Does amaise conduct data protection impact assessments?
Yes. amaise conducts data protection impact assessments (DPIA / Privacy Impact Assessments) for high-risk processing as required by the respective data protection regulations (GDPR Art. 35, Swiss nDSG Art. 22, as well as comparable US requirements). This specifically includes:
Processing of health data (medical reports, diagnoses)
Processing of data from legal proceedings (attorney correspondence, court documents)
Processing of data subject to special confidentiality obligations (e.g., professional secrecy, attorney-client privilege)
The DPIAs are managed as part of the ISO 27001 compliance program via the compliance platform and take into account both European and US data protection standards.
Additionally, an AI-specific data protection impact assessment was conducted for the LLM integration. This covers AI data processing: no use for training, regional processing, no cross-region transfers.