These documents are template-level information for transparency. They are not certified legal translations or lawyer-approved equivalents in every language. For binding advice, consult qualified counsel. Enterprise customers receive executed MSA, Order Form, and counter-signed DPA — see Enterprise contracting.
Policy version: 2026-07-13 · EN
Data Protection Impact Assessment (DPIA) — Template
For: TrustOriginality.ai customers (controllers) processing personal data via the platform
Frameworks: GDPR Art. 35 · KVKK · EU AI Act (where personal data in AI systems)
Version: 0.1-skeleton · Date: 2026-06-16
Not legal advice — complete with your DPO / counsel.
1. Project overview
| Field |
Value |
| Project name |
[e.g. CMS AI screening / KYC verification] |
| Controller |
[Customer legal name] |
| Processor |
Soluzyn OÜ (DPA executed) |
| DPIA owner |
[Name, role] |
| Date |
[YYYY-MM-DD] |
| Review cycle |
[Annual / on material change] |
2. Description of processing
| Item |
Detail |
| Purpose |
[e.g. Detect undisclosed AI-generated media before publication] |
| Legal basis (GDPR Art. 6) |
[Legitimate interest / Consent / Contract — specify] |
| Special categories (Art. 9) |
[Yes/No — e.g. biometric KYC selfies via /api/kyc] |
| Data subjects |
[Employees, customers, students, claimants, etc.] |
| Personal data categories |
Content submitted for analysis; account metadata; IP logs; [biometric if KYC] |
| Minimization measures |
Text input SHA-256 hashing (optional); PDF retention [30] days; no raw text stored when hash-only mode enabled |
| Recipients |
TrustOriginality (processor); sub-processors per DPA Annex B |
| Transfers |
[EU / TR / US — specify SCCs if applicable] |
| Retention |
Per DPA Annex A and panel retention settings |
3. Necessity and proportionality
- Why is automated detection necessary vs manual review alone?
- What is the minimum data required (modality, resolution, duration)?
- Can hash-only or metadata-only modes suffice?
4. Risks to data subjects
| Risk |
Likelihood |
Severity |
Mitigation |
| False positive → wrongful publication block |
[L/M/H] |
[L/M/H] |
Human review threshold; appeal process |
| False negative → undisclosed AI content |
[L/M/H] |
[L/M/H] |
Multi-modal checks; provenance (C2PA) |
| Biometric misuse (KYC) |
[L/M/H] |
[L/M/H] |
Explicit consent; GET /api/kyc/privacy-notice; limited retention |
| Re-identification from logs |
[L/M/H] |
[L/M/H] |
Hashing; access controls; deletion API |
| Profiling in high-risk context |
[L/M/H] |
[L/M/H] |
Prohibited per AUP for sole automated Annex III decisions |
5. Measures to address risks
6. KVKK-specific (Türkiye)
| Item |
Detail |
| VERBİS registration |
[Customer obligation if applicable] |
| Data controller representative |
[If required] |
| Cross-border transfer |
[KVKK Board approval / undertakings if needed] |
| Explicit consent |
[For special categories / biometric] |
7. Consultation
8. Approval
| Role |
Name |
Signature |
Date |
| Controller representative |
|
|
|
| DPO |
|
|
|
- DPA:
legal/DPA-TEMPLATE.md
- Annex A processing description:
legal/annexes/ANNEX-A-DESCRIPTION-OF-PROCESSING.md
- Technical limitations:
legal/ANNEX-IV-TECHNICAL-DOCUMENTATION.md
- Panel:
DELETE /api/account · retention settings · activity log export