Compliance

Compliance

Our regulatory compliance posture across GDPR, EU AI Act, Privacy by Design, Security by Design, and Responsible AI frameworks.

Last reviewed: August 2026

Overview

Compliance Status

Real-time compliance status across our key regulatory frameworks.

✓ Active Compliance

GDPR

General Data Protection Regulation (EU) 2016/679. Full compliance implemented including privacy notices, DPAs, data subject rights procedures, and breach notification protocols.

In Preparation

EU AI Act

Regulation (EU) 2024/1689. Actively preparing for compliance. Our AI systems are classified and risk-assessed. Human oversight and transparency measures already in place.

✓ Active Compliance

Privacy by Design

Privacy is embedded into all our systems and processes from the design phase, not added as an afterthought. All new features undergo privacy impact assessment.

✓ Active Compliance

Security by Design

Security requirements are built into our software development lifecycle from the earliest stages. Threat modeling, secure code review, and penetration testing are standard practice.

✓ Active Compliance

Responsible AI

Our AI development follows principles of safety, transparency, fairness, and human oversight. We maintain an internal AI ethics review process for all new AI deployments.

Evaluating

ISO 27001

We are evaluating ISO 27001 certification for our Information Security Management System. Our current practices align with ISO 27001 requirements.

GDPR

GDPR Compliance Details

What We've Implemented

Privacy Notice and Cookie Policy with clear consent mechanisms
Data Processing Agreements (DPAs) available for all enterprise clients
Data Subject Rights procedures: access, rectification, erasure, portability, objection
72-hour breach notification process documented and tested
Records of Processing Activities (RoPA) maintained
Data minimization and purpose limitation enforced
Sub-processor list maintained and updated
International transfer safeguards (SCCs for data transfers to USA)

Your Rights Under GDPR

Right to Access (Art. 15)
Request a copy of your personal data within 30 days
Right to Erasure (Art. 17)
Request deletion of your data where legally permissible
Right to Portability (Art. 20)
Receive your data in machine-readable format
Right to Object (Art. 21)
Object to processing based on legitimate interests
Submit a GDPR Request
EU AI Act

EU AI Act Preparedness

The EU AI Act (Regulation 2024/1689) establishes a risk-based framework for AI systems. Here is our readiness status.

Risk Classification

Low-Risk AI Applications
Customer service chatbots, content recommendation, scheduling assistants — our primary deployments fall in this category
Limited-Risk AI Applications
Healthcare booking and clinical data handling — subject to transparency requirements which we already implement
Prohibited Uses
We do not build or deploy AI for biometric surveillance, social scoring, or manipulation — all explicitly prohibited by the EU AI Act

Preparedness Checklist

AI system inventory and risk classification completed
Human oversight mechanisms implemented for all AI deployments
Transparency: users informed when interacting with AI
AI system logging and auditability in place
!
Conformity assessment documentation in progress
!
Technical documentation for high-risk systems in progress
Principles

Privacy & Security by Design

Privacy by Design (PbD)

We implement all 7 foundational principles of Privacy by Design:

Proactive: Privacy problems are anticipated and prevented, not remediated
Default: Maximum privacy protection is the default setting
Embedded: Privacy is embedded into design, not bolted on
Positive sum: Privacy and security are not traded off against each other
End-to-end: Privacy is maintained throughout the data lifecycle
Visibility: Operations are transparent and verifiable
User-centric: Data subjects are kept at the center of all decisions

Security by Design (SbD)

Security is a first-class requirement in our software development lifecycle:

Threat modeling for all new product features
Secure code review in pull request process
Automated vulnerability scanning in CI/CD pipeline
OWASP Top 10 addressed in development guidelines
Dependency vulnerability monitoring (Dependabot)
Periodic penetration testing by external security firms
Security training for all engineering team members
Responsible AI

Our Responsible AI Commitment

Blue Bridge is committed to AI that benefits organizations while respecting individual rights and societal values.

Transparency

We always disclose when users are interacting with AI. Our AI systems do not deceive users about their AI nature.

Fairness

We evaluate AI outputs for bias and implement corrective measures. AI decisions can be reviewed and overridden by humans.

Human Oversight

All AI systems have clear escalation paths to human agents. No fully autonomous AI decisions in high-stakes domains without human review.

Privacy

AI systems are designed with data minimization. We do not use client data to train our foundation models without explicit consent.

🚫
No Prohibited Uses

We do not build AI for mass surveillance, biometric identification without consent, social credit scoring, or psychological manipulation.

Accountability

We maintain internal AI ethics reviews for all new deployments. We take responsibility for AI systems we build and deploy.

Compliance Questions?

Our compliance team responds to enterprise inquiries within 5 business days.

compliance@bluebridge.es View Trust Center