7: What are the Legal Documentation Requirements?
For commercial release, what mandatory legal documents (e.g., Technical Documentation, DPIA, Risk Assessment) are required for the IRIS application?
35 Answers
-
IRIS would require:
Technical Documentation (EU AI Act)
Risk Management File
Data Protection Impact Assessment (DPIA – GDPR)
Conformity Assessment
Post-market monitoring plan
A high-risk AI system like IRIS must, at minimum, have EU AI Act technical documentation (Annex IV) and an EU Declaration of Conformity, with a GDPR DPIA additionally required if it processes personal data, forming the core legal basis for market release and accountability.
Risky assessment and risky management is essential along with documentation of data
Commercial release would require formal documents such as risk assessments and data protection reviews. These show that safety, privacy, and compliance risks were evaluated before deployment. They are essential for responsible approval.
Technical Documentation Risk Management Records System Logs
Records of processing activities ( RoPA
Legally required under GDPR because IRIS processes sensitive biometric data (facial tracking). This document proves you have minimized privacy risks
Clear explanations of how data is collected, used and shared
For commercial deployment, IRIS would realistically require: Technical Documentation (EU AI Act Article 11). Quality Management System documentation (Article 17). Conformity Assessment and EU Declaration of Conformity. Post-Market Monitoring Plan and logging mechanisms. Risk Management documentation. Data Protection Impact Assessment (DPIA) under GDPR, due to biometric and behavioural data processing. User instructions and transparency notices. These documents collectively demonstrate compliance with both AI-specific and data protection law.
Risk assessment and DPIA
Drivers license
Quality manual and policy
- Technical Documentation (Annex IV)
- Risk Management Documentation
- Quality Management System Evidence
- EU Declaration of Conformity
-
Operational Logs/Record Keeping
-
Registration in the AI Act high risk database
- DPIA under GDPR (if personal data processing qualifies)
GDPR, Risk Assessment Documents SOC2 Type 2 End-user agreement Privacy Policy Terms and conditions
Article 11 & Annex IV, Article 47, DPIA - GDPR Article 35, Article 9, Article 27, QMS Article 17, Article 13, Post-Market Monitoring Plan
I don't think they provided any required document.
I think it would be beneficial if the contents included information on what data is stored about the individual (if any at all) and what decisions the person can make in terms of the system.
full tech specifications. Anonymised information regarding pilot etc usage.
From a data analysis perspective, the preservation of well-documented datasets, evaluation results, and risk assessments over time would be highly valuable for improving future systems. In particular, access to aggregated, anonymised, or synthetic datasets and benchmark results could support reproducibility, independent evaluation, and more robust performance comparisons across models.
This would also strengthen public trust by enabling external scrutiny of system performance, fairness, and safety outcomes, while still maintaining appropriate safeguards for privacy and data protection.
Preserved documentation should include dataset sources, demographic coverage, performance metrics, known limitations, update history, and incident logs. That would help regulators assess fairness, safety, and reproducibility over time.
The documentation should preserve training and validation methods, known limitations, bias assessments, and incident records. Citizens and regulators would also benefit from clear descriptions of update history and monitoring outcomes.
It should include data provenance, bias testing, failure cases, and safety assumptions. That information would help identify whether the system is reliable enough for public use.
Useful documentation would include test results, known limitations, dataset composition, and model-change logs. That creates a record that can support later audits and safety reviews.
The documentation should preserve dataset descriptions, test methodology, and evidence of bias mitigation. That would help reproduce and scrutinize the system later.
should include the training dataset, evaluation results, fairness analyses, and incident reports. That would make later oversight much more effective.
Preserved documentation should include model cards, data sheets, test metrics, and version history. Those records help regulators and researchers understand how the system behaves in practice.
Useful retained documentation would include audit trails, validation reports, and updates to the dataset over time. That supports accountability and later review.
Documentation should include data provenance, bias testing, failure cases, and safety assumptions. That information would help identify whether the system is reliable enough for public use.
It should include the training dataset, evaluation results, fairness analyses, and incident reports. That would make later oversight much more effective.
Their responses/failures/lessons learned
Should be all. But this is one of the issues raised earlier, especially for saving face images.
Assuming consent was obtained, it is important to keep the data for future improvements.
Your Answer
Login to add your answer!
We’d love to hear your thoughts — share a meaningful answer by logging in.