SIS-licensed ISO clauses and controls·an add-on inside the AI clients and agents you already use
    Sector · Privacy

    Privacy & data protection

    Data protection that grounds every answer in the article, then turns it into evidence.

    Ansvar is a gateway for the AI assistant your team already uses — Claude, Microsoft Copilot, any MCP client. Connect it, and every answer below comes back cited to the provision or marked unresolved.

    29DPIA jurisdiction evidence paths
    99GDPR articles, addressable
    doc://paragraph-level citations

    Privacy work starts with the GDPR article and keeps the national source in view. The DPIA screen routes from confirmed jurisdiction scope to the available authority trigger material, then carries the assessment through necessity, proportionality, risks, safeguards, and Article 36. Every factual finding is cited or left unresolved.

    what we cover

    The law and standards we ground on

    Regulation

    GDPR (Reg (EU) 2016/679)

    full article-level, recitals included

    Regulation

    ePrivacy Directive (2002/58/EC)

    Regulation

    Law Enforcement Directive (EU) 2016/680

    Regulation

    GDPR Art. 22 — automated individual decision-making

    plus the EU AI Act intersection for AI-driven decisions

    Law

    National GDPR-implementation statutes

    audited GREEN set — see /coverage for the live jurisdiction footprint

    GuidancePremium

    Case-law fan-out where licensing permits

    arrives inside search on Premium and above

    what you can do

    Workflows that turn it into evidence

    DPIA — GDPR Article 35 with jurisdiction-aware national screening

    screen the GDPR baseline and the national trigger evidence available across 29 operational jurisdictional source paths, with Germany (BDSG) and Sweden (IMY) variants; drives Art. 36 prior-consultation and severity × likelihood scoring

    LINDDUN privacy threat model

    systematic privacy-threat elicitation over your data-flow diagram

    Document review, paragraph-cited

    a privacy notice, DPA, RoPA or processor contract against GDPR, each finding anchored to a doc:// segment

    GDPR gap analysis

    cited gap register with PDF / CSV / GRC-import export

    STRIDE threat model for Art. 32 TOMs

    security-of-processing measures evidenced against the article

    FRIA — EU AI Act Art. 27

    for AI systems processing personal data

    assembledTeam

    National-divergence & transfer analysis

    cross-jurisdiction comparison, legitimate-interest balancing (Art. 6(1)(f)), Chapter V transfers — assembled from cited research

    STRIDE threat-model workflows run on every plan against a system you describe — 1 run a month on Free, 2 on Solo, 5 on Premium, which also adds the LINDDUN and TARA families, the rendered reports, and case law inside the run. Document-grounded workflows run on Team and Company. Every tier runs the same corpora as cited research inside your own AI client.

    Questions buyers ask first

    Do you store our documents or personal data?
    No. Your AI client connects to the gateway and the corpora answer source-scoped questions; the MCP servers store no client data. Uploaded documents you review are held under your own tenant and cited by segment hash.
    Is the case law in the answer reliable?
    Case law arrives through premium fan-out only where the source licensing permits it, and every hit is cited to the deciding body. Where no licensed case-law source covers a point, the answer says so rather than inventing one.
    Which national data-protection laws are covered?
    The EU-level GDPR text is on every tier. National implementation statutes are covered for the audited GREEN jurisdictions listed on /coverage. National DPA enforcement decisions are out of scope where their licensing does not permit redistribution.

    Run it against your own systems

    Connect the AI client you already use and ask your first cited question — Free, Solo, Premium and Team are self-serve.

    Building privacy compliance? It works today — we take on a few design partners per sector to tune it to your team.