Assenteo users).<br>
2. **We’re here to raise the bar, not rank companies**: Our goal isn’t to criticize. It’s to lift the overall standard of data protection across the AI space and help everyone build stronger, more trusted products.<br>
3. **We’re a snapshot in time**: Our reviews reflect what we see on the date we publish. Companies change and grow, and so will their privacy practices.
   {% endhint %}

We believe good data protection is good business and we’re excited to be part of helping AI companies get it right.

[**Assenteo**](https://www.assenteo.com/) **scoring: To help guide you we give a score between 0-25.** The closer a company is to 25, the more [Assenteo](https://www.assenteo.com/) considers it as a Privacy Leader.

## 1. Assenteo’s Take

As a health and wellness tool, data protection is essential for Whoop. Users are aware that they are choosing a provider to share their exercise and health status insights with and therefore need to be reassured of their practices for their privacy.\
\
Under EU and US laws, insights about our health (including sleep quality, stress, performance) is health  data, as it relates to a user’s health. Menstruation data, can also reveal sexual health or reproductive health status, and may indirectly reveal sexual orientation or intentions to conceive. A company which collects and processes this type of data is therefore handling [sensitive personal data](/dictionary/pii).&#x20;

Companies like Whoop therefore must ensure data protection practices are transparent as they have a higher responsibility under law. Outside of law land however, highly sensitive data categories are also the areas that matter the most to people and society. To not protect these data types could damage customer trust giving rise to the social responsibility Whoop has. <br>

**Whoop is taking steps to help inform their customers about data practices, however there are areas of opportunity to help consumers understand how their data is being used.**

## 2. Assenteo's AI DPO Assessment

<mark style="background-color:green;">**In total Whoop scored: 17/25**</mark>

### Privacy Policy and documentation

**2/5**

* Whoop hosts a [Privacy Policy](https://www.whoop.com/gb/en/full-privacy-policy/) for the personal data and data collection of Whoop users, whether they use their bracelet or other software.&#x20;
* The Privacy Policy is not dated.&#x20;
* Whoop also provides a [Privacy page](https://www.whoop.com/gb/en/whoop-privacy-policies/) that highlights their key privacy information.

### Data Collection

**3/5**

* The Privacy Policy clearly how the data is collected.&#x20;
* The Privacy Policy clearly lists the data categories collected, including account information, wellness (health) data, communications when speaking with Whoop, payment data and app usage data.&#x20;
* It is not possible to Means of using the app with no personal data collection.&#x20;

### Data Processing

**4/5**

* Whoop outlines under what circumstances your personal data will be processed. &#x20;
* Whoop explicitly outlines which third-party service providers are used and their contact details in the privacy policy.&#x20;
* Whoop relies on Standard Contractual Clauses for transfer to the US.&#x20;

### User controls

**2/2**

* Users are informed of their rights and are able to request access, deletion, correction and other rights despite where they live.
* An email address is provided for rights requests and Whoop has a Data Protection Officer for users to get in touch with.

### AI-Specific Disclosures

**4/5**

* Whoop outlines that they use an LLM partner (OpenAI) to provide their Whoop Coach.&#x20;
* Whoop also uses AI in their support.&#x20;
* Whoop also has stated their training policy - Zero-Retention/Zero Training Policy. Only anonymized data is shared with OpenAI and this data is not stored or used in training.&#x20;
* Whoop mentions to not provide personal data while also stating they only share anonymized data.&#x20;

### Cookie Handling and Data Sale

2/3

* Whoop uses cookies on their website to track users. A cookie banner is shown when opening their website. Cookies are dropped only when a user opts in.&#x20;
* Whoop states in their Privacy Policy that they do not sell user information.&#x20;
* Whoop collects a reasonable amount of data and gives cookie granularity.

## 3. Highlights

* **Transparency in data sharing with third parties**: Whoop outlines the names and contact details of all services they share data with. Big tick from Assenteo here as it clearly shows the other companies a user’s data may be shared with, including their location.&#x20;
* **Privacy-first AI coach**: Whoop takes a stance to not allow the data retention or training by OpenAI in providing their AI powered feature, their AI Coach. While we don’t reward more points for not using anonymized data for training, transparency in this area is crucial for trust building.

## 4. Where Trust Can Grow

Whoop is doing a good job in privacy. These opportunities could build more trust with users that Whoop handles personal data safely and securely:

* **Show health data coverage**: Currently Whoop does not mention health data protection regulations on their website such as HIPAA, however they do refer to collecting and processing data that may constitute health data. While Whoop is not mandated to have a HIPAA specific Privacy Officer, having a HIPAA expert as part of their advisory would further strengthen trust.&#x20;
* **User-friendly privacy page**: While it is helpful to have a separate privacy page for users, Whoop can make understanding how they handle personal information more straightforward for users with clearer design and UX of the page. In particular we found this more like another legal page, as other regulations were also mixed in and it was quite wordy. <br>

{% hint style="info" %}
At [Assenteo](https://www.assenteo.com/), we provide an enterprise-ready trust layer for AI builders, providing access to data compliance experts and automation. While this review focused on basic compliance and public transparency, our core service supports full compliance, strong UX practices, and competitive advantage through trust. \
\
**If you're a serious builder,** [**let's chat**](https://www.assenteo.com/) and turn compliance into a USP.&#x20;
{% endhint %}

<figure><img src="/files/vFbwveTuCVpCDsccCo0m" alt=""><figcaption></figcaption></figure>


# AI DPO: Willow

Hi, this is AI DPO, providing data protection reviews of AI startups to showcase best practices. In these reviews, we assess basic compliance and transparency signals from public sources.

<figure><img src="/files/mZCEeTmbcUnxITUGUebE" alt=""><figcaption></figcaption></figure>

If you are anything like me you might have been interacting with tech a bit differently lately. In particular I’ve started to notice my preference towards dictation over typing when sending a text or day to day admin. While many users utilize their OS’s native tools, one tool lately caught my eye to be more efficient when working at my desk: Willow.&#x20;

[Willow](https://willowvoice.com/), is a speech-to-text tool that is activated by pressing ‘fn’ or the keyboard shortcut you choose. Once recording, you dictate while holding fn. On release, the text is inserted in the place you have selected. &#x20;

Here’s a data protection-first look at Willow to highlight what’s working (and suggest easy wins to build more trust with their users).

## I) How Assenteo Reviews Companies

Through AI DPO, we’re here to help AI companies build data protection practices that are both compliant and customer-friendly.

When we review a company, we follow three simple principles:

{% hint style="success" %}

1. **We stick to what’s public**: Our reviews focus only on public-facing privacy practices, not private strategies, product features, or confidential details (those deeper insights are reserved for Assenteo users).<br>
2. **We’re here to raise the bar, not rank companies**: Our goal isn’t to criticize. It’s to lift the overall standard of data protection across the AI space and help everyone build stronger, more trusted products.<br>
3. **We’re a snapshot in time**: Our reviews reflect what we see on the date we publish. Companies change and grow, and so will their privacy practices.
   {% endhint %}

We believe good data protection is good business and we’re excited to be part of helping AI companies get it right.

[**Assenteo**](https://www.assenteo.com/) **scoring: To help guide you we give a score between 0-25.** The closer a company is to 25, the more [Assenteo](https://www.assenteo.com/) considers it as a Privacy Leader.

## 1. Assenteo’s Take

As a productivity tool, data protection may not appear essential for Willow on the face of it. However, AI scribes function by recording your voice, and transcribing the input through processing. More privacy-centric users, or larger organizations, will be vigilant to ensure any provided data is stored, transferred and processed with privacy in mind.\
\
Under EU and US laws, voice recordings which identify an individual are considered personal data. While this is not sensitive data like health information, a company which collects and processes any personal data is required to have a level of organizational and security compliance in place. This is before any consideration of the content of recordings.&#x20;

Furthermore, if handled incorrectly, voice data can be manipulated and abused to impersonate an individual, which can have far reaching ramifications on a person's reputation and life.&#x20;

Companies like Willow therefore must ensure data protection practices are in place and transparent to ensure users data remains secure.&#x20;

**Willow is working to keep customers informed about how their personal data is used and is building a privacy-focused tool. However, there’s still room to build more trust and explain clearly how user data is handled.**

## 2. Assenteo's AI DPO Assessment

<mark style="background-color:green;">**In total Willow scored: 12/25**</mark>

### Privacy Policy and documentation

**3/5**

* Willow hosts a [Privacy Policy](https://willowvoice.com/privacy-policy) for the personal data and data collection of Willow users.&#x20;
* The Privacy Policy was updated in the last year.&#x20;
* Willow does not have a Privacy or Security hub on their website. However, on signing up to the tool, they inform the user how data is used.&#x20;

### Data Collection

**3/5**

* The Privacy Policy clearly describes how data is collected.&#x20;
* The Privacy Policy clearly lists the data categories collected, including account information, dedicated text and usage data.&#x20;

### Data Processing

**2/5**

* Willow outlines under what circumstances your personal data will be processed.&#x20;
* Willow does not share which third-party service providers are used.&#x20;
* Willow does not address whether EU data is transferred to the US.

### User controls

**1/2**

* Users are prompted to choose their preference around the use of their data during onboarding. Either you can allow your anonymized transcripts to be used for model and feature improvement, or keep all data local on your device.&#x20;
* An email address is provided for privacy questions.
* Users are not informed of their rights and are able to request access, deletion, correction and other rights despite where they live.

### AI-Specific Disclosures

**2/5**

* Willow does provide information in their onboarding flow and privacy policy how they use input and output from the product for model training. &#x20;

### Cookie Handling and Data Sale

**1/3**

* Willow uses cookies on their website to track users, but does not show a cookie banner.
* Willow however does give users options on how they are tracked and their usage used for platform improvement when using the scribe.&#x20;

## 3. Highlights

* **Privacy-first design**: Willow defaults to not tracking users through ‘private mode’. Willow only collects basic technical and account-related data to run the app in this setting. This gives an option for users who want to maintain full privacy and control over their data the possibility to do so.&#x20;
* **In-app privacy information**: Willow does not hide privacy choices that the user should make. Instead they have embedded how a user’s data will be used and given the user that choice during the onboarding flow. <br>

## 4. Where Trust Can Grow

Willow is doing a good job in privacy for such a new company. These opportunities could build more trust with users that Willow handles personal data safely and securely:<br>

* **Transparency in product functionality and data flows**: Willow does not outline how the platform works, or services they share data with for the scribe to work.&#x20;
* **User-friendly privacy information (pre-app)**: While Willow explains the difference between private mode and sharing usage data for scribe improvement, this is not highlighted on their home page. There is a mention of the scribe being privacy and security first, but the statement doesn’t fully describe the functionality or user flow.&#x20;

{% hint style="info" %}
At [Assenteo](https://www.assenteo.com/), we provide an enterprise-ready trust layer for AI builders, providing access to data compliance experts and automation. While this review focused on basic compliance and public transparency, our core service supports full compliance, strong UX practices, and competitive advantage through trust. \
\
**If you're a serious builder,** [**let's chat**](https://www.assenteo.com/) and turn compliance into a USP.&#x20;
{% endhint %}

<figure><img src="/files/vFbwveTuCVpCDsccCo0m" alt=""><figcaption></figcaption></figure>


