47 days remaining. EU AI Act high-risk enforcement begins August 2, 2026. High-risk AI system penalties up to €15M.
View compliance packages →
Sentinel
GDPR · AI Act · NIS2 · Fixed-Price · 7–21 Day Delivery

EU Compliance.
Fixed price. Delivered fast.

Sentinel is a compliance platform that produces your GDPR documentation, AI Act assessment, and NIS2 readiness — in 7 to 21 days, at a fixed price. No hourly billing. No six-figure budgets. Full EU compliance coverage for Irish businesses.

⚠ GDPR fines up to €20M or 4% of turnover · AI Act high-risk fines up to €15M · Enforcement active now

✓ Fixed price — no surprises ✓ Delivered in 7–21 days ✓ CIPP/E certified advisors ✓ Evidence-ready documents
Live — Cumulative EU GDPR penalties
€7,100,000,000
Ireland's DPC issued €652M in penalties in 2024 alone — more than half the EU total for the year. This figure increases every second as enforcement continues.
EU AI Act — High-Risk Compliance Deadline
August 2, 2026
All organisations deploying AI in high-risk applications must demonstrate full compliance by this date. Penalties reach €35M or 7% of global annual turnover.
--Days
--Hours
--Mins
--Secs
€7.1BEU GDPR penalties since 2018
€15MAI Act high-risk system penalty
€20MGDPR penalty — or 4% of turnover
72 hrsMandatory breach notification window
Aug 2AI Act enforcement date 2026
What Sentinel is

We produce your compliance documents.
You stay protected.

GDPR applies to every Irish and EU business — regardless of size. The AI Act high-risk deadline is August 2, 2026. Most SMEs do not have a compliance team, a DPO, or months to spend on this.

Sentinel produces every document you need: Article 30 register, privacy policy, breach response procedure, AI Act assessment, NIS2 readiness report, and staff training certificates — each reviewed by a CIPP/E certified advisor before delivery. Fixed price. Defined scope.

7–21 day delivery
Traditional compliance engagements take 4–12 weeks. When the August 2 deadline is weeks away, speed is critical.
💰
Fixed-price transparency
Traditional compliance consultants charge €200–500 per hour with no ceiling. A GDPR audit routinely exceeds €8,000 before a single document is produced. Sentinel: fixed price, defined scope.
🎓
CIPP/E certified advisors
Every engagement is reviewed by a CIPP/E certified EU compliance professional — the recognised qualification standard across all 27 EU member states.
Services

Every compliance obligation. One engagement.

Sentinel covers the full spectrum of EU compliance requirements. Each service is delivered as part of a fixed-price package — customised to your organisation, not a generic template.

🔍
Mandatory
Compliance Gap Assessment
A structured analysis of your organisation against GDPR, AI Act, and NIS2. Plain-English report identifying every gap, its risk level, and remediation sequence. The foundation of every Sentinel engagement.
⚠ Without this — your regulatory exposure is unknown
🤖
Deadline Aug 2
AI Act Risk Classification
Systematic inventory and risk classification of every AI system your organisation uses. Produces the technical documentation, conformity assessment preparation, and governance framework required under the AI Act.
⚠ Unclassified AI systems — immediate enforcement risk from August 2
📄
Legally mandatory
GDPR Document Suite
Article 30 Record of Processing Activities, privacy policy, data breach response procedure, and data subject rights process — all tailored to your organisation's specific processing activities.
⚠ Absence of documentation — automatic finding in any DPC investigation
🌐
GDPR mandatory
Consent & Cookie Compliance
Compliant cookie consent mechanism, privacy notice, and consent management documentation. Non-compliant cookie implementations are the most frequently reported GDPR violation to the DPC.
⚠ Most frequently reported GDPR violation in Ireland
🏛️
AI Act required
AI Governance Framework
Human oversight procedures, AI transparency documentation, model governance policies, and bias monitoring requirements — required for all organisations operating high-risk AI systems under the AI Act.
⚠ No governance framework — non-compliant from August 2, 2026
🔗
All regulations
Third-Party & Supplier Management
Assessment of supplier relationships from a data processing perspective. Production of Data Processing Agreements for all processors. Protects your organisation if a supplier fails their obligations.
⚠ Controller liability extends to processor non-compliance
🛡️
NIS2 required
Cybersecurity & NIS2 Compliance
NIS2 incident response plan, cybersecurity risk assessment, technical security measures documentation, and board-level oversight framework. NIS2 is already in force — many organisations remain unaware of their obligations.
⚠ NIS2 is enforced now — not optional
🎓
GDPR + AI Act
Staff Training & Certification
GDPR requires documented annual staff training. AI Act requires AI literacy training. Custom modules for your industry — tracked completion, certificates issued, records audit-ready.
⚠ Absence of training records — a liability in any investigation
📡
Ongoing
Regulatory Monitoring
Continuous monitoring of EU regulatory developments. Sentinel alerts you when changes create new obligations and delivers updated documentation to reflect revised requirements.
✓ Regulatory changes actioned before they affect your position
Regulations covered

Five regulations. Complete coverage.

Every EU regulation that could affect your business — covered, documented, and monitored.

GDPR
General Data Protection Regulation
Up to €20M or 4% of turnover
In force since 2018
AI Act
EU Artificial Intelligence Act
Up to €35M prohibited · €15M high-risk
High-risk: August 2, 2026
NIS2
Network & Information Security
Up to €10M — essential entities
In force now
CSRD
Corporate Sustainability Reporting
Mandatory reporting
Phased 2024–2026
DORA
Digital Operational Resilience Act
Financial sector
In force January 2025
Industries served

The organisations with the greatest regulatory exposure.

🤖
Recruitment Agencies
AI CV screening and video interview tools are explicitly classified as HIGH RISK under AI Act Annex III. 88% of Irish recruiters now use AI screening — almost none are compliant.
Annex III HIGH RISK
💻
Technology & SaaS
Customer data at scale, AI features in product, and investors require compliance documentation at Series A. Non-compliance blocks fundraising and enterprise sales.
GDPR + AI Act
💳
Fintech & Financial
GDPR + DORA + AI Act simultaneously. AI-assisted credit assessment and fraud detection carry specific high-risk AI obligations under AI Act Annex III.
GDPR · DORA · AI Act
🏥
Healthcare Clinics
Health data is special category under GDPR — highest penalties and strictest processing conditions. Any clinic using digital records or AI diagnostic tools must be fully compliant.
Special category data
⚖️
Legal Practices
Privileged and sensitive client data with increasing AI tool deployment. A law practice with a data breach faces both regulatory and professional disciplinary consequences.
Privileged data risk
📣
Marketing Agencies
Every campaign touches GDPR. Cookie tracking, email marketing, behavioural targeting, customer profiling — all require documented legal bases. Controller and processor obligations apply.
GDPR · Consent · DPA
🛒
E-Commerce
Customer data at scale, payment processing, email lists, cookie consent, AI product recommendations — you process more data than almost any other SME category.
GDPR · High-volume data
🏢
HR Software Companies
AI in performance scoring, candidate matching, or retention prediction is Annex III high-risk. Products influencing employment decisions must be compliant before August 2.
Annex III HIGH RISK
Pricing

Fixed-price compliance. No hourly billing.

Simple, transparent pricing. One fixed fee. Defined scope. Delivered in 14 days.

Why Sentinel?
Traditional consultants charge €18,000–€300,000 for GDPR + AI Act compliance.
Sentinel starts at €1,500. Fixed price. Same legally-validated outcome.
Fixed price 14 days No hourly billing

Founding client programme

Sentinel is accepting its inaugural client engagements. Founding clients receive direct access to our senior compliance team on every aspect of their project.

Direct senior access Founding client pricing locked in 30-day post-delivery support
✓ New to compliance? Begin with a one-time project. Monthly monitoring is available once your compliance baseline is established.
Which package is right for you?
Essentials — €1,500You handle personal data. No AI tools. Need GDPR documentation only.
Compliance Ready — €3,500You use AI tools (ChatGPT, CRMs, screening). Need GDPR + AI Act covered.
Full Compliance — €9,500100+ staff, multiple regulations, board reporting, DPO advisory included.
Not sure? All packages include a scoping call. We confirm the right fit before any work begins.
Any size · GDPR only
GDPR Focus
Essentials
1,500
Fixed fee · 7 business days · GDPR only
Save €2,500–€6,500 vs traditional consultants
For: small businesses, startups, any company not yet using AI tools
  • Data mapping and processing register (Art. 30)
  • Privacy policy — written for your business
  • Cookie policy and consent framework
  • Data breach response procedure
  • Staff data protection awareness guide
  • GDPR compliance gap analysis report
  • One delivery call with our team
  • 30 days post-delivery email support

Traditional consultants: €4,000–8,000 · You pay: €1,500

Any size · GDPR + AI Act
Most requested
Compliance Ready
3,500
Fixed fee · 14 business days · GDPR + AI Act
Save €10,500–€21,500 vs traditional consultants
For: any company using AI tools — ChatGPT, screening software, AI-powered CRMs
  • Everything in Essentials
  • AI tools inventory — all systems mapped and classified
  • EU AI Act risk classification for each tool
  • AI governance policy document
  • Human oversight procedures (required under AI Act)
  • AI transparency notices for staff and customers
  • Staff AI literacy training module
  • Data Processing Agreements — up to 5 suppliers
  • Audit-ready compliance evidence folder
  • Two delivery calls with our team
  • 30 days post-delivery email support

Traditional consultants: €14,000–25,000 · You pay: €3,500

100–500 employees · All regulations
Complete Coverage
Full Compliance
9,500
Fixed fee · 21 business days · GDPR + AI Act + NIS2
Save €50,000+ vs traditional consultants
For: mid-size companies needing full EU regulatory coverage and board documentation
  • Everything in Compliance Ready
  • NIS2 cybersecurity policy and incident response plan
  • NIS2 risk assessment for your sector
  • Supplier compliance assessments — up to 10
  • Board-level compliance summary report
  • Staff GDPR training with completion certificates
  • DPO advisory session — 2 hours with qualified advisor
  • Data Processing Agreements — up to 10 suppliers
  • Three delivery calls with our team
  • 30 days post-delivery email support

Traditional consultants: €60,000–150,000 · You pay: €9,500

Why subscribe instead of paying once?
GDPR guidance changes. AI Act implementation rules are issued monthly. NIS2 enforcement has started. A compliance document from 6 months ago may already be outdated. Subscribers always have current, enforceable documentation — without paying for a new project every time regulations move.
What changes every month
DPC decisions & guidance
AI Act implementation rules
NIS2 enforcement updates
New AI tools need classifying
Staff training renewal
New suppliers need DPAs
New to compliance? then subscribe to stay current.
What the market charges vs Sentinel
What you get Market rate Sentinel price
Monitoring + regulatory alerts €500–€1,500/month €199/month
Monitoring + document updates €1,500–€3,000/month €599/month
Named advisor + full service €3,000–€8,000/month €1,499/month
Fractional DPO — legal accountability €5,000–€10,000/month €3,500/month
Any size
Monitoring
Sentinel Watch
199/mo
Monthly · Cancel anytime
Save €300–€1,300/month vs market
  • GDPR regulatory change monitoring
  • AI Act implementation alerts
  • Monthly compliance briefing
  • DPC decision alerts — your sector
  • Email advisory — 1 business day
  • Annual compliance health check

Market: €500–€1,500/mo · Sentinel: €199/mo

Any size
Most popular
Sentinel Maintain
599/mo
Monthly · Annual plan saves €1,200/year
Save €900–€2,400/month vs market
  • Everything in Watch
  • Documents updated when regulations change
  • New AI tool assessments on request
  • Supplier DPA updates — up to 2/month
  • Staff training renewal annually
  • Quarterly compliance review call
  • Compliance evidence log — audit ready

Market: €1,500–€3,000/mo · Sentinel: €599/mo

50–500 employees
Advisory
Sentinel Advise
1,499/mo
Monthly · Named advisor assigned
Save €1,500–€6,500/month vs market
  • Everything in Maintain
  • Named compliance advisor — your point of contact
  • Monthly check-in call with written summary
  • GDPR, AI Act, and NIS2 full monitoring
  • Unlimited document updates
  • Supplier assessments — up to 5/month
  • Board compliance summary — quarterly

Market: €3,000–€8,000/mo · Sentinel: €1,499/mo

Any size
Fractional DPO
Sentinel DPO
3,500/mo
Monthly · Qualified DPO assigned to your org
Save €1,500–€6,500/month vs full-time DPO
  • Everything in Advise
  • Named qualified DPO — legal accountability
  • DPC registration and correspondence
  • Breach notification management — 72hr window
  • DPIA oversight for new projects
  • Data subject access request management
  • Unlimited same-day email advisory

Full-time DPO: €60,000–€90,000/year · Sentinel: €42,000/year

Annual plan: Pay annually on any retainer and save the equivalent of 2 months. Ask about annual pricing on your consultation call.
Sentinel provides compliance software and information services — not legal advice. All documentation should be reviewed by a qualified solicitor before formal reliance. Full disclaimer →
Sentinel · EU Regulatory Risk Assessment

What is your organisation's
estimated penalty exposure?

Answer 6 questions. Receive an evidence-based estimate of your exposure under GDPR and the EU AI Act — calculated on the actual legal penalty framework, not headline maximum figures.

⚖️ Based on GDPR Article 83 and EU AI Act Article 99 penalty framework. Does not constitute legal advice.
Question 1 of 6
Question 1 of 6
How many employees does your organisation have?
Company size is a primary factor in penalty calculation. EU AI Act Article 99(6) explicitly provides that SMEs receive proportionally adjusted penalties — for SMEs, fines are capped at the lower of the fixed amount or the revenue percentage, not the higher. This significantly affects your realistic maximum exposure.
1–10 employees
Micro-enterprise
SME AI Act protections apply in full
11–50 employees
Small enterprise
SME AI Act protections apply in full
51–250 employees
Medium enterprise
SME protections likely apply
250+ employees
Large organisation
Standard calculation — higher of fixed or % applies
Question 2 of 6
What is your organisation's approximate annual revenue?
GDPR penalties are calculated as up to 4% of global annual turnover. AI Act penalties for SMEs are the lower of the fixed amount or the percentage — meaning this figure directly determines your realistic maximum exposure, not the headline figures. Enter your best estimate.
€200K €500K €1M €3M €10M €50M
Question 3 of 6
What categories of personal data does your organisation process?
GDPR distinguishes between standard personal data and special categories. Special category data — health, financial, biometric, children's data — attracts significantly higher penalties and triggers stricter processing conditions. Select all that apply.
Basic contact data
Names, email addresses, phone numbers, postal addresses
Behavioural or tracking data
Cookies, purchase history, browsing behaviour, customer profiling
Financial data
Payment records, credit information, bank account details, salary data
Health or medical data
Patient records, medical history, wellbeing data, insurance information
Special category data — highest penalty exposure
Employment and HR data
Employee records, recruitment data, performance assessments, payroll
Children's data (under 18)
Data relating to minors — attracts highest regulatory scrutiny
Special category data — severe penalty exposure
Question 4 of 6
Which AI systems does your organisation currently use or deploy?
The EU AI Act classifies AI systems by risk level. Annex III explicitly identifies high-risk applications — recruitment, credit assessment, healthcare, and public-facing decisions. These require full compliance documentation by August 2, 2026. Select all that apply.
None — we do not use AI tools
No AI exposure under the EU AI Act
General productivity AI (e.g. ChatGPT, Copilot, Gemini)
Used internally for drafting, summarisation, or research — limited or minimal risk
AI for marketing or customer targeting
Behavioural advertising, email personalisation, customer segmentation
AI for recruitment or HR decisions
CV screening, candidate ranking, video interview assessment, performance scoring
⚠ Annex III HIGH RISK — full compliance required by August 2, 2026
AI for credit assessment or financial decisions
Credit scoring, fraud detection, loan assessment, insurance underwriting
⚠ Annex III HIGH RISK — full compliance required by August 2, 2026
AI in healthcare or medical applications
Diagnostic support, patient triage, clinical decision support, medical imaging
⚠ Annex III HIGH RISK — full compliance required by August 2, 2026
AI customer service or chatbots
Automated customer support, virtual assistants, complaint handling AI
Question 5 of 6
Which compliance documents does your organisation currently have in place?
Existing compliance documentation is one of the primary mitigating factors under GDPR Article 83(2)(c) and AI Act Article 99. Regulators treat documented good-faith compliance efforts significantly more favourably. Each document you have reduces your estimated exposure.
GDPR-compliant privacy policy
Published on your website, covering all required information
✓ Reduces estimated exposure
Article 30 Record of Processing Activities
Documented register of all data processing activities, purposes, and legal bases
✓ Reduces estimated exposure — first document the DPC requests
Data breach response procedure
Documented procedure for identifying and notifying breaches within 72 hours
✓ Reduces estimated exposure
Compliant cookie consent mechanism
Genuine opt-in consent — no pre-ticked boxes, equal accept/reject options
✓ Reduces estimated exposure
Documented staff GDPR training records
Evidence of annual training with completion records
✓ Reduces estimated exposure
AI system inventory and risk classification
Documented inventory with risk classifications under the AI Act
✓ Significantly reduces AI Act exposure
Question 6 of 6
Has your organisation previously been subject to DPC investigation, complaint, or enforcement action?
Prior regulatory history is an explicit aggravating factor under GDPR Article 83(2)(i) and (j). A clean regulatory history is a mitigating factor that reduces penalty calculation.
No previous complaints, investigations, or enforcement actions
Clean regulatory history
Mitigating factor in fine calculation
A complaint or enquiry has been received
A complaint has been lodged but no formal finding has been made
A formal DPC investigation has been conducted
The DPC has opened or conducted a formal investigation
Aggravating factor — increases penalty calculation
A previous fine or enforcement action has been issued
The organisation has received a previous GDPR fine or enforcement order
Significant aggravating factor — materially increases penalty calculation
Professional credentials

Qualified expertise behind every engagement.

Sentinel combines advanced AI generation with professional compliance review. Every engagement is supported by CIPP/E certified compliance advisors — ensuring documentation meets the standards regulators and legal professionals expect.

🎓
CIPP/E Certified Advisors
Every Sentinel engagement is reviewed by a CIPP/E certified compliance professional. CIPP/E — Certified Information Privacy Professional (Europe) — is the recognised qualification standard for EU data protection and privacy compliance, awarded by the International Association of Privacy Professionals (IAPP).
⚖️
Legally Validated Frameworks
All document frameworks and templates are built against the current text of the applicable regulation. They are validated for accuracy before use and reviewed on a quarterly basis as regulatory guidance evolves. AI generates. Qualified professionals verify.
🔄
Quarterly Review Cycle
EU regulatory guidance changes continuously — the DPC alone issued 11 updates in 2024. All Sentinel document frameworks are reviewed quarterly to ensure they reflect the current regulatory position. AI Act implementation guidance is tracked as it is published through 2026 and 2027.
🤝
Solicitor Collaboration Model
Sentinel produces the substantive compliance documentation. Your solicitor reviews the finished suite and confirms legal readiness — typically 1–2 hours of their time rather than 20+ hours of original drafting. Professional oversight is maintained at a fraction of the cost.

What CIPP/E certification means for your organisation

The CIPP/E credential is awarded by the International Association of Privacy Professionals (IAPP) — the world's largest privacy professional organisation. It represents demonstrated knowledge of European data protection law, regulatory framework, and compliance practice. It is the qualification standard recognised by data protection authorities and legal professionals across the EU. When a Sentinel compliance advisor reviews your documentation, they bring this qualification and the current regulatory knowledge it represents.

Recognised across all 27 EU member states
CIPP/E is the accepted professional standard for privacy compliance expertise throughout the European Union.
Current regulatory knowledge maintained
Certification requires ongoing professional development — advisors remain current as regulations evolve.
Every engagement reviewed before delivery
No Sentinel compliance pack is delivered without review by a CIPP/E certified advisor.
Transparent about what we provide
Sentinel provides compliance software and information services — not legal advice. We always recommend solicitor review before formal reliance.
Frequently asked questions

Common questions answered.

Does the EU AI Act apply if we only use tools like ChatGPT?+
Yes. The AI Act applies to any organisation that deploys or uses AI systems — not solely to organisations that develop AI. If your organisation uses ChatGPT for client-facing communications, AI-assisted recruitment, AI-powered customer service, or any AI system that influences decisions about individuals, you have obligations under the Act. At minimum you must maintain an inventory and risk classification. High-risk applications require full documentation by August 2, 2026.
How does Sentinel's pricing compare to traditional compliance consultants?+
Traditional compliance consultants charge €18,000–€300,000 for combined GDPR + AI Act engagements, depending on company size and risk profile. Sentinel's Compliance Ready package at €3,500 covers GDPR + AI Act documentation — defined scope, fixed price, 14-day delivery. The difference reflects our AI-assisted production model reviewed by qualified compliance professionals, rather than traditional hourly billing at €200–500 per hour.
Is Sentinel a compliance consultancy? Will I still need a solicitor?+
Sentinel is a compliance software and information service — not a law firm and not a legal practice. We strongly recommend that all clients have their compliance documentation reviewed by a qualified solicitor before formal reliance. Sentinel makes this practical and affordable: your solicitor reviews a complete, professionally structured suite in 1–2 hours rather than drafting from first principles over 20+ hours. You retain professional oversight at approximately 10% of a full legal engagement cost.
What if the DPC contacts our organisation?+
Organisations with a Sentinel compliance pack are substantially better positioned. You will have: a documented Article 30 record, a data breach response procedure, evidence of staff training, an AI system inventory with risk classifications, and a structured evidence folder available for immediate production. DPC investigations take genuine, documented compliance effort into account when determining sanctions — organisations demonstrating good-faith compliance efforts are significantly less likely to receive the maximum penalty.
Do we require monthly monitoring or is a one-time engagement sufficient?+
For most organisations, a one-time project engagement establishes the compliance baseline. Monthly monitoring becomes operationally important when: you are growing rapidly and introducing new AI systems; you require automatic document updates as regulations evolve (the AI Act is implemented in phases through 2026 and 2027); or you need ongoing assurance your position remains current. We will advise you honestly on your consultation call whether ongoing monitoring is warranted.
Our organisation is not based in Ireland — do EU regulations still apply?+
Yes, in most cases. GDPR applies to any organisation that processes personal data of EU residents regardless of where the organisation is established. The AI Act applies to any AI system placed on the EU market or put into service in the EU — including systems operated by non-EU organisations. If your organisation has EU customers, EU employees, or EU-based operations of any kind, you have EU compliance obligations.
What is the realistic timeline to achieve compliance before August 2, 2026?+
The Essentials package is delivered within 7 business days. Compliance Ready within 14 business days. Full Compliance within 21 business days. There is sufficient time to achieve compliance before the August 2 deadline — but the window is finite. Request a consultation and we will confirm your specific timeline and confirm that your organisation can be compliant before enforcement begins.
Contact Sentinel

Request a free compliance consultation.

A 20-minute call with our compliance team to assess your regulatory exposure, identify your gaps, and recommend the appropriate package. No payment required. No commitment.

🌐sentinel-firm.com
Response time
We respond to all enquiries within one business day to confirm your consultation time. No automated responses — every enquiry is reviewed by our compliance team.
⏰ August 2, 2026 — 47 days remaining
If you want to be compliant before the AI Act enforcement date, enquire today. Delivery timelines range from 7 to 21 business days depending on the package selected.

Request a free consultation

Complete the form below and we will be in touch within one business day to confirm your appointment.

No payment. No commitment. We respond within one business day.

Legal Notice & Disclaimer
Sentinel is a compliance software and information service. It does not provide legal advice. All content, documents, reports, gap analyses, risk assessments, AI Act compliance packs, governance policies, and other materials provided through Sentinel's services are for informational and operational guidance purposes only and do not constitute legal advice. All documents should be reviewed by a qualified solicitor in your jurisdiction before formal implementation or submission to any regulatory authority. Use of Sentinel's services does not constitute or guarantee regulatory compliance. Sentinel accepts no liability for regulatory penalties, enforcement actions, or business losses. Sentinel is a compliance software and information service operating via sentinel-firm.com. Terms of Service · Privacy Policy · Legal Disclaimer