Orthopaedic industry — GDPR and AI governance
A company operating in the orthopaedic sector required a practical framework covering privacy, GDPR and the organisational implications of using AI applications.
18 September 2026
The situation
Privacy requirements, staff behaviour, technology choices and AI use can overlap in ways that are difficult to manage if each topic is addressed independently.
The work
The assignment considered GDPR and privacy requirements alongside the practical use of AI applications.
It also addressed the organisational side: responsibilities, staff understanding, use rules, tailored applications and the implications of the EU AI Act.
The approach
The purpose was not to create a pile of policies.
The purpose was to make the requirements usable inside the organisation: clear enough to apply, connected enough to avoid contradictions and practical enough to support day-to-day work.
