DigiTorc

GDPR Compliance,  AI Governance and Data Management Services

DigiTorc delivers Data Protection, Data Management and AI Act Governance Services

Since the launch of the EU Digital Decade (2021‑2030), Brussels has unleashed an unprecedented wave of digital legislation aimed at creating a single, trustworthy, and competitive digital market across the Union. At the heart of this agenda are three cornerstone statutes that together regulate personal data, non‑personal data, and the artificial‑intelligence systems that process them.

EULawTimeLine4

  1. The General Data Protection Regulation (GDPR), implemented in Irish Law as the Data Protection Act 2018, is a rights‑based law for the protection of personal data and harmonises privacy rules across all EU Member States. Compliance requires a lawful basis for each processing activity; the conduct of Data‑Protection Impact Assessments (DPIA) for high‑risk operations; robust technical safeguards for organisations and mechanisms to uphold data‑subject rights.
  2. Building on the GDPR’s foundation, the EU AI Act was adopted in 2024 as the world’s first comprehensive AI‑specific law. It introduces a risk‑based classification for AI systems, obliging providers of high‑risk AI to undergo conformity assessments, publish transparency information, and maintain post‑market monitoring. Crucially, Article 5 imposes a hard‑stop prohibition on AI that manipulates, deceives, or exploits vulnerable persons.
  3. Complementing these two regulations, the EU Data Act came into force in September 2025 to govern the sharing and reuse of non‑personal data. It sets fair contractual terms for data‑intermediation services, requires transparent access conditions, non‑discriminatory pricing, and respects data‑portability requests across a wide range of sectors from personal  IoT devices to Industry 4.0.
EU 3 Laws Medium

Together, these three statutes form a tri‑layered digital governance architecture: the GDPR safeguards individuals’ privacy rights; the AI Act ensures that the algorithms processing that data operate transparently and do not cause undue harm and the Data Act guarantees equitable access to vast pools of non‑personal data to fuel AI and digital service development. The convergence of these rules means that organisations operating in the EU must adopt an integrated compliance strategy—covering data‑protection impact assessments, AI‑risk assessments, and data‑sharing contracts—or face steep financial penalties under this tightly‑woven regulatory framework.

What We Do

Audit

We offer a range of competitive auditing services using proven methodologies to benchmark your organisation, identify gaps and risks.  Successful data protection, AI compliance and cybersecurity programs need to be regularly audited, whether your organisation is preparing for certification to a particular standard or striving to achieve a quality mark to help build brand trustworthiness with customers, partners and investors.  

Impact Assessments

Outsource your Data Protection Impact Assessments (DPIA), Fundamental Rights Impact Assessment (FRIA), AI Conformity Assessment (AICA) and AI Impact Assessment (AIIA,) to DigiTorc and reduce risk and expense while driving your data protection and AI compliance programmes.

DPO and AIO

Many organisations have a legal obligation to appoint a Data Protection Officer (DPO) or appoint an AI Officer as part of good AI Governance Practice.  These functions may be outsourced. DigiTorc can be your DPO and AIO to help you drive your GDPR and AI Act compliance programmes.

Compliance

We work with you to develop & implement customised data protection, cybersecurity, trustworthy AI governance and data management processes that will map to your organisation's leadership vision, objectives, policies and skillsets.  The development of such artefacts are often requisite in preparation for data protection, cybersecurity and trustworthiness certification exercises. 

Training

DigiTorc provides awareness training across for data protection, digital transformation and trustworthy AI governance training tailored to meet the requirements of key organisation stakeholders, general staff, and those individuals responsible for managing data protection, digital transformation and AI projects.

We can customise training for all your data protection, digital transformation and trustworthy AI governance and operational needs.

Encryption and Pseudonymisation

Whether is protecting the personal data that you hold for others in care or are preparing datasets to train AI systems using public or privately collected personal data, DigiTorc offers best in class encryption and pseudonymisation solutions to minimise risks associated with personal data breaches or AI poison data attacks. Talk to us about what technologies can help you meet your organisation's requirements.

EU Representative

If you offer cloud hosted services to EU citizens or sell products that process personal data and you don't have a registered office in the EU, DigiTorc can serve as your EU Representative and undertake statutory services of supporting Data Subject Rights, Breach Notification and other activities.

If you are a provider of high-risk AI systems and don't have an office or staff within the jurisdiction, DigiTorc can act as your representative and interact with competent AI market surveillance authorities on your behalf in accordance with Article 22 of the EU AI Act.

Data Management

When planing a digital transformation project and wish to identify, understand and classify data, DigiTorc can advise, undertake classification projects and provide you with the data management tools you need to manage such efforts on an ongoing basis.

Whether you need to understand your business and organisation better, implement a data retention policy, identify datasets to train AI models or build a record of processing activities (ROPA) to meet GDPR obligations. Talk to DigiTorc about mapping your data to your business needs.

Testimonials

Michael Spratt from DigiTorc recently came to the office to give members of our staff GDPR training which the team found most beneficial. It is really crucial that our team are aware of the implications of GDPR as we hold data of more than 200,000 members. Michael’s presentation was extremely informative and educational and gave us an excellent idea of what systems and policies we should have in place, ways that we can improve our GDPR as well as pitfalls to look out for and way of being prepared in the case of a breach. After our training, the team felt much more confident in tackling GDPR issues and has since met and put in place further GDPR measures for our members. I would definitely recommend DigiTorc’s GDPR training.”

Alex Barton

Operations & Admin Coordinator - Uplift

Felim & Michael went further than I expected to deliver a high quality and detailed DPIA for SRL Very tenacious at getting to the root of what really need to change for us to implement Privacy by Design be GDPR compliant. DigiTorc provided an excellent quality of service.

Tim Morgan

COO Service Robotics LTD

Michael Spratt from DigiTorc recently came to the office to give members of our staff GDPR training which the team found most beneficial. It is really crucial that our team are aware of the implications of GDPR as we hold data of more than 200,000 members. Michael’s presentation was extremely informative and educational and gave us an excellent idea of what systems and policies we should have in place, ways that we can improve our GDPR as well as pitfalls to look out for and way of being prepared in the case of a breach. After our training, the team felt much more confident in tackling GDPR issues and has since met and put in place further GDPR measures for our members. I would definitely recommend DigiTorc’s GDPR training.” I would definitely recommend Digitorc Alex Barton - Operations & Admin Coordinator - Uplift Felim & Michael went further than I expected to deliver a high quality and detailed DPIA for SRL Very tenacious at getting to the root of what really need to change for us to implement Privacy by Design be GDPR compliant. DigiTorc provided an excellent quality of service. Service Robotics ltd DPIA delivered – thorough and cost effective Tim Morgan COO Service Robotics LTD The Irish Franchise Association used the GDPR consultancy services of Digitorc during Quarter 1 2019. Digitorc gave us some very practical and helpful advice which we were able to implement in a very cost effective, no nonsense way. I have no hesitation in recommending Digitorc to any potential users Cost effective, No nonsense

Tom Shanahan

Executive Director Irish Franchise Association

We were delighted to have the services of Felim O’ Neill from Digitorc to assist us in getting GDPR complaint. Felim provided a very professional and thorough review of all aspects of our business and gave practical solutions and guidelines. I would highly recommend any business who are worried about the daunting task of getting compliant to employ the services of Digitorc. – Declan Dempsey CFO

Anthony Ryan Ltd

Chief Financial Officer

DigiTorc were the best deal we found after looking at a dozen alternatives. Once chosen it was refreshing to sit back and let DigiTorc analyse, develop and deploy data privacy solutions that work for us. I will certainly use them again.

Angela Behan

Managing Director PARC LTD

Before I met Michael Spratt of Digitorc I was overwhelmed by the work required to become GDPR compliant. There appeared to be so many elements to it and I did not know where to start. Michael suggested doing a needs analysis first to identify our priorities. His knowledge of GDPR immediately put me at ease and his logical, pragmatic approach made the task manageable.
I decided to enlist Michael’s support based on his knowledge of the regulation and his straight forward approach in dealing with it.

We are a small organisation and his professional expertise was invaluable. Now we are up to date with policies and procedures, have identified the risks and put steps in place to mitigate against them. I would have no hesitation in recommending Michael as a GDPR consultant – we have made significant steps towards achieving GDPR compliance in a relatively short space of time.

Una Kenny

Project Manager

The Team

SQ MS

Michael Spratt

Dublin based

Senior data‑protection consultant with 30 + years of experience across telecom, big‑data and media sectors; PhD (Law), MBA, BEng, CIPP/E and Chartered Engineer, with multicultural work experience in Europe, Africa and the Middle East.

Feim O'Neill

Felim O'Neill

Galway Based

Senior Consultant with 35 + years of international experience in business with a focus on IT, extensive international experience and recently ran the Grant Thornton west of Ireland data protection and AI consultancy service.

Murtagh Forde GDPR consultant DigiTorc Belfast

Murtagh Forde

Belfast Based

Murtagh is a senior sales and marketing executive with 25 years of global experience, having built a network of representatives in 40 countries and generated €15 million + in annual revenue for the education‑and‑training sector. He holds a language degree from the University of London together with a state‑recognised Skills Trainer qualification from NUI Galway.

Scroll to Top