00. How to use this kit
A fast path through risk classification, GDPR data flows, documentation, and controls.
Purpose. This kit helps you understand and reduce AI-related regulatory risk under the EU AI Act and GDPR at a practical level. It is not legal advice and does not certify compliance.
Recommended path (60–120 minutes):
- Classify AI risk (Section 02)
- Map personal data flows (Section 03)
- Document your AI system (Section 04)
- Review basic controls (Section 05)
When to stop. Stop DIY and seek validation if (a) risk is medium/high, (b) outputs affect individuals materially, (c) sensitive data is involved, (d) enterprise procurement requires formal answers, or (e) you are unsure about any key decision.