Free guide · ungated

The LuckMa DPIA Alignment Guide

A section-by-section map from a GDPR Article 35 Data Protection Impact Assessment to the evidence LuckMa produces — so your DPO can see, before signing anything, exactly which parts of the assessment the platform supports and which are still on the roadmap.

Talk to a founder

Honesty guardrail. LuckMa is not "DPIA-certified" — the DPIA is completed by you, the data controller. Every row below reads "supports" or "provides evidence for," never "certifies." Rows that aren't producible today are marked ⚠️ Partial or ❌ Roadmap / gap, on purpose.

Why this guide exists

A DPIA is triggered by exactly what LuckMa enables — automated decision-making with significant effects, new AI/ML, sensitive data at scale. That is not a collision to avoid; it is your buyer's compliance obligation, and the Observe → Ask → Analyze → Decide → Act loop is built to emit the evidence it requires. This guide follows the seven sections of a standard DPIA template and, for each, states what the assessment demands, how LuckMa supports it, the concrete evidence artifact it emits, and an honest status.

DPIA section → LuckMa evidence

DPIA section (Art. 35)What it demandsHow LuckMa supports itEvidence artifactStatus
§1 Screening & necessity Identify high-risk automated processing and scope autonomy. LuckMa is the governed automated-decision layer; the trust ladder (rules → human-in-loop → shadow → adoption gate → autonomous) scopes autonomy explicitly per model. Decision-mode registry per model/version ✅ Core
§2 Data flow & inventory Map inputs, sources, lineage, and retention. Observe normalizes and timestamps every input with bad-input rejection, so each decision journals the exact inputs it saw. Timestamped input record + data-lineage log ✅ Core
§3 Legal basis & Art. 22 explanation Explain automated decisions to data subjects. Every decision carries a human-readable rationale and a calibrated confidence score — the "right to explanation" evidence, per call. Per-decision rationale + confidence score ✅ Core
§4 Risk assessment & mitigation Concrete safeguards and residual-risk controls. Safety gates, a kill-switch, drift-breach → instant revert, and shadow-before-adopt provide the mitigation matrix's controls. Control catalog + gate/trigger logs ✅ Core
§5 Third-party / vendor due diligence Processor terms, data residency, transfer mechanism. Selectable AWS/GCP regions; encrypted in transit and at rest. A DPA and SCCs are still required paperwork — provided, not asserted. Region config + encryption attestation (needs DPA + SCCs) ⚠️ Partial
§6 Consultation & sign-off DPO evidence to approve before launch. The decision journal gives compliance inspectable provenance for every call; a dedicated audit UI for drill-down is in build. Auditable decision journal (audit UI in progress) 🔜 Roadmap
§7 Ongoing monitoring & review Continuous post-launch monitoring. Drift detection plus reproducibility (one model version per stamp) and journaling — replay any decision by version and input hash. Drift alerts + reproducible replay ✅ Core
Cross-cutting: individual rights Support access, export, and deletion (RTBF) requests. Honest gap: data-subject-rights tooling is a planned feature, not shipped. ❌ Gap → Phase 2
Cross-cutting: fairness Bias audit for credit / hiring / health. Honest gap: fairness / non-discrimination audits are planned, not shipped. ❌ Gap → Phase 3

Honest reading: the Observe→Ask→Analyze→Decide→Act loop already covers most of the technical DPIA surface — lineage, explainability, safeguards, monitoring. The three ⚠️/❌ rows (DPA/SCC paperwork, data-subject-rights tooling, fairness audits) are the real gaps, named on purpose. Naming them is more credible than papering over them.

How to use it

Take this into your own DPIA template (Confluence, Notion, Google Docs). For each section, paste the LuckMa evidence column as your "safeguards / evidence" entry, and treat the ⚠️/❌ rows as open action items to raise with us. Want the underlying replay or a walkthrough for your DPO? Start a conversation — the founder replies within one business day. No form required to read or print this guide.

Back to DPIA overview