Documentation

Getting started

The small business compliance journey

This is the whole journey in one pass, following a fictional small retailer through every step from a blank account to an evidenced compliance posture. It maps to the same order the platform itself enforces: describe the organisation, register every system, classify each AI system's risk, work the checklists that generates, produce the documents the law expects, and keep the evidence up to date.

Transcript

Meet Nordwind Goods. They sell home and garden products online and from two small shops, with around forty staff. Like most small businesses, they use AI every day, most visibly a customer support chatbot on their website.

Their compliance lead, Amara, has created the company account and signed in. This is where the work begins: the platform that will track the whole programme.

Both regulations rest on the same idea. GDPR Article 5 paragraph 2 does not just require you to comply, it requires you to be able to demonstrate that you comply. The AI Act extends the same duty with records, logs, and documentation.

Here is the whole journey. Tell the platform about the company, register every system, classify their risk, work the checklists that generates, produce the documents the law expects, and keep the evidence up to date.

A fresh account lands on an empty dashboard with one clear starting point: complete onboarding, and the platform will shape itself around the company.

Let us start onboarding for Nordwind Goods.

First, the company name. This appears throughout the platform and on every generated document, so it should match the registered legal name.

The questions map the company to the right obligations. Does Nordwind use or develop AI systems? Yes, the chatbot.

Nordwind bought the chatbot rather than building it, so it is a deployer: it uses an AI system under its own authority. That distinction matters because the AI Act puts different duties on providers and deployers.

Sector and company size. Retail, and small, with eleven to fifty employees. These answers tune which obligations the platform will surface.

Nordwind is a private company, so it is not a public authority, and the last two questions can be honest too: there is no steering committee yet, and no documented lifecycle policy. That is the point of the exercise.

Next, the frameworks. EU GDPR is always on, and because the company uses AI, the EU AI Act is switched on for them. Keep both.

Complete onboarding. The company profile is set, both regimes are enabled, and the obligation engine is now generating the checklist for everything that applies.

Go to My Obligations to see the result.

This is the generated obligation set. Every article that applies to Nordwind, across the AI Act and GDPR, with a platform-managed path, an action for you, and an overall posture score.

Now the system inventory. Nothing is registered yet, and nothing can be assessed, documented, or evidenced until it exists here.

Register Nordwind's first AI system, the support chatbot.

The name, the owner, and the vendor. Nordwind bought the chatbot from a vendor, so the vendor is named. These details go straight into the inventory and, later, the documentation.

The purpose is what makes it an AI system: it answers customer questions and handles order tracking in natural language.

And the data it processes. The chatbot sees chat transcripts, order details, and customer contact information, which is personal data. Register it.

The chatbot is registered and now has its own workspace. Back to the inventory to add the rest of the estate.

Small businesses also run plenty of systems that are not AI. Nordwind's customer relationship management system holds customer accounts and order history, so it needs registering as a standard IT system.

The CRM processes names, addresses, and purchase history, so it sits squarely under GDPR. Register it.

Two systems now in the inventory, one AI and one not, and the compliance engine is tracking both.

Every AI system needs a risk classification, because the AI Act calibrates its obligations to it. Open the chatbot's risk and impact tab.

Start the risk assessment. The questions mirror the AI Act's own logic, walking through purpose, sector, and the Annex three high risk areas.

Its purpose is natural language processing: the chatbot.

It serves the general public, in general business. No high risk sector under Annex three applies.

The screening questions come next: no subliminal techniques, no exploitation of vulnerable groups, no social scoring, no employment decisions, and no impact on access to essential services. Nordwind's chatbot passes all of them.

There is human oversight: the chatbot hands complex cases to a person. But there are two honest answers here. The chatbot can generate content that reads as human, and customers are not always told they are talking to a machine.

Submit the assessment.

The chatbot is classified as limited risk, under Article 50. Not high risk, but the transparency obligation still applies: people interacting with it must be told it is an AI.

The classification generated a real compliance checklist for the chatbot, spanning both regimes. Open it.

Every item is an obligation. Working one here shows the pattern: read the requirement, and mark it complete with evidence. This is how the audit trail is built.

Progress updates instantly, and the same figure feeds the dashboard, the obligations page, and the report.

Documents come next. Governance and Docs holds the whole catalogue: AI governance policy, records of processing, breach reports, and more.

GDPR Article 30 requires a record of processing activities: what you process, why, and who you share it with. One click generates the draft from everything already in the platform.

The same goes for the AI governance policy, the document that sets out how the company will run its AI responsibly. Generate it, and review the draft in the preview.

Now the GDPR side of day to day work. The Trust and Privacy Hub holds requests, breaches, processors, and consent.

A customer has asked for a copy of everything Nordwind holds about them. That is a data subject request under Article 15, and it has a hard one month deadline. Log it.

The countdown starts immediately, because a data subject request is a legal deadline, not good practice.

And if the worst happens, a personal data breach has a seventy two hour clock. Nordwind's support engineer emailed an export to the wrong recipient. Log it with the detail.

The seventy two hour notification countdown is now running, and the platform will walk the team through the notification itself.

The AI Act's Article 4 requires every organisation to ensure AI literacy among its staff. The platform turns that into a short assessment. Open it.

Answer the questions. For a small team this is a quick, practical way to prove the literacy duty is being met.

Passed. The certificate is evidence, ready to attach to the compliance record.

Post market monitoring under Article 72 keeps the record live after deployment. Open the chatbot's monitoring timeline.

Add a monitoring entry: a weekly review of the chatbot's performance, with the metrics that back it up.

And when something goes wrong with a system, Article 73 requires an incident report. Nordwind's chatbot briefly misrouted a refund request. Log the incident with its impact and corrective action.

Compliance is a team job. Invite Priya, who handles support, as an editor so she can log requests and evidence without admin rights.

Now the evidence that ties it together. Upload the bias evaluation report for the chatbot to the evidence vault, linked to the system.

Every action, from registration to this upload, is in the audit trail with its actor and timestamp. That is accountability made visible.

Back on the dashboard, the picture has changed completely. Systems registered, framework scores rising, urgent alerts with their deadlines, and the whole programme now visible at a glance.

That is the journey: onboard, register, classify, work the checklists, document, and keep the evidence current. None of it is one big step, it is a steady pattern, and this platform exists to make it repeatable.

Why this is required

Both regimes rest on the same idea: it is not enough to comply, you must be able to demonstrate that you comply. GDPR Article 5(2) states that duty explicitly and calls it accountability; the AI Act extends it through records, logs and documentation.

For a small business the volume is smaller but the structure is identical. One AI chatbot and one CRM still produce a risk classification, checklist items, records of processing, incident and breach registers, and an audit trail. The order in which these appear is not optional — nothing can be assessed, documented or evidenced until it exists in the inventory.

What EuroCompliant does

The onboarding wizard maps the organisation to its obligation set: sector, size, and whether it is a provider, a deployer, or both. Enabling the frameworks you are actually subject to generates the checklist items and document types for that set.

Every registered system, AI or conventional, becomes the anchor for its own risk classification, compliance checklist, documents and monitoring. The risk assessment mirrors the AI Act's own logic, so a retail support chatbot lands on the transparency obligations of Article 50 rather than the heavy high-risk duties of Annex III.

The GDPR day-to-day work — data subject requests with their one-month deadline, breach reports with their seventy-two hour clock, records of processing, processors and consent — runs alongside the AI Act duties of literacy, post-market monitoring and incident reporting. Every action lands in the audit trail.

Deadlines

72 hoursA personal data breach must be notified to the supervisory authority within 72 hours of becoming aware of it (GDPR Art. 33).
1 monthA data subject request must be answered within one month of receipt (GDPR Art. 12).
15 daysA serious AI incident must be reported to the market surveillance authority within 15 days (EU AI Act Art. 73).

Walking through it

1

Onboard your organisation

Company name, sector, size and AI value-chain role. These answers determine which obligations apply, and both core frameworks (GDPR, EU AI Act) are enabled.

Open /onboarding →
2

Register every system

AI systems and conventional IT systems that process personal data. The inventory is what every other obligation attaches to.

Open /systems →
3

Classify each AI system's risk

Run the assessment. The classification decides which AI Act duties apply — Article 50 transparency for a limited-risk chatbot, far more for high-risk systems.

Open /assessment →
4

Work the generated checklists

Each classified system produces its obligation set. Complete items and attach evidence as you go.

Open /compliance-docs →
5

Generate your documents

Records of processing, the AI governance policy, technical documentation and the rest, generated from the data already in the platform.

Open /compliance-docs →
6

Handle GDPR and AI Act duties

Data subject requests, breach reports, processors, consent, AI literacy, post-market monitoring and incident reporting.

Open /privacy-hub →

The law

Frequently asked

We are a small company — do we really need all of this?

The obligations scale by what you process and what your systems do, not by headcount. If you run an AI system that processes personal data, both the GDPR and the AI Act apply to you, and the audit trail requirement in particular does not have a small-business exemption. The volume of work is smaller than for a large enterprise, but the structure — register, classify, document, evidence — is the same.

Where does the tutorial start?

From a blank account. Nothing is pre-loaded: the onboarding, the systems, the assessment and every GDPR and AI Act record are created live on camera, so you can follow along with your own company.

Do I have to do everything at once?

No, but the order is fixed. Register systems first, because the inventory is what every obligation attaches to. Prohibited practices and the AI literacy duty are already in force, so those are worth checking immediately.

Related guides

Try it on your own systems

Everything in this guide runs in the live product. Start a free trial and follow along with your own data.

Start free trial