Find out where you are exposed under GDPR and the AI Act
If you use AI anywhere in hiring, you already have legal duties most companies have not started on.
Where should we start?
Your website is the part anyone can check without asking you. We read the page a first-time visitor gets, before anything is clicked.
We did not run any of your JavaScript. Everything above is what your page hands over on its own, so a consent banner that loads its trackers only after someone agrees will look clean here. What we found is evidence of a problem — finding nothing is not evidence that there isn't one.
The Privacy & AI Act Agent
Both of these are continuous obligations, and both change underneath you — a marketing tag added on a Tuesday, a new AI tool in the sales team, another piece of EU guidance. The agent keeps the register current instead of you rebuilding it before each audit.
- It watches the site. Re-checks who your pages hand visitors to and what is set before consent, and tells you when that changes — usually the week after somebody adds a tag.
- It keeps the registers. Processing register, data-processing agreements, and an inventory of every AI system in use with its risk tier — the documents you are asked for and never have ready.
- It handles the requests. Access and deletion requests get a tracked, on-time answer, and staff AI-literacy training is logged as it happens.
Eyetea · Privacy & AI Act agent · an outside-in view and an indicative tiering — not an audit, and not legal advice
We request your homepage and your privacy policy · nothing you answer here is sent anywhere or stored