For DPO / Legal
Compex is designed to support DPO and legal review by making scope, policy, approval, auditability, and evidence records explicit. These docs do not claim that Compex is fully GDPR compliant or that use of Compex guarantees legal protection.
Compex is evaluation-stage and not independently certified. Each pilot needs its own legal basis, data-processing scope, review process, and risk assessment.
Review focus areas
- What data is in scope?
- What workload or service is allowed?
- Who approves the run?
- Who can access outputs?
- What evidence records are retained?
- What limitations are acknowledged before approval?
What this means
For DPO / Legal readers, Compex should be evaluated as a policy-controlled execution and evidence layer. The useful question is whether it can provide a clearer, narrower, and more reviewable path than uncontrolled sharing or ad hoc exports.
Current status
The current posture includes role-separated access, policy-controlled workflows, audit and evidence records, and sandbox and pilot environments. Certification-readiness planning is part of the roadmap.
Limitations
Compex does not determine lawful basis, replace a DPIA, guarantee anonymization, or certify downstream model outputs. Those questions remain with the responsible parties.