LEGAL ENTITY
Norway, EEA member state
Registered in Norway
Norway is an EEA member state, and the GDPR applies there through the EEA Agreement. YPAI is a Norwegian company with no US corporate entity.
SOVEREIGN AI ETHICS FRAMEWORK
Norway-based, EEA residency by default, no US corporate entity. Data residency, subprocessors and international-transfer controls are defined per project. GDPR Article 28 DPA shipped with every engagement, 30-day erasure SLA, EU AI Act Article 10 documentation per project.
Registered in Norway, EEA operations. DPA shipped with every engagement. Reply inside one EU business day.
REGULATORY DEADLINE LANDSCAPE
MiFID II has applied since 2018, Schrems II since 2020, and DORA since January 2025. The fourth deadline is the one still ahead: the Digital Omnibus on AI moved it in July 2026, so from 2 December 2027 the EU AI Act data-governance obligations for standalone Annex III high-risk systems are enforceable, and they fall on the provider that trains or places the system on the market (Article 3(3)), not on a downstream deployer. AI embedded in regulated products follows on 2 August 2028. A later deadline does not move the work: the vendor selected today has to evidence Article-level alignment now.
CORPORATE STRUCTURE
The CLOUD Act reaches a US-domiciled vendor even when its data sits in the EU, so a transfer review checks where the vendor is registered as well as where the data is processed.
LEGAL ENTITY
Norway, EEA member state
Registered in Norway
Norway is an EEA member state, and the GDPR applies there through the EEA Agreement. YPAI is a Norwegian company with no US corporate entity.
OPERATIONS
Lysaker torg 5, 1366 Lysaker
Norwegian headquarters, EEA residency by default
Data residency, subprocessors and international-transfer controls are defined per project. EEA processing by default; SCCs are available for any customer-directed transfer outside the EEA.
US corporate entity
Norwegian AS, org. no. 933 915 778
None
YPAI is a Norwegian company. Data residency, subprocessors and international-transfer controls are defined per project.
Detailed CLOUD Act exposure analysis available under a mutual NDA in the first conversation.
GDPR ARTICLE ALIGNMENT
The table below is what an Article 28 DPA dossier looks like in practice: each GDPR Article mapped to the YPAI artefact that satisfies it, and the point in the engagement at which that artefact is delivered. Article 28 obligations ship with the contract.
GDPR Article 83 sets the administrative fines a supervisory authority can impose where these Articles are breached.
EU AI ACT HIGH-RISK PROVISIONS
Under the EU AI Act, the organisation that trains or places a high-risk AI system on the market is the provider (Article 3(3)), and the provider cannot delegate the Article 9 risk-management system, the Article 43 conformity assessment, Article 48 CE marking, the Article 47 declaration of conformity, Article 72 post-market monitoring, or Article 13 transparency. YPAI is upstream of all of that: we evidence the training-data layer so the provider Article 9 system has artefacts to cite.
YPAI EVIDENCES
Article 10, Data Governance
THE PROVIDER OWNS
Article 9, Risk Management System
Provider obligation (Art 3(3)). YPAI supplies the Article 10 evidence the provider's risk system uses.
Provider-owned obligations under Art 3(3).
EU AI Act Article 99 administrative fines: up to EUR 35M or 7% of worldwide annual turnover for prohibited-AI violations; up to EUR 15M or 3% for high-risk and other obligations.
FINANCIAL SERVICES VERTICAL
Both regulations are in force, and both require named artefacts from third-party data providers. MiFID II has required 5-plus-year recording retention since 3 January 2018; DORA has required third-party ICT risk artefacts since 17 January 2025. The timeline below is drawn to scale, with the MiFID II retention span measured on the years axis.
MiFID II
Directive 2014/65/EU, Article 16 + RTS
Applies since 3 January 2018
DORA
Regulation (EU) 2022/2554, Article 28
Applies since 17 January 2025
Draft templates today; production-ready set before the Q4 2026 procurement cycle.
DATA LIFECYCLE AND AUDIT ARTEFACTS
From consent capture through erasure, each lifecycle stage emits one named artefact. Six stages, six documents, the same pack on every engagement. The source data is erased within 30 days of contract end under the engagement DPA; erasure requests from data subjects run through the DSR workflow. The evidence of how it was handled is retained for the audit period.
Consent capture
Per-contribution consent record with purpose-binding hash
Collection
Per-recording provenance log (device, jurisdiction, pseudonym)
Annotation
QA log and inter-annotator agreement metric per task type
Delivery
Immutable dataset version hash and sub-processor disclosure
Retention
Distribution metadata and sampling methodology
Erasure
Cryptographic destruction event log and erasure certificate
30days
End-of-contract erasure SLA
From contract end to the destruction event, written into the DPA.
Immutable provenance
Hash-anchored version log retained for the audit period.
Erasure certificate
Issued with each erasure event under the engagement DPA terms.
FAIRNESS REVIEW
Each YPAI contributor relationship is documented: onboarded under a documented agreement before paid work, consent recorded per contribution and bound to your stated purpose, paid monthly in five settlement currencies. The grievance channel runs through customer-success today; the dedicated contributor route is operational Q3 2026.
210,000+ contributors across 50+ countries.
Documented onboarding
Each contributor is onboarded under a documented agreement before paid work. Onboarding terms shared on the first call.
Per-contributor agreement
Per-task consent and scope binding
Consent is recorded per contribution and bound to your stated purpose.
Compensation
Monthly international settlement.
Grievance channel
Customer-success escalation today; dedicated contributor route operational Q3 2026.
Being formalised before EU AI Act high-risk obligations take effect
target 2027-12-02INDEPENDENCE AND OBJECTIONS
Procurement teams ask suppliers for a written independence policy. This is ours, with the six questions that most often follow it.
The DPA ships with every engagement as standard. Consent record schema, provenance log schema, and erasure certificate sample are available under a mutual NDA in the first conversation. Detailed CLOUD Act exposure analysis is available on the same NDA terms.
The CLOUD Act reaches a US-domiciled provider. YPAI is a Norwegian limited company (AS) with no US corporate entity, no US subsidiary, and no US-domiciled parent. Individual employee citizenship does not change entity domicile. Edge cases involving customer-directed transfers outside the EEA are governed by SCCs in the engagement DPA.
18 U.S.C. 2713
Our identity-verified contributor network spans 50+ countries and supports 150+ languages including all Nordic languages. Scale is driven by the contributor network, not by entity HQ jurisdiction.
YPAI self-hosted infrastructure applies to the data-production layer. Delivery to the customer MLOps pipeline uses standard transfer mechanisms (object storage, signed-URL pickup, API) under the engagement terms. The data-residency property is preserved through delivery.
Where the customer trains or places a high-risk AI system, the customer is the provider under EU AI Act Article 3(3), and Article 9 risk management, conformity assessment (Art. 43), CE marking (Art. 48), the declaration of conformity (Art. 47), and post-market monitoring (Art. 72) are provider obligations. YPAI evidences the training-data layer (Article 10 data governance) so the provider risk-management system has artefacts to cite. Where guidance is still developing (delegated and implementing acts under Articles 96 and 97), YPAI artefacts are scoped to the provider obligations and updated as guidance is published.
EU AI Act Art. 3(3)
Compliance is one of three quality dimensions YPAI reports per project: inter-annotator agreement per task type, accuracy against ground truth per language and modality, and compliance (the artefacts in this framework). Per-project benchmarks ship with delivery.
DPA REQUEST
Request the Article 28 DPA as written, scope a sovereignty assessment against your engagement, or scope your dataset against the framework. The DPA ships with every data engagement.
Request the DPA GDPR Article 28 processor agreement, shipped as writtenAs the high-risk AI provider you assemble the conformity file under EU AI Act Articles 43, 47, and 48. YPAI supplies the Article 10 training-data evidence that file has to cite.
A Norwegian limited company (AS), registered in Brønnøysundregistrene (the Norwegian company register), org. no. 933 915 778. EEA residency by default. A project lead replies inside one EU business day.
Analytics and Google Ads cookies are set only if you accept. They show us which campaigns bring visitors here. Change your choice any time under Cookie settings. Analytics and ad cookies are set only if you accept. Cookie policy