
Role: Lead Designer
Scope: Information Architecture, Design
Platform: Web / B2B SaaS
Overview
When the EU AI Act was introduced, it created a massive, intimidating shift for the industry. Most companies were staring at a scary legal PDF with no idea how to actually "do" compliance. While GDPRLocal already had an existing portal for data protection, it wasn't equipped for these specific new AI requirements. Our team’s mission was to design and integrate a new suite of features that guided companies through this legal maze, turning a heavy regulatory burden into a manageable digital workflow. We worked on 5 new features: AI Literacy, AI Representative, AI Risk Assessment, AI Governance and AI Officer.
This case study focuses on the design of the AI Risk Assessment feature.
The Challenge
Discovery
The research phase was a deep dive into the legal requirements of Article 4, combined with a series of interviews with internal Data Protection Officers to understand where the current process stood.
What we learned?
Through the discovery sessions, we identified two friction points that guided the decisions we made:
Our first instinct was to design a fully automated tracker, one that would update milestones based on document uploads and system triggers alone. But the DPO interviews told a different story: a plan gets agreed on a call, not when a file lands in the portal. If we'd built a purely automated system, the progress bar would always be a step behind the actual work, and DPOs would end up manually overriding it anyway just to keep it honest. So we shifted to a hybrid model, automation where the system genuinely had visibility (document status, submissions), and manual validation where the real decision-making happens offline.


Solution
We focused on two key areas to turn this technical audit into a smooth, manageable experience for both the Admin and the Client Users.
The Hybrid Progress Stepper
I designed the stepper to let DPOs manually check off milestones reached in offline calls, since our research showed a fully automated system wouldn't reflect how compliance actually happens.
Milestone Tracking
HLFF
Plan Agreed
AI Compliance Checker
AI DPIA
Risk Assesment Completed
Compliance Report
Handover


Review & Comment Loop
We built a contextual commenting system that ties feedback directly to the document, so clients know exactly what's required to reach "Completed" status, without digging through email threads.


Key Takeaways & Impact
This was a new feature, so we had no usage metrics or analytics from a "before" version to compare against. What we did have was a clear picture of the current process: DPOs chasing technical specs through email threads, with no centralized source of truth. Our validation came from direct feedback during rollout and from how the pattern got reused afterward:
Direct DPO feedback: DPOs told us that having milestone validation and client comments in one place meant they no longer had to reconstruct status from scattered email threads. That was the exact friction point our discovery interviews pointed to as the biggest source of delay.
Reused beyond the original scope: The Hybrid Progress Stepper was adopted for GDPRLocal's other regulatory compliance workflows beyond AI.
Client portal



Admin portal



Thanks for stopping by.

Role: Lead Designer
Scope: Information Architecture, Design
Platform: Web / B2B SaaS
Overview
When the EU AI Act was introduced, it created a massive, intimidating shift for the industry. Most companies were staring at a scary legal PDF with no idea how to actually "do" compliance. While GDPRLocal already had an existing portal for data protection, it wasn't equipped for these specific new AI requirements. Our team’s mission was to design and integrate a new suite of features that guided companies through this legal maze, turning a heavy regulatory burden into a manageable digital workflow. We worked on 5 new features: AI Literacy, AI Representative, AI Risk Assessment, AI Governance and AI Officer.
This case study focuses on the design of the AI Risk Assessment feature.
The Challenge
Discovery
The research phase was a deep dive into the legal requirements of Article 4, combined with a series of interviews with internal Data Protection Officers to understand where the current process stood.
What we learned?
Through the discovery sessions, we identified two friction points that guided the decisions we made:
Our first instinct was to design a fully automated tracker, one that would update milestones based on document uploads and system triggers alone. But the DPO interviews told a different story: a plan gets agreed on a call, not when a file lands in the portal. If we'd built a purely automated system, the progress bar would always be a step behind the actual work, and DPOs would end up manually overriding it anyway just to keep it honest. So we shifted to a hybrid model, automation where the system genuinely had visibility (document status, submissions), and manual validation where the real decision-making happens offline.


Solution
We focused on two key areas to turn this technical audit into a smooth, manageable experience for both the Admin and the Client Users.
The Hybrid Progress Stepper
I designed the stepper to let DPOs manually check off milestones reached in offline calls, since our research showed a fully automated system wouldn't reflect how compliance actually happens.
Milestone Tracking
HLFF
Plan Agreed
AI Compliance Checker
AI DPIA
Risk Assesment Completed
Compliance Report
Handover


Review & Comment Loop
We built a contextual commenting system that ties feedback directly to the document, so clients know exactly what's required to reach "Completed" status, without digging through email threads.


Key Takeaways & Impact
This was a new feature, so we had no usage metrics or analytics from a "before" version to compare against. What we did have was a clear picture of the current process: DPOs chasing technical specs through email threads, with no centralized source of truth. Our validation came from direct feedback during rollout and from how the pattern got reused afterward:
Direct DPO feedback: DPOs told us that having milestone validation and client comments in one place meant they no longer had to reconstruct status from scattered email threads. That was the exact friction point our discovery interviews pointed to as the biggest source of delay.
Reused beyond the original scope: The Hybrid Progress Stepper was adopted for GDPRLocal's other regulatory compliance workflows beyond AI.
Client portal



Admin portal



Thanks for stopping by.

Role: Lead Designer
Scope: Information Architecture, Design
Platform: Web / B2B SaaS
Overview
When the EU AI Act was introduced, it created a massive, intimidating shift for the industry. Most companies were staring at a scary legal PDF with no idea how to actually "do" compliance. While GDPRLocal already had an existing portal for data protection, it wasn't equipped for these specific new AI requirements. Our team’s mission was to design and integrate a new suite of features that guided companies through this legal maze, turning a heavy regulatory burden into a manageable digital workflow. We worked on 5 new features: AI Literacy, AI Representative, AI Risk Assessment, AI Governance and AI Officer.
This case study focuses on the design of the AI Risk Assessment feature.
The Challenge
Discovery
The research phase was a deep dive into the legal requirements of Article 4, combined with a series of interviews with internal Data Protection Officers to understand where the current process stood.
What we learned?
Through the discovery sessions, we identified two friction points that guided the decisions we made:
Our first instinct was to design a fully automated tracker, one that would update milestones based on document uploads and system triggers alone. But the DPO interviews told a different story: a plan gets agreed on a call, not when a file lands in the portal. If we'd built a purely automated system, the progress bar would always be a step behind the actual work, and DPOs would end up manually overriding it anyway just to keep it honest. So we shifted to a hybrid model, automation where the system genuinely had visibility (document status, submissions), and manual validation where the real decision-making happens offline.


Solution
We focused on two key areas to turn this technical audit into a smooth, manageable experience for both the Admin and the Client Users.
The Hybrid Progress Stepper
I designed the stepper to let DPOs manually check off milestones reached in offline calls, since our research showed a fully automated system wouldn't reflect how compliance actually happens.
Milestone Tracking
HLFF
Plan Agreed
AI Compliance Checker
AI DPIA
Risk Assesment Completed
Compliance Report
Handover


Review & Comment Loop
We built a contextual commenting system that ties feedback directly to the document, so clients know exactly what's required to reach "Completed" status, without digging through email threads.


Key Takeaways & Impact
This was a new feature, so we had no usage metrics or analytics from a "before" version to compare against. What we did have was a clear picture of the current process: DPOs chasing technical specs through email threads, with no centralized source of truth. Our validation came from direct feedback during rollout and from how the pattern got reused afterward:
Direct DPO feedback: DPOs told us that having milestone validation and client comments in one place meant they no longer had to reconstruct status from scattered email threads. That was the exact friction point our discovery interviews pointed to as the biggest source of delay.
Reused beyond the original scope: The Hybrid Progress Stepper was adopted for GDPRLocal's other regulatory compliance workflows beyond AI.
Client portal



Admin portal



Thanks for stopping by.