International Law Compliance
How AI+ Pro aligns with the international data protection and AI frameworks that govern our customers, from the GDPR and the EU AI Act to CCPA/CPRA and the mechanisms behind cross-border transfers.
GDPR Compliance (European Union)
AI+ Pro is fully compliant with the General Data Protection Regulation (GDPR), ensuring the highest standards of data protection for EU citizens.
- Lawful basis for processing established
- Data subject rights fully implemented
- Privacy by design and by default
- Data Protection Impact Assessments (DPIA)
- EU-US Data Privacy Framework certified
- Standard Contractual Clauses (SCCs) in place
EU AI Act Readiness
We are prepared for the EU AI Act requirements, implementing risk-based approaches and ensuring transparent AI operations.
- Risk categorization of AI systems
- Transparency obligations fulfilled
- Human oversight mechanisms
- Accuracy and robustness measures
- Conformity assessments prepared
CCPA/CPRA Compliance (California, USA)
Full compliance with California Consumer Privacy Act and California Privacy Rights Act, protecting the privacy rights of California residents.
- Consumer rights requests honored
- Opt-out mechanisms available
- Privacy notices updated
- Data minimization practices
- Annual privacy audits conducted
Cross-Border Data Transfer Mechanisms
We employ multiple legal mechanisms to ensure lawful international data transfers:
- Standard Contractual Clauses (EU)
- Adequacy decisions compliance
- Binding Corporate Rules (BCRs)
- APEC Cross-Border Privacy Rules (CBPR)
- Transfer Impact Assessments
International Standards
AI+ Pro is built against recognised information-security and privacy management standards. We publish the controls rather than a certificate: certification names an audit an external body performed, and we list only findings we can produce on request.
| Standard | Scope | Status |
|---|---|---|
| ISO/IEC 27001 | Information security management | Designed against; not yet certified |
| ISO/IEC 27701 | Privacy information management | Designed against; not yet certified |
| ISO/IEC 27017 | Cloud security controls | Designed against; not yet certified |
| ISO/IEC 27018 | Processing of personal data in the cloud | Designed against; not yet certified |
| SOC 2 Type II | Trust services criteria | Not yet audited |
The technical controls behind these — encryption in transit and at rest, role-based access, audit logging, tenant and deployment isolation, and the retrieval boundary that limits what any model receives — are described on Security and Deployment. Where a customer requires certified assurance today, the on-premise and isolated-tenant deployments place the platform inside the customer's own certified environment.
Regional Data Protection Laws
In short
We comply with data protection laws across multiple jurisdictions:
| Region | Jurisdiction | Law |
|---|---|---|
| Asia-Pacific | Australia | Privacy Act |
| Asia-Pacific | Japan | APPI |
| Asia-Pacific | South Korea | PIPA |
| Asia-Pacific | India | DPDP Act |
| Asia-Pacific | China | PIPL |
| Americas & others | Canada | PIPEDA |
| Americas & others | Brazil | LGPD |
| Americas & others | United Kingdom | UK GDPR |
| Americas & others | Switzerland | nFADP |
| Americas & others | Dubai | DIFC Data Protection Law |
International Compliance Contacts
- EU Representative
- contact@aiplus.pro — Dublin, Ireland
- UK Representative
- contact@aiplus.pro — London, United Kingdom
- Global Data Protection Officer
- contact@aiplus.pro
