Skip to content

DPO FAQ — the questions you'll be asked

If you’re evaluating ISNAD for an EU AI Act deployment, these are the four questions your legal team will ask. Honest answers, in plain English.

The data processing addendum template is in this documentation (dpa-template.md). We finalize and sign it with you before the engagement starts — it is not a bracket-filled placeholder at signing time. The entity behind ISNAD is a registered company; we share its details and the signed DPA directly with your procurement team.

How does erasure work if the log is append-only?

Section titled “How does erasure work if the log is append-only?”

This is the honest tension in any immutable record: the log can’t be rewritten (that is the tamper-detection guarantee), but GDPR Art 17 (right to erasure) still applies to personal data. ISNAD’s answer is tombstone / hash-first redaction — see the erasure note. In short: the personal data is redacted, a hash of what was there is kept, and the chain’s integrity holds while the PII is gone.

Yes. Retention is operator-configurable. The defaults we recommend map to the EU AI Act: logs ≥ 6 months (Art 19), technical documentation 10 years (Art 18). You set the exact term in the retention policy that ships with your evidence bundle.

ISNAD records who handled an answer and the hashes, not the raw customer data itself. You control what fields are logged. If you log PII, the erasure mechanism above applies.