Personalised tuition in Malta & onlineEnquiries & applications: WhatsApp +356 7940 1017 · [email protected]
Governance

Compliance should be mapped to evidence, owners and systems.

The platform adds a control/evidence register and AI-use-case inventory. It is a readiness framework, not a claim of certification or legal advice.

Control areaArchitectureEvidence / ownerClaim
Privacy / data rightsData-rights requests, retention policies, exports and access controlsRequest logs, policy versions, access auditReadiness architecture only
SafeguardingRestricted case workflow, controlled messaging and escalationCase/action logs and role evidenceNo external certification claimed
AI governanceUse-case register, risk assessment, evaluation, provenance, approvalsEvaluation results, approval records and model registryOperational readiness
SecurityMFA-ready identity, session logs, incidents, backups, restore testsControl evidence and test recordsNo SOC/ISO certification claimed
PaymentsProvider tokens remain external; event/reconciliation architectureProvider/webhook and reconciliation recordsProvider compliance remains provider-specific
Regulatory snapshot — 11 September 2026: the EU AI Act is generally applicable from 2 August 2026. Under the current EU implementation timeline, certain high-risk use cases in education and other Annex III areas are scheduled to apply from 2 December 2027. Requirements and classification depend on the exact use case, so this page should be reviewed against current official guidance before production reliance.
Find TutorWhatsApp