Trusted by 50+ privacy teams across 14 countries
Healthcare
Aviation
Energy
Legal
Technology
Zurzach logo
AXA logo
Openmedical logo
Glencore logo
Pilatus logo
Liferay logo
CareerFairy logo
Voicepoint logo
Kellerhals Carrard logo
Aclaris logo
Avantec logo
Diakonie Bethanien logo
Liferay logo
CareerFairy logo
Zurzach logo
Voicepoint logo
Openmedical logo
Kellerhals Carrard logo
AXA logo
Aclaris logo
Avantec logo
Diakonie Bethanien logo
Key Product Capabilities

How Priverion Operationalizes EU AI Act Compliance Across Your Entire Group

The prohibited practices provisions are already enforceable. These capabilities help multi-entity organizations move from awareness to documented compliance , across every subsidiary, in weeks.

AI Register for EU AI Act Readiness

Catalog every AI system deployed across your group , including third-party vendor tools embedded in HR, security, and customer engagement platforms. Map each system against the Article 5 prohibited practices list and flag exposure before regulators do. One centralized register, visible across all subsidiaries.

100% vendor risk assessment coverage achieved

Zurzach Care , full third-party AI inventory across all entities

AI-Assisted Risk Scoring and DPIA Automation

When an AI system sits in the gray zone between prohibited and high-risk, you need rigorous documentation. Priverion's AI-assisted DPIA drafting helps compliance teams generate impact assessments faster , with risk scoring that accounts for prohibited practice indicators. AI assists your team's judgment; it never replaces it. No customer data is used for model training.

200+ hours saved in compliance documentation

Medtec , ISO 27001 preparation, first engagement year

Group-Wide Compliance Dashboards and Audit Evidence

When a supervisory authority asks for evidence that your organization has assessed prohibited AI practices across all subsidiaries, you need to produce it in minutes , not scramble across 47 spreadsheets. Board-ready dashboards show real-time compliance posture per entity. Generate audit-ready evidence packages for any jurisdiction on demand.

60% reduction in compliance admin time

Aircraft manufacturer , first 6 months of deployment

Automated ROPA Recertification Across Entities

AI systems that process personal data require up-to-date Records of Processing Activities. Priverion automates recertification across every subsidiary in your group , so when a prohibited practice is flagged in a vendor's processing activity, you catch it during routine recertification, not during a regulatory investigation.

100% ROPA recertification rate, fully automated

AXA , automated across all group entities

Vendor Risk Assessments for Third-Party AI

Most prohibited AI practice exposure hides in third-party tools , the emotion recognition feature buried in your video conferencing platform, the biometric categorization in your hiring tool. Priverion's vendor risk assessment workflows systematically evaluate every third-party AI system against prohibited practice criteria before it enters your ecosystem.

24/7 DPO support across multiple entities

Tapeze , continuous oversight for group-wide vendor compliance

Swiss Data Sovereignty . By Design, Not by Marketing

Your AI compliance data , risk assessments, audit evidence, processing records , deserves the same protection as the personal data it documents. Priverion is Swiss-built and Swiss-hosted. All data processing occurs within Swiss infrastructure. In a post-Schrems II landscape, that's not a marketing checkbox. It's a legal foundation for cross-border compliance confidence.

Operational in weeks, not months

Average Priverion deployment time-to-value across mid-market and enterprise customers

We don't cover ESG, ethics hotlines, or cookie consent. Our strength is group-wide privacy and AI compliance management , done deeply, not broadly.

Priverion vs. OneTrust

Why mid-market teams are making the switch

Enterprise privacy platforms weren't built for you. They were built for Fortune 500 procurement cycles, six-figure budgets, and 18-month implementations. Here's what changes when your platform actually fits your reality.

The OneTrust experience

Pricing that expands on you

Per-user, per-module pricing means costs balloon as your team grows. Adding a subsidiary? That's another line item. Budget predictability disappears the moment you start onboarding.

US-hosted infrastructure

Data processed in US-based cloud environments. In a post-Schrems II landscape, this creates ongoing transfer risk and additional documentation burden for European organizations.

Built for the Fortune 500

Feature-rich to the point of paralysis. ESG modules, ethics hotlines, cookie consent , you're paying for capabilities your privacy team will never touch. Implementation timelines stretch to months.

200+ shallow integrations

A long connector list looks impressive in an RFP. In practice, shallow integrations create maintenance overhead and break when source systems update , adding work instead of removing it.

Complexity as a feature

Steep learning curve means your team needs dedicated training and often external consultants just to get started. The tool that was supposed to simplify compliance becomes another project to manage.

The Priverion experience

Pricing that stays predictable

Based on number of companies and organizational size , not per-user or per-module. Add team members across subsidiaries without watching your invoice climb. Your CFO will notice.

Swiss-hosted, Swiss-built

All data processing within Swiss infrastructure. European data residency guaranteed , not as a premium add-on, but as the default. In a post-Schrems II world, this isn't a preference. It's a legal simplification.

Built for group-wide privacy

Every feature exists to solve multi-entity privacy management. ROPA, DPIA, vendor assessments, incident management, DSR handling , all in one platform, all connected. Nothing you'll never use, nothing missing that you need.

Deep integrations that matter

We connect deeply with the systems that drive privacy workflows . HR, procurement, IT asset management. Fewer connectors, zero maintenance headaches, real data flowing where it needs to go.

Operational in weeks

Aircraft manufacturer achieved 60% reduction in compliance admin time within their first 6 months. Not because they hired consultants , because the platform is designed for privacy professionals, not IT departments.

Aircraft manufacturer , measured over first 6 months of deployment

Stop managing privacy in spreadsheets

Get your Friday afternoons back

See how organizations like Aircraft manufacturer cut compliance admin time by 60% in six months , with automated recertification, group-wide visibility, and Swiss data sovereignty built in.

60%

Less compliance admin , Aircraft manufacturer, first 6 months

200+

Hours saved in ISO 27001 prep , Medtec

Weeks

Not months to go live

Book a 30-minute walkthrough

No sales pitch. A real walkthrough with a privacy practitioner who speaks your language.

Swiss-built and Swiss-hosted

AI-assisted, human-decided

No per-user pricing traps

About this page: references, definitions, and FAQs

Key Takeaways: EU AI Act Prohibited AI Practices

The EU AI Act's Article 5 bans eight categories of AI practices outright, with enforcement active since February 2, 2025. Penalties reach up to €35 million or 7% of global annual turnover, the highest tier in the regulation. Compliance teams must inventory all AI systems (including third-party vendor tools), map each against the prohibited practices list, and document assessments before supervisory authorities request evidence. Swiss-hosted platforms like Priverion help multi-entity organisations centralise this process across subsidiaries.

What is the EU AI Act?

The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive legal framework for artificial intelligence. It was published in the Official Journal of the European Union on 12 July 2024 and entered into force on 1 August 2024. The regulation adopts a risk-based approach, classifying AI systems into four tiers: prohibited, high-risk, limited-risk, and minimal-risk. Source: EUR-Lex, Regulation (EU) 2024/1689

What does Article 5 of the EU AI Act prohibit?

Article 5 of the EU AI Act establishes an absolute ban on eight categories of AI practices deemed to pose unacceptable risks to fundamental rights. These include: (a) subliminal, manipulative, or deceptive techniques causing significant harm; (b) exploitation of vulnerabilities due to age, disability, or social/economic situation; (c) social scoring by public authorities; (d) predictive policing based solely on profiling; (e) untargeted scraping of facial images for facial recognition databases; (f) emotion recognition in workplaces and educational institutions; (g) biometric categorisation systems inferring sensitive attributes such as race, political opinions, or sexual orientation; and (h) real-time remote biometric identification in publicly accessible spaces for law enforcement, subject to narrow exceptions. Source: EU AI Act, Article 5(1)(a) to (h)

When did the prohibited practices provisions take effect?

The prohibited practices under Article 5 became enforceable on 2 February 2025, six months after the regulation's entry into force, as specified in Article 113 of the EU AI Act. This was the first enforcement milestone. High-risk AI system obligations follow on 2 August 2026. Source: EU AI Act, Article 113

What are the penalties for prohibited AI practices?

Under Article 99(3) of the EU AI Act, violations of the prohibited practices provisions carry fines of up to €35 million or 7% of worldwide annual turnover, whichever is higher. For comparison, the GDPR's maximum fine is €20 million or 4% of global turnover. According to the IAPP, the AI Act's penalty structure is the most severe of any EU digital regulation to date.

Does the EU AI Act apply outside the European Union?

Yes. Article 2 of the EU AI Act has extraterritorial scope. It applies to providers who place AI systems on the EU market regardless of where they are established, and to deployers located within the EU. It also covers providers and deployers in third countries where the output produced by their AI system is used within the EU. This mirrors the GDPR's extraterritorial reach under Article 3. Source: EU AI Act, Article 2

How does the EU AI Act interact with the GDPR?

The EU AI Act and the GDPR apply simultaneously. Recital 10 of the AI Act explicitly states that the regulation is "without prejudice" to the GDPR. AI systems that process personal data must comply with both frameworks. The European Data Protection Board (EDPB) has noted that data protection impact assessments under GDPR Article 35 and the AI Act's conformity assessments for high-risk systems may overlap, and organisations should coordinate both processes.

What is the difference between prohibited and high-risk AI systems?

Prohibited AI systems (Article 5) are banned outright: there is no compliance pathway that permits their deployment. High-risk AI systems (Articles 6 to 49) are permitted but subject to extensive obligations including conformity assessments, risk management systems, data governance, technical documentation, human oversight, transparency requirements, and registration in the EU database. The European Commission's Annex III lists the specific use cases classified as high-risk.

How should organisations assess their AI inventory for prohibited practices?

Compliance teams should: (1) create a centralised AI register cataloguing every AI system deployed across the organisation, including third-party vendor tools; (2) map each system against the eight prohibited practice categories in Article 5; (3) conduct risk assessments for systems in grey zones between prohibited and high-risk; (4) document all assessments with audit-ready evidence; and (5) establish ongoing monitoring processes, particularly for vendor-supplied AI embedded in HR, security, and customer engagement platforms. According to a 2024 survey by IAPP, fewer than 30% of organisations had completed a full AI inventory by the time the prohibited practices provisions took effect.

Statistics and Sources

The EU AI Act (Regulation 2024/1689) was published on 12 July 2024 and entered into force on 1 August 2024. The prohibited practices provisions under Article 5 became enforceable on 2 February 2025. Maximum fines for prohibited practice violations reach €35 million or 7% of global annual turnover under Article 99(3). The regulation classifies AI systems into four risk tiers. According to the EDPB, national supervisory authorities are expected to coordinate enforcement with data protection authorities. The European Union Agency for Cybersecurity (ENISA) has published guidance on AI cybersecurity requirements that intersect with the AI Act's technical documentation obligations for high-risk systems.

Comparison: EU AI Act Penalty Tiers

Violation CategoryMaximum FineTurnover PercentageAI Act Article
Prohibited AI practices (Article 5)€35 million7% of global annual turnoverArticle 99(3)
High-risk AI system obligations€15 million3% of global annual turnoverArticle 99(4)
Incorrect information to authorities€7.5 million1% of global annual turnoverArticle 99(5)

Comparison: EU AI Act vs. GDPR

AspectEU AI ActGDPR
ScopeAI systems (risk-based)Personal data processing
Maximum fine€35M / 7% turnover€20M / 4% turnover
Extraterritorial reachYes (Article 2)Yes (Article 3)
Enforcement startFeb 2025 (prohibited); Aug 2026 (high-risk)May 2018
Impact assessmentConformity assessment (high-risk)DPIA (Article 35)
Registration requirementEU database for high-risk AINo central register