s.m

Expanding a compliance portal to handle the complexities of new AI regulations.

Role: Lead Designer

Scope: Information Architecture, Design

Platform: Web / B2B SaaS

Overview

When the EU AI Act was introduced, it created a massive, intimidating shift for the industry. Most companies were staring at a scary legal PDF with no idea how to actually "do" compliance. While GDPRLocal already had an existing portal for data protection, it wasn't equipped for these specific new AI requirements. Our team’s mission was to design and integrate a new suite of features that guided companies through this legal maze, turning a heavy regulatory burden into a manageable digital workflow. We worked on 5 new features: AI Literacy, AI Representative, AI Risk Assessment, AI Governance and AI Officer.

This case study focuses on the design of the AI Risk Assessment feature.

The Challenge

For Clients

Clients didn't know which technical details actually mattered to the law, and had no visibility into their product's audit readiness.

For Data Protection Officers

DPOs were chasing technical specs through email threads, with no centralized way to validate milestones or maintain a single source of truth across multiple client products.

Discovery

The research phase was a deep dive into the legal requirements of Article 4, combined with a series of interviews with internal Data Protection Officers to understand where the current process stood.

What we learned?

Through the discovery sessions, we identified two friction points that guided the decisions we made:

The status Gap

80% of the friction wasn't legal work, it was status checking. Clients were anxious because they couldn't see progress. DPOs were overwhelmed because they had no way to track it.

The Offline Reality

Compliance doesn't just happen in an app, it happens on Zoom calls and in strategy meetings. We discovered that a rigid, automated system would fail so we needed a "Hybrid" model where humans could manually validate the progress.

Our first instinct was to design a fully automated tracker, one that would update milestones based on document uploads and system triggers alone. But the DPO interviews told a different story: a plan gets agreed on a call, not when a file lands in the portal. If we'd built a purely automated system, the progress bar would always be a step behind the actual work, and DPOs would end up manually overriding it anyway just to keep it honest. So we shifted to a hybrid model, automation where the system genuinely had visibility (document status, submissions), and manual validation where the real decision-making happens offline.

Solution

We focused on two key areas to turn this technical audit into a smooth, manageable experience for both the Admin and the Client Users.

The Hybrid Progress Stepper

I designed the stepper to let DPOs manually check off milestones reached in offline calls, since our research showed a fully automated system wouldn't reflect how compliance actually happens.

Milestone Tracking

HLFF

Plan Agreed

AI Compliance Checker

AI DPIA

Risk Assesment Completed

Compliance Report

Handover

Review & Comment Loop

We built a contextual commenting system that ties feedback directly to the document, so clients know exactly what's required to reach "Completed" status, without digging through email threads.

Key Takeaways & Impact

This was a new feature, so we had no usage metrics or analytics from a "before" version to compare against. What we did have was a clear picture of the current process: DPOs chasing technical specs through email threads, with no centralized source of truth. Our validation came from direct feedback during rollout and from how the pattern got reused afterward:

Direct DPO feedback: DPOs told us that having milestone validation and client comments in one place meant they no longer had to reconstruct status from scattered email threads. That was the exact friction point our discovery interviews pointed to as the biggest source of delay.

Reused beyond the original scope: The Hybrid Progress Stepper was adopted for GDPRLocal's other regulatory compliance workflows beyond AI.

Client portal

Admin portal

Thanks for stopping by.

Expanding a compliance portal to handle the complexities of new AI regulations.

Role: Lead Designer

Scope: Information Architecture, Design

Platform: Web / B2B SaaS

Overview

When the EU AI Act was introduced, it created a massive, intimidating shift for the industry. Most companies were staring at a scary legal PDF with no idea how to actually "do" compliance. While GDPRLocal already had an existing portal for data protection, it wasn't equipped for these specific new AI requirements. Our team’s mission was to design and integrate a new suite of features that guided companies through this legal maze, turning a heavy regulatory burden into a manageable digital workflow. We worked on 5 new features: AI Literacy, AI Representative, AI Risk Assessment, AI Governance and AI Officer.

This case study focuses on the design of the AI Risk Assessment feature.

The Challenge

For Clients

Clients didn't know which technical details actually mattered to the law, and had no visibility into their product's audit readiness.

For Data Protection Officers

DPOs were chasing technical specs through email threads, with no centralized way to validate milestones or maintain a single source of truth across multiple client products.

Discovery

The research phase was a deep dive into the legal requirements of Article 4, combined with a series of interviews with internal Data Protection Officers to understand where the current process stood.

What we learned?

Through the discovery sessions, we identified two friction points that guided the decisions we made:

The status Gap

80% of the friction wasn't legal work, it was status checking. Clients were anxious because they couldn't see progress. DPOs were overwhelmed because they had no way to track it.

The Offline Reality

Compliance doesn't just happen in an app, it happens on Zoom calls and in strategy meetings. We discovered that a rigid, automated system would fail so we needed a "Hybrid" model where humans could manually validate the progress.

Our first instinct was to design a fully automated tracker, one that would update milestones based on document uploads and system triggers alone. But the DPO interviews told a different story: a plan gets agreed on a call, not when a file lands in the portal. If we'd built a purely automated system, the progress bar would always be a step behind the actual work, and DPOs would end up manually overriding it anyway just to keep it honest. So we shifted to a hybrid model, automation where the system genuinely had visibility (document status, submissions), and manual validation where the real decision-making happens offline.

Solution

We focused on two key areas to turn this technical audit into a smooth, manageable experience for both the Admin and the Client Users.

The Hybrid Progress Stepper

I designed the stepper to let DPOs manually check off milestones reached in offline calls, since our research showed a fully automated system wouldn't reflect how compliance actually happens.

Milestone Tracking

HLFF

Plan Agreed

AI Compliance Checker

AI DPIA

Risk Assesment Completed

Compliance Report

Handover

Review & Comment Loop

We built a contextual commenting system that ties feedback directly to the document, so clients know exactly what's required to reach "Completed" status, without digging through email threads.

Key Takeaways & Impact

This was a new feature, so we had no usage metrics or analytics from a "before" version to compare against. What we did have was a clear picture of the current process: DPOs chasing technical specs through email threads, with no centralized source of truth. Our validation came from direct feedback during rollout and from how the pattern got reused afterward:

Direct DPO feedback: DPOs told us that having milestone validation and client comments in one place meant they no longer had to reconstruct status from scattered email threads. That was the exact friction point our discovery interviews pointed to as the biggest source of delay.

Reused beyond the original scope: The Hybrid Progress Stepper was adopted for GDPRLocal's other regulatory compliance workflows beyond AI.

Client portal

Admin portal

Thanks for stopping by.

Expanding a compliance portal to handle the complexities of new AI regulations.

Role: Lead Designer

Scope: Information Architecture, Design

Platform: Web / B2B SaaS

Overview

When the EU AI Act was introduced, it created a massive, intimidating shift for the industry. Most companies were staring at a scary legal PDF with no idea how to actually "do" compliance. While GDPRLocal already had an existing portal for data protection, it wasn't equipped for these specific new AI requirements. Our team’s mission was to design and integrate a new suite of features that guided companies through this legal maze, turning a heavy regulatory burden into a manageable digital workflow. We worked on 5 new features: AI Literacy, AI Representative, AI Risk Assessment, AI Governance and AI Officer.

This case study focuses on the design of the AI Risk Assessment feature.

The Challenge

For Clients

Clients didn't know which technical details actually mattered to the law, and had no visibility into their product's audit readiness.

For Data Protection Officers

DPOs were chasing technical specs through email threads, with no centralized way to validate milestones or maintain a single source of truth across multiple client products.

Discovery

The research phase was a deep dive into the legal requirements of Article 4, combined with a series of interviews with internal Data Protection Officers to understand where the current process stood.

What we learned?

Through the discovery sessions, we identified two friction points that guided the decisions we made:

The status Gap

80% of the friction wasn't legal work, it was status checking. Clients were anxious because they couldn't see progress. DPOs were overwhelmed because they had no way to track it.

The Offline Reality

Compliance doesn't just happen in an app, it happens on Zoom calls and in strategy meetings. We discovered that a rigid, automated system would fail so we needed a "Hybrid" model where humans could manually validate the progress.

Our first instinct was to design a fully automated tracker, one that would update milestones based on document uploads and system triggers alone. But the DPO interviews told a different story: a plan gets agreed on a call, not when a file lands in the portal. If we'd built a purely automated system, the progress bar would always be a step behind the actual work, and DPOs would end up manually overriding it anyway just to keep it honest. So we shifted to a hybrid model, automation where the system genuinely had visibility (document status, submissions), and manual validation where the real decision-making happens offline.

Solution

We focused on two key areas to turn this technical audit into a smooth, manageable experience for both the Admin and the Client Users.

The Hybrid Progress Stepper

I designed the stepper to let DPOs manually check off milestones reached in offline calls, since our research showed a fully automated system wouldn't reflect how compliance actually happens.

Milestone Tracking

HLFF

Plan Agreed

AI Compliance Checker

AI DPIA

Risk Assesment Completed

Compliance Report

Handover

Review & Comment Loop

We built a contextual commenting system that ties feedback directly to the document, so clients know exactly what's required to reach "Completed" status, without digging through email threads.

Key Takeaways & Impact

This was a new feature, so we had no usage metrics or analytics from a "before" version to compare against. What we did have was a clear picture of the current process: DPOs chasing technical specs through email threads, with no centralized source of truth. Our validation came from direct feedback during rollout and from how the pattern got reused afterward:

Direct DPO feedback: DPOs told us that having milestone validation and client comments in one place meant they no longer had to reconstruct status from scattered email threads. That was the exact friction point our discovery interviews pointed to as the biggest source of delay.

Reused beyond the original scope: The Hybrid Progress Stepper was adopted for GDPRLocal's other regulatory compliance workflows beyond AI.

Client portal

Admin portal

Thanks for stopping by.