Executive summary
Demo · Fictional companyCompany
Acme AI Inc. (fictional)
Sector
SaaS / Artificial intelligence
Declared markets
Canada, United States, European Union
3 critical or high-priority gaps to close before an enterprise sale.
We tell you what is missing. We never declare anyone compliant, including in this demo report.
Findings
Severity, jurisdiction, source, confidence, recommended action
No personal information protection officer identified
CriticalJurisdiction: Quebec
Source: Law 25: general designation requirement
Confidence: High (primary source)
Recommended action: Designate an officer (by default, the most senior executive) and publish it on the site.
Insufficient transparency on user-facing generative AI systems
HighJurisdiction: European Union
Source: EU AI Act, Art. 50: transparency obligations
Confidence: High (primary source)
Recommended action: Clearly disclose when a user is interacting with an AI system.
Incomplete HTTP security headers on the public site
MediumJurisdiction: All jurisdictions
Source: Cybersecurity best practice (OWASP)
Confidence: High (direct measurement)
Recommended action: Add the missing headers (CSP, HSTS, X-Content-Type-Options).
Privacy policy lacks an explicit opt-out mention
MediumJurisdiction: California
Source: CCPA/CPRA: right to opt out of sale or sharing
Confidence: Moderate (guidance)
Recommended action: Add a visible opt-out mechanism and a dedicated clause.
No mention of a legal basis for processing or a data protection officer
HighJurisdiction: European Union
Source: GDPR, Art. 6 (lawfulness) and Art. 37 (DPO)
Confidence: High (primary source)
Recommended action: Document the legal basis per purpose; appoint a DPO if the threshold applies.