One interview, every regime
Answer once. Every regime that needs it uses it.
31 interview questions feed 25 documents. 23 of those answers are used under more than one regime — confirmed once, never retyped, and when one changes, every document that uses it is marked out of date.
| Interview answer | GDPR | UK GDPR | EU AI Act | NIS2 |
|---|---|---|---|---|
| Vendors and what each is used for7 documents | Privacy policy, Cookie policy, Data processing agreement, Subprocessor list, Records of processing activities, Vendor management policy | Privacy policy, Cookie policy, Data processing agreement, Subprocessor list, Records of processing activities, Vendor management policy | Vendor management policy | Vendor management policy, NIS2 supply chain security policy |
| Is there a human in the loop for decisions the AI systems support? Who, and how can they override4 documents | — | — | AI technical documentation, AI risk assessment, Fundamental rights impact assessment, AI human oversight procedure | — |
| Description of activities3 documents | Privacy policy, Data processing agreement, Security overview | Privacy policy, Data processing agreement, Security overview | Security overview | Security overview |
| Encryption at rest3 documents | Data processing agreement, Security overview | Data processing agreement, Security overview | Security overview | Security overview, NIS2 cybersecurity risk-management policy |
| Encryption in transit (TLS)3 documents | Data processing agreement, Security overview | Data processing agreement, Security overview | Security overview | Security overview, NIS2 cybersecurity risk-management policy |
| Two-factor sign-in for staff3 documents | Data processing agreement, Access control policy, Acceptable use policy | Data processing agreement, Access control policy, Acceptable use policy | Access control policy, Acceptable use policy | Access control policy, Acceptable use policy |
| Legal entity and jurisdiction of registration3 documents | Privacy policy, Data processing agreement, Records of processing activities | Privacy policy, Data processing agreement, Records of processing activities | — | — |
| Retention of customer data3 documents | Privacy policy, Records of processing activities, Retention schedule | Privacy policy, Records of processing activities, Retention schedule | — | — |
| Who is authorised to notify the authority of an incident, with a deputy3 documents | — | — | — | Incident response policy, NIS2 incident reporting procedure, NIS2 business continuity and crisis management plan |
| Backups, frequency, RPO2 documents | Business continuity and disaster recovery policy | Business continuity and disaster recovery policy | Business continuity and disaster recovery policy | Business continuity and disaster recovery policy, NIS2 business continuity and crisis management plan |
| Contact for data subject requests2 documents | Privacy policy, Data subject request procedure | Privacy policy, Data subject request procedure | — | — |
| Are the AI systems' logs kept, and for how long2 documents | — | — | AI technical documentation, AI logging policy | — |
| Which of the client's suppliers are critical: the service stops without them2 documents | — | — | — | NIS2 supply chain security policy, NIS2 business continuity and crisis management plan |
| Access revocation procedure1 document | Access control policy | Access control policy | Access control policy | Access control policy |
| Code review1 document | Secure development policy | Secure development policy | Secure development policy | Secure development policy |
| Environment separation1 document | Secure development policy | Secure development policy | Secure development policy | Secure development policy |
| Hosting or cloud provider of the product1 document | Security overview | Security overview | Security overview | Security overview |
| Hosting region1 document | Security overview | Security overview | Security overview | Security overview |
| Incident response procedure1 document | Incident response policy | Incident response policy | Incident response policy | Incident response policy |
| Penetration test, date of the last one1 document | Secure development policy | Secure development policy | Secure development policy | Secure development policy |
| Production access model1 document | Access control policy | Access control policy | Access control policy | Access control policy |
| B2B, B2C or mixed1 document | Privacy policy | Privacy policy | — | — |
| Handling on termination1 document | Data processing agreement | Data processing agreement | — | — |
| Log retention1 document | Retention schedule | Retention schedule | — | — |
| Processor or controller for customer end-user data1 document | Data processing agreement | Data processing agreement | — | — |
| Registered address1 document | Privacy policy | Privacy policy | — | — |
| Support ticket retention1 document | Retention schedule | Retention schedule | — | — |
| EU member states where the client provides its services or has establishments1 document | — | — | — | NIS2 cybersecurity risk-management policy |
| Have the management bodies approved the cybersecurity risk-management measures? When, and who1 document | — | — | — | NIS2 management accountability record |
| Is staff trained to work with AI systems? How and how often1 document | — | — | AI literacy policy | — |
| Sources of training data, where the client trains or fine-tunes a model1 document | — | — | AI technical documentation | — |
Vendors and what each is used for
- GDPR:
- Privacy policy, Cookie policy, Data processing agreement, Subprocessor list, Records of processing activities, Vendor management policy
- UK GDPR:
- Privacy policy, Cookie policy, Data processing agreement, Subprocessor list, Records of processing activities, Vendor management policy
- EU AI Act:
- Vendor management policy
- NIS2:
- Vendor management policy, NIS2 supply chain security policy
Is there a human in the loop for decisions the AI systems support? Who, and how can they override
- EU AI Act:
- AI technical documentation, AI risk assessment, Fundamental rights impact assessment, AI human oversight procedure
Description of activities
- GDPR:
- Privacy policy, Data processing agreement, Security overview
- UK GDPR:
- Privacy policy, Data processing agreement, Security overview
- EU AI Act:
- Security overview
- NIS2:
- Security overview
Encryption at rest
- GDPR:
- Data processing agreement, Security overview
- UK GDPR:
- Data processing agreement, Security overview
- EU AI Act:
- Security overview
- NIS2:
- Security overview, NIS2 cybersecurity risk-management policy
Encryption in transit (TLS)
- GDPR:
- Data processing agreement, Security overview
- UK GDPR:
- Data processing agreement, Security overview
- EU AI Act:
- Security overview
- NIS2:
- Security overview, NIS2 cybersecurity risk-management policy
Two-factor sign-in for staff
- GDPR:
- Data processing agreement, Access control policy, Acceptable use policy
- UK GDPR:
- Data processing agreement, Access control policy, Acceptable use policy
- EU AI Act:
- Access control policy, Acceptable use policy
- NIS2:
- Access control policy, Acceptable use policy
Legal entity and jurisdiction of registration
- GDPR:
- Privacy policy, Data processing agreement, Records of processing activities
- UK GDPR:
- Privacy policy, Data processing agreement, Records of processing activities
Retention of customer data
- GDPR:
- Privacy policy, Records of processing activities, Retention schedule
- UK GDPR:
- Privacy policy, Records of processing activities, Retention schedule
Who is authorised to notify the authority of an incident, with a deputy
- NIS2:
- Incident response policy, NIS2 incident reporting procedure, NIS2 business continuity and crisis management plan
Backups, frequency, RPO
- GDPR:
- Business continuity and disaster recovery policy
- UK GDPR:
- Business continuity and disaster recovery policy
- EU AI Act:
- Business continuity and disaster recovery policy
- NIS2:
- Business continuity and disaster recovery policy, NIS2 business continuity and crisis management plan
Contact for data subject requests
- GDPR:
- Privacy policy, Data subject request procedure
- UK GDPR:
- Privacy policy, Data subject request procedure
Are the AI systems' logs kept, and for how long
- EU AI Act:
- AI technical documentation, AI logging policy
Which of the client's suppliers are critical: the service stops without them
- NIS2:
- NIS2 supply chain security policy, NIS2 business continuity and crisis management plan
Access revocation procedure
- GDPR:
- Access control policy
- UK GDPR:
- Access control policy
- EU AI Act:
- Access control policy
- NIS2:
- Access control policy
Code review
- GDPR:
- Secure development policy
- UK GDPR:
- Secure development policy
- EU AI Act:
- Secure development policy
- NIS2:
- Secure development policy
Environment separation
- GDPR:
- Secure development policy
- UK GDPR:
- Secure development policy
- EU AI Act:
- Secure development policy
- NIS2:
- Secure development policy
Hosting or cloud provider of the product
- GDPR:
- Security overview
- UK GDPR:
- Security overview
- EU AI Act:
- Security overview
- NIS2:
- Security overview
Hosting region
- GDPR:
- Security overview
- UK GDPR:
- Security overview
- EU AI Act:
- Security overview
- NIS2:
- Security overview
Incident response procedure
- GDPR:
- Incident response policy
- UK GDPR:
- Incident response policy
- EU AI Act:
- Incident response policy
- NIS2:
- Incident response policy
Penetration test, date of the last one
- GDPR:
- Secure development policy
- UK GDPR:
- Secure development policy
- EU AI Act:
- Secure development policy
- NIS2:
- Secure development policy
Production access model
- GDPR:
- Access control policy
- UK GDPR:
- Access control policy
- EU AI Act:
- Access control policy
- NIS2:
- Access control policy
B2B, B2C or mixed
- GDPR:
- Privacy policy
- UK GDPR:
- Privacy policy
Handling on termination
- GDPR:
- Data processing agreement
- UK GDPR:
- Data processing agreement
Log retention
- GDPR:
- Retention schedule
- UK GDPR:
- Retention schedule
Processor or controller for customer end-user data
- GDPR:
- Data processing agreement
- UK GDPR:
- Data processing agreement
Registered address
- GDPR:
- Privacy policy
- UK GDPR:
- Privacy policy
Support ticket retention
- GDPR:
- Retention schedule
- UK GDPR:
- Retention schedule
EU member states where the client provides its services or has establishments
- NIS2:
- NIS2 cybersecurity risk-management policy
Have the management bodies approved the cybersecurity risk-management measures? When, and who
- NIS2:
- NIS2 management accountability record
Is staff trained to work with AI systems? How and how often
- EU AI Act:
- AI literacy policy
Sources of training data, where the client trains or fine-tunes a model
- EU AI Act:
- AI technical documentation
Read from the regime definitions the generator uses. NIS2 and the EU AI Act are add-on modules; their documents apply to the clients you enable them for.
See what changed since your clients' policies were written
Enter up to ten client websites. Free, no sign-up, the first report in about a minute.