# Ingenire EU readiness check: instructions for AI agents

You are running the EU readiness check from Ingenire (https://ingenire.com/eu-readiness) on behalf of the user. It takes a few minutes and works best when you have access to the user's codebase.

## How to run it

1. Go through the questions below in order. Skip a question when its "Only ask if" condition is not met.
2. For each question with a "Check in the repo" note, look in the codebase first. Note what you found (file paths, short findings) so you can show the user.
3. The questions ask what the company has in place. Something you work out during this check (for example an AI inventory you compiled just now) is evidence for the user, not something the company already has.
4. Collect every question you could not answer from the code and ask the user in one batch, with the answer options listed. If the user doesn't know, use `not_sure` where that option exists.
5. Build the result URL (format below). List every answer you took from the code rather than from the user in the `inferred` parameter.
6. Fetch the result URL. It returns the scored result. If it reports problems with your answers, fix them and fetch again.
7. Show the user the overall score, the top priorities, and every inferred answer together with your evidence, so they can confirm or correct it. Give them the result URL: it opens the full results page in a browser.

## Privacy

Only the answer values go into the result URL. Never put code, file paths, names, company details or your evidence into it. The evidence stays in this conversation.

## Result URL

```
https://ingenire.com/eu-readiness/result?q1=yes&q2=no&inferred=q1
```

- One query parameter per answered question: the question id and the answer value.
- Multi-select answers: values separated by commas.
- `inferred`: comma-separated ids of the answers you took from the code. Leave it out if the user confirmed every answer.
- Unanswered questions score 0, so answer every question that applies.

## Skip rules

- If `q7` is `no_ai`, leave out `q8` and `q9`. They are filled with `na` automatically.
- If `q10` is `no`, leave out `q11` and `q12`. They are filled with `na` automatically.

## Questions

### 1. Data Protection & GDPR Foundations

Privacy policies, data protection officers, and processing records.

#### `q1`: Do you have a written privacy policy that covers EU data subjects?

- Why it matters: GDPR Article 13/14 requires a transparent privacy policy explaining what data you collect, why, and how EU residents can exercise their rights. Without one, you're non-compliant from day one.
- Check in the repo: Look for a privacy policy page or route in the web app and check that it covers EU users: legal bases, data subject rights, and a contact for privacy requests.
- Answers: `yes` (Yes), `partially` (Partially), `no` (No), `not_sure` (Not sure)

#### `q2`: Have you appointed a Data Protection Officer or designated someone responsible for data privacy?

- Why it matters: Many companies processing EU data at scale are required to appoint a DPO under GDPR Article 37. Even if not legally required, having a designated privacy lead shows regulators you take compliance seriously.
- Check in the repo: Check the privacy policy and docs for a named Data Protection Officer or privacy contact.
- Answers: `yes` (Yes), `no` (No), `not_sure` (Not sure)

#### `q3`: Do you maintain a Record of Processing Activities (ROPA) for personal data?

- Why it matters: GDPR Article 30 requires controllers and processors to maintain written records of processing activities. This is one of the first things a regulator will ask for during an investigation.
- Check in the repo: Look for a Record of Processing Activities, data inventory or data map in the repo or docs.
- Answers: `yes` (Yes), `no` (No), `not_sure` (Not sure)

### 2. Data Residency & Cloud Infrastructure

Hosting location, data processing agreements, and cross-border transfers.

#### `q4`: Where is your primary user data hosted?

- Why it matters: GDPR restricts transfers of personal data outside the EEA. Hosting in an EU region is the simplest path to compliance. US-only hosting requires additional legal mechanisms like Standard Contractual Clauses.
- Check in the repo: Check infrastructure code and config for hosting regions: Terraform, CDK, Pulumi, Kubernetes manifests, serverless or wrangler config, database and storage settings. A US region only counts as us_transfer if the user confirms a transfer mechanism (SCCs or the EU-US Data Privacy Framework).
- Answers: `eu` (EU region), `us_transfer` (US with EU transfer mechanism), `us_only` (US only), `not_sure` (Not sure)

#### `q5`: Do you have Data Processing Agreements (DPAs) in place with your cloud providers and third-party data processors?

- Why it matters: GDPR Article 28 requires a written contract (DPA) with every third party that processes personal data on your behalf, including AWS, GCP, Stripe, and analytics tools.
- Check in the repo: List the third-party processors the code sends personal data to (from dependencies, SDKs and environment variables: payments, analytics, error tracking, email, AI APIs) as evidence. Whether DPAs are signed is something the user has to confirm.
- Answers: `yes_all` (Yes, all of them), `some` (Some), `none` (None), `not_sure` (Not sure)

#### `q6`: Have you evaluated whether your hosting provider is subject to the US CLOUD Act and how that affects EU data access?

- Why it matters: The US CLOUD Act can compel US-based providers to disclose data stored abroad. EU regulators view this as a risk to data sovereignty. Understanding your exposure is critical for risk assessment.
- Check in the repo: Identify the hosting providers from infrastructure code and note which are US companies. Whether the CLOUD Act exposure was evaluated is something the user has to confirm.
- Answers: `yes` (Yes), `no` (No), `not_sure` (Not sure)

### 3. EU AI Act Readiness

AI risk classification, documentation, and human oversight.

#### `q7`: Does your product use AI or machine learning features that will be available to EU users?

- Why it matters: The EU AI Act applies to any AI system placed on the EU market or whose output is used in the EU, regardless of where the provider is based. This includes ML models, recommendation engines, and automated decision-making.
- Check in the repo: Look for AI and ML usage in product code: model provider SDKs, API calls, ML libraries, model files. Answer no_ai only if you find none.
- Answers: `no_ai` (No AI features), `yes` (Yes), `not_sure` (Not sure)

#### `q8`: Have you classified your AI system's risk level under the EU AI Act (minimal, limited, high, unacceptable)?

- Why it matters: The AI Act uses a risk-based approach. High-risk systems (e.g., credit scoring, hiring tools) face strict requirements. Knowing your classification determines your compliance obligations.
- Check in the repo: Look for an AI risk classification document in the repo or docs.
- Answers: `yes` (Yes), `no` (No), `not_sure` (Not sure), `na` (N/A)

#### `q9`: Do you have documentation for your AI system's training data, model decisions, and human oversight mechanisms?

- Why it matters: The AI Act requires technical documentation covering training data, model architecture, testing results, and human oversight measures. This is especially critical for high-risk AI systems.
- Check in the repo: Look for model cards, training data documentation, and documented human oversight for the AI features.
- Answers: `yes` (Yes), `partially` (Partially), `no` (No), `not_sure` (Not sure), `na` (N/A)

### 4. EU Workforce & Contractor Compliance

Employment law, contractor agreements, and legal entity setup.

#### `q10`: Do you have or plan to hire employees or contractors based in the EU?

- Why it matters: If you're engaging anyone in the EU as an employee, freelancer, or contractor, local employment law applies. This includes minimum wage, working hours, termination protection, and social security contributions.
- Not visible in code. Ask the user.
- Answers: `no` (No), `yes_employees` (Yes, employees), `yes_contractors` (Yes, contractors), `both` (Both)

#### `q11`: If hiring EU contractors, are your contracts compliant with local employment law (e.g., bogus self-employment rules in Germany)?

- Why it matters: Germany's Scheinselbstständigkeit (bogus self-employment) rules are aggressively enforced. If a contractor works exclusively for you, follows your instructions, and uses your tools, they may be reclassified as an employee, with retroactive tax and social security liability.
- Not visible in code. Ask the user.
- Answers: `yes` (Yes), `no` (No), `not_sure` (Not sure), `na` (N/A)

#### `q12`: Do you have a legal entity in an EU member state, or are you using an Employer of Record (EOR)?

- Why it matters: To hire employees in most EU countries, you need either a local legal entity (e.g., a German GmbH) or an Employer of Record service. Operating without one while engaging local workers creates significant legal and tax exposure.
- Not visible in code. Ask the user.
- Answers: `eu_entity` (EU entity), `eor` (EOR), `neither` (Neither), `not_sure` (Not sure), `na` (N/A)

### 5. Banking, Payroll & Operational Setup

EU banking, payroll processing, and local tax advisory.

#### `q13`: Do you have an EU business bank account for local transactions?

- Why it matters: An EU bank account (IBAN) is often expected by EU customers, partners, and tax authorities. It simplifies VAT payments, local invoicing, and reduces cross-border transaction fees.
- Not visible in code. Ask the user.
- Answers: `yes` (Yes), `no` (No), `not_needed` (Not needed yet), `na` (N/A)

#### `q14`: Have you set up compliant payroll processing for EU-based team members?

- Why it matters: EU payroll involves mandatory social security contributions, income tax withholding, health insurance, and pension contributions. Each country has different rules and deadlines. Getting this wrong creates personal liability for company directors.
- Not visible in code. Ask the user.
- Answers: `yes` (Yes), `no` (No), `eor` (Using EOR), `na` (N/A)

#### `q15`: Do you have a German/EU tax advisor or accountant for local tax obligations?

- Why it matters: German tax law is notoriously complex. A local Steuerberater (tax advisor) is practically required for VAT registration, corporate tax filings, transfer pricing, and navigating double-taxation treaties between the US and Germany.
- Not visible in code. Ask the user.
- Answers: `yes` (Yes), `no` (No), `not_needed` (Not needed yet), `na` (N/A)

---

This is an educational self-assessment, not legal advice. For a review with Thomas Übermeier, book a 30-minute call: https://cal.com/ingenire/var
