Vendor assurance · contracts

Privacy and AI contract review

Embed AI reviews privacy terms, data processing agreements and AI supplier contracts. Zahed Ashkara helps legal and procurement teams clarify roles, data flows, information duties and practical arrangements, including suppliers without AI functionality.

Vendor check

10 business days

A vendor score and list of missing evidence

Concrete contract questions for the supplier or procurement

Clarity on AI Act role and risk route

GDPR, DPIA and FRIA signals per AI feature

Data processing agreements and privacy terms

You can engage Zahed Ashkara without an AI-related question. We agree scope, timing and rate upfront; the AI engagements below are an additional specialist route.

  • Clarify roles: controller, processor or another recipient.
  • Review data processing agreements and propose concrete amendments.
  • Review subprocessors, security, incidents, retention and exit arrangements.
  • Map data flows and any transfers outside the EEA.

Fictional example: a new supplier offers AI screening of applicants. Documentation and a contract are missing.

Embed AI

What an intake sheet looks like

Based on your answers. Evidence has not been checked. This sheet helps prepare a conversation and does not give a final legal conclusion.

Known facts

Use and purpose
A new supplier ranks applicants for an initial selection. Recruitment or selection.
Supplier and evidence
New supplier: Supplier X (fictional). Neither available.
Data
Ordinary personal data. Within the EU: Yes.
Affected people
Applicants. The AI prepares a decision about them.
Review and decision
A reviewer has been assigned: Recruiter. Open decision: What evidence is needed before we allow a trial with applicant data? Who decides: HR manager.

Missing evidence

  • Documentation on operation and limitations is missing.
  • Contract terms are missing.

Next actions

  1. 1. Request documentation on intended use and limitations

    You are buying AI, but supplier documentation is missing. Also request data terms and evidence behind sales claims.

    Suggested owner: Procurement

  2. 2. Assess the influence on selection and request the supplier’s reasoning

    The AI is used in recruitment or influences a decision about applicants. Examine its actual use, classification and scope for human review.

    Suggested owner: Privacy officer or DPO

  3. 3. Assess whether a DPIA is needed before use

    You indicated sensitive data, vulnerable people or influence on a decision about a person. Assess the nature, scale, context and purpose of processing.

    Suggested owner: Privacy officer or DPO

Provisional direction

A DPIA may be needed. Ask the privacy officer or DPO to assess whether this processing is likely to create a high privacy risk. AVG / GDPR, art. 35

This appears to be a use requiring closer attention for recruitment or assessment of people. Examine the precise Annex III route and any exceptions. The corresponding Chapter III, Sections 1 to 3 duties follow on 2 December 2027; transitional rules may be relevant. AI Act, art. 6, 111, 113 / Annex III

Open decision

What evidence is needed before we allow a trial with applicant data?

Who decides: HR manager

Create your own intake sheet in five questions

Why vendor checks are commercially critical

A claim such as AI Act-ready requires evidence. Many organizations buy AI through existing SaaS, HR tech, finance tooling or generative AI features. Suppliers often say the product is safe or compliant, but your organization still needs to show what it uses, which role it has and which evidence is missing.

1

Provider/deployer remains unclear

A contract may mention AI features, but not who carries which AI Act duty during use, modification or resale.

2

Vendor evidence is too generic

Security certifications help, but they do not replace model information, logging, bias, human oversight or transparency evidence.

3

Contracts miss audit-ready terms

Without concrete duties on information, updates, incidents and data, procurement and legal carry open risks.

What we check

AI functionality, use case, contract scope and intended use

Provider/deployer/responsibility split per supplier and workflow

AI Act route: high-risk, transparency duty, GPAI chain, low risk or unclear

GDPR and processing: processor role, data flows, training data, logging and retention

Vendor evidence: documentation, model information, evaluations, bias, monitoring and incidents

Contract gaps: audit rights, change notifications, subprocessors, duties and exit

DPIA/FRIA signals and information needed for impact analysis

Human oversight, user transparency and appeal or escalation routes

Red/yellow/green vendor score with missing evidence

Decision memo with contract questions, risks and go/no-go or negotiation points

Approach in 10 business days

1

Scope and documents

We choose the supplier, contract, AI features, user group and decision point: purchase, renewal, pilot or customer question.

2

Evidence review

We review vendor docs, security/privacy materials, AI information, product claims, DPA, contract and procurement questions.

3

AI Act and GDPR mapping

We map role, risk route, data processing, transparency and possible DPIA/FRIA questions side by side.

4

Contract and governance gaps

We translate missing evidence into concrete contract questions, controls, monitoring and responsibilities.

5

Decision memo

You receive a short decision document with vendor score, open risks, negotiation points and next steps.

Who this works for

Procurement and vendor management

Teams that want to test AI purchasing without unpacking every contract from scratch.

Legal, privacy and compliance

Teams that need AI Act, GDPR, DPIA/FRIA and contractual duties in one decision view.

HR, finance and operations

Teams buying or renewing AI tools in processes where people, scores, access or oversight are affected.

SaaS and AI suppliers

Vendors that want to answer enterprise customer questions with clearer evidence, role split and contract explanation.

Afterwards you have

A vendor score and list of missing evidence

Concrete contract questions for the supplier or procurement

Clarity on AI Act role and risk route

GDPR, DPIA and FRIA signals per AI feature

A decision memo for purchase, renewal, pilot or customer conversation

Frequently asked questions

Is this a legal contract review?

Yes. As legal counsel, Zahed Ashkara reviews privacy terms and data processing agreements. AI contracts can also require supplier documentation and AI Act role reviews. We agree the assessment and proposed amendments upfront.

Can you assess existing suppliers?

Yes. The check works for new suppliers, contract renewals, pilots and existing SaaS features where AI has become part of the product.

What if the vendor has little AI documentation?

Then we record that explicitly as a risk. You receive targeted questions about model information, data use, logging, bias, monitoring, incidents and human oversight.

Is this only for high-risk AI?

No. Transparency duties, GPAI chains, low-risk AI and unclear SaaS features can also create contractual or GDPR risks.

Can this help with enterprise sales?

Yes. For vendors, the check can help answer customer questions about the AI Act, GDPR, security, bias and evidence more consistently.

Do not let vendor claims replace evidence.

Discuss your question with Zahed Ashkara. Include the assessment, start date and support you need; we agree the scope together.

Rivium Westlaan 46, Capelle aan den IJsselCoC 90283597