72-hour breach rule
If a data breach risks harm to people, you must tell the Data Protection Commission within 72 hours of becoming aware of it.
GDPR Art. 33
AI literacy (Article 4)
Making sure staff who use AI understand what it can and can't do, and its risks — with a record that you trained them.
Why it matters — In force since February 2025 and applies to every organisation using AI.
EU AI Act Art. 4
Annex III category
The EU AI Act lists specific high-risk uses in its Annex III — for example recruitment, credit scoring, or education. This records which one applies.
EU AI Act Annex III
Article 9(2) condition
The specific extra permission you need to handle special-category data — for example explicit consent, or providing health care. A normal lawful basis alone isn't enough.
GDPR Art. 9(2)
Automated decision-making
A decision about a person made by software with no meaningful human involvement — for example auto-rejecting an application.
Why it matters — People have a right to human review of such decisions.
GDPR Art. 22
CE mark
A stamp the maker puts on a product to say it meets EU rules. For a high-risk AI tool you should see it before you rely on it.
Why it matters — The Act asks deployers to check it before using a high-risk system.
EU AI Act Art. 13
Data-subject request
When someone asks to see, correct, or delete the personal data you hold about them. You must respond within one month.
GDPR Art. 12–22
Declaration of conformity
A document from the tool's maker formally stating it meets the EU AI Act's requirements. You obtain and keep a copy.
Why it matters — It is the maker's evidence that a high-risk system is compliant.
EU AI Act Art. 13
DPA (Data Processing Agreement)
The contract GDPR requires with any supplier that handles personal data for you. It binds them to protect it and only use it as you instruct.
Why it matters — Processing personal data through a tool with no DPA is a live GDPR gap.
GDPR Art. 28
DPIA
A Data Protection Impact Assessment — a structured check you do before high-risk data processing, to find and reduce risks to people.
Why it matters — Mandatory for certain processing, such as large-scale health data.
GDPR Art. 35
EU AI Act risk tier
How risky a use is under the EU AI Act: minimal, limited (needs transparency), or high (strict obligations).
EU/EEA data residency
Whether the tool stores and processes your data inside the EU/European Economic Area. Data leaving the EEA needs a legal safeguard.
GDPR Art. 44–49
FRIA
A Fundamental Rights Impact Assessment — a check of how a high-risk AI system could affect people's rights, done before you deploy it. Mainly for public bodies and similar.
Why it matters — Required for some deployers before a high-risk system goes live.
EU AI Act Art. 27
GPAI
A general-purpose AI model — a broad model like the one behind ChatGPT or Copilot that can do many things, rather than one narrow task.
Why it matters — Using a GPAI tool brings extra transparency and literacy duties.
EU AI Act Art. 52
High risk
Uses the EU AI Act treats as high-risk — recruitment, credit, health, education, biometrics. They carry the strictest obligations.
EU AI Act Annex III
Human oversight
A named person with the authority to watch over a high-risk AI system and step in — no important decision is left to the machine alone.
EU AI Act Art. 26(2)
Impact
How bad it would be if the risk happened, from 1 (negligible) to 5 (severe — a serious fine or real harm).
Instructions for use
The maker's official guidance on how to run the tool safely and correctly. You must obtain them and follow them.
EU AI Act Art. 26(1)
Lawful basis
The legal reason you're allowed to use someone's personal data — such as their consent, a contract, or a legitimate interest. Every use needs one.
GDPR Art. 6
Likelihood
How probable the risk is, from 1 (rare) to 5 (almost certain). Your best judgement is fine.
Limited risk
Customer-facing AI like chatbots or AI-written content. The main duty is transparency — telling people they're dealing with AI.
EU AI Act Art. 50
Logs
Records the AI system keeps of how it operated. For high-risk systems you retain these, as far as you technically can.
EU AI Act Art. 26(6)
Prohibited practices
A short list of AI uses the EU bans outright — such as manipulative systems, social scoring by authorities, or untargeted biometric surveillance. You confirm you use none.
EU AI Act Art. 5
Record of Processing Activities
A written record of what personal data you hold, why, and who you share it with. Think of it as an inventory of your data use.
GDPR Art. 30
Risk score
Likelihood multiplied by Impact, from 1 to 25. Higher scores need faster action: 16+ is Critical, 10–15 High, 5–9 Medium.
Sanctioned
Whether IT has formally approved the tool for work use. 'Unknown' is common — and itself worth flagging.
Special-category data
Extra-sensitive personal data — health, biometrics, race, religion, sexuality and the like. It needs stronger protection and an extra legal condition.
GDPR Art. 9
Standard Contractual Clauses
EU-approved contract terms that let you send personal data outside the EEA lawfully. One of the accepted safeguards for a transfer.
GDPR Art. 46
Subprocessor
A supplier your supplier uses to help handle your data — for example the cloud host behind a SaaS tool. They need to be covered too.
GDPR Art. 28