EU AI Act + GDPR · 8 jurisdiction-specific documents · One-time purchase

AI governance documents built for EU obligations.

The EU AI Act (Regulation 2024/1689) and GDPR create obligations that a jurisdiction-neutral pack cannot cover. The EU Pro Pack adds 8 documents that map your AI tools to the risk tiers, record processing activities, and prepare you for breach notification — all referenced directly to the regulation articles that require them.

Referenced to EU AI Act articlesGDPR Art. 22, 30, 35 coveredEditable DOCX and XLSX files7-day guarantee
EU PRO PACK · RULEFRAMEXLSX

EU AI Act Art. 6–9 · Risk classification

EU AI Act Risk Classification Worksheet

[Company Name] · Completed [Date] · Owner [Name]

01

AI tool or system

ChatGPT, Copilot, Workable…

02

Risk tier

Prohibited / High / Limited / Minimal

03

Obligations triggered

Transparency, logging, human oversight…

04

Review date

Annual or on material change

EU AI Act

Regulation (EU) 2024/1689, in force August 2024

Review source

GDPR

Regulation (EU) 2016/679 — Arts. 22, 28, 30, 33–35

Review source

EDPB Guidelines on AI

European Data Protection Board, 2024–2025

Review source

Who needs this

The EU AI Act applies to more businesses than most SMEs realise.

Extraterritorial reach means the Act covers any AI system placed on the EU market or put into service in the EU — regardless of where the business is registered. A US e-commerce company with EU customers, a UK agency with EU clients, or an Irish SME using a US AI tool may all have obligations under Regulation 2024/1689.

EU-based businesses

Any SME in Germany, France, the Netherlands, Ireland, or elsewhere in the EU using AI tools.

Non-EU companies with EU customers

US and UK companies whose AI systems process data from EU residents or target EU users.

Companies using high-risk AI

Recruitment, HR, credit scoring, and customer-facing AI systems are classified high-risk under Annex III.

GDPR-obligated businesses

Any organisation processing EU personal data — GDPR obligations for AI (Art. 22, 30, 35) apply independently of the AI Act.

What is included

8 documents, each referenced directly to the regulation article that requires it.

Every file in this pack exists because a specific EU AI Act or GDPR article creates an obligation that the Starter Pack does not cover. Files that would be near-identical to the Starter Pack equivalent were not included — the Pro Pack earns its price on every document.

1 file

Classification

EU AI Act Risk Classification Worksheet

XLSX
EU AI Act Art. 6–9 (Reg. 2024/1689)

Maps each AI tool your business uses to the four risk tiers: prohibited, high-risk, limited-risk, and minimal-risk. The EU AI Act assigns different obligations by tier — this worksheet is the first step in knowing what applies to you.

2 files

Policies

EU-Aligned AI Usage Policy

DOCX + PDF
EU AI Act + GDPR Art. 22

The Starter Pack usage policy, extended with tier-specific obligations under the EU AI Act and GDPR Article 22 automated decision-making rules. Materially different from the neutral version.

EU AI Transparency Disclosure

DOCX + PDF
EU AI Act Art. 50 + GDPR Art. 13–14

Customer-facing and employee-facing language explaining AI use, combining Article 50 EU AI Act transparency obligations with GDPR Articles 13–14 AI-specific privacy notice requirements.

2 files

Records

GDPR AI Data Processing Register

XLSX
GDPR Art. 30

Records each AI system, its lawful basis for processing personal data, the data categories involved, and retention periods. GDPR Article 30 requires controllers to maintain processing records; no Starter Pack equivalent covers this.

DPIA Trigger Checklist

XLSX
GDPR Art. 35 + EDPB Guidelines

Determines whether a Data Protection Impact Assessment is required for an AI use case, following GDPR Article 35 criteria and European Data Protection Board guidelines. No Starter Pack equivalent — required before deploying AI systems that process personal data at scale.

2 files

Checklists

GDPR Data Input Rules Checklist

XLSX
GDPR Art. 5–6, Art. 9

The Starter Pack data input checklist extended with a lawful basis column and special-category data (health, biometric, ethnic origin) flagging — the data types EU AI Act high-risk systems most commonly touch.

EU AI Vendor Due Diligence Checklist

XLSX
EU AI Act Art. 25–28 + GDPR Art. 28

The Starter Pack vendor review checklist plus CE marking verification, conformity assessment checks, and processor agreement requirements under GDPR Article 28. Required before deploying any high-risk AI system from a third-party provider.

1 file

Response

EU AI Incident Response Procedure

DOCX + PDF
EU AI Act Art. 73 + GDPR Art. 33–34

The Starter Pack incident procedure extended with the 72-hour GDPR data breach notification clock and the EU AI Act Article 73 serious incident reporting path to the market surveillance authority.

EU AI Governance Pro Pack

$49one-time payment
  • All 8 EU-specific documents
  • 3 editable DOCX + PDF files
  • 5 fillable XLSX worksheets
  • Referenced to EU AI Act articles
  • Lifetime file access
  • 7-day money-back guarantee

Already have the Starter Pack? The EU Pro Pack + Starter Pack bundle is available at checkout for $69 — save $9 versus buying separately.

Get the EU Pro Pack — $49

Secure checkout and invoice through Lemon Squeezy. VAT applied where required.

Questions

Before you purchase.

Does the EU AI Act apply to my business?
If your business has EU customers, EU employees, or processes personal data of people in the EU, some obligations apply regardless of where your company is headquartered. The EU AI Act (Regulation 2024/1689, in force August 2024) has extraterritorial reach for AI systems placed on the EU market or put into service in the EU. Most SMEs using AI tools like ChatGPT, Copilot, or recruitment software fall into the limited-risk or minimal-risk tiers, which have lighter obligations — but the risk classification step is still required.
Do I need the Starter Pack too?
The EU Pro Pack adds EU-specific documents on top of a foundation of good AI governance practice. It is designed to complement the Starter Pack (L1), not replace it. The Starter Pack covers neutral operational rules, employee guidance, and training notes that are not EU-specific. If you already have internal AI governance documents, review them against the EU Pro Pack before purchasing both.
Is this legal or compliance advice?
No. The pack provides practical operational templates informed by the EU AI Act (Regulation 2024/1689), GDPR, and European Data Protection Board guidance. It does not guarantee regulatory compliance, does not constitute legal advice, and does not replace a qualified lawyer or DPO for your specific obligations. Requirements vary by AI system type, risk tier, sector, and business context.
What formats are included?
Three documents are provided as editable DOCX and polished PDF files: the EU-Aligned AI Usage Policy, the EU AI Transparency Disclosure, and the EU AI Incident Response Procedure. Five worksheets are provided as fillable XLSX workbooks: the Risk Classification Worksheet, GDPR Data Processing Register, GDPR Data Input Rules Checklist, EU AI Vendor Due Diligence Checklist, and DPIA Trigger Checklist.
What is the refund policy?
7-day money-back guarantee. Contact us within seven days of purchase if the materials do not meet your needs.

Keep going

Start with the foundation, or read the background

Important disclaimer

The EU AI Governance Pro Pack provides operational guidance and templates informed by the EU AI Act (Regulation 2024/1689), GDPR, and European Data Protection Board guidelines. It is not legal advice, does not guarantee regulatory compliance, and does not substitute for qualified legal or data protection counsel. Requirements vary by AI system risk tier, sector, business context, and member state implementation. Consult a qualified lawyer or Data Protection Officer for obligations specific to your situation.