Compliance
Dataset Provenance & Audit Documentation
Last updated: July 2026
Every dataset delivery includes provenance records, consent documentation, and audit-ready exports mapped to EU AI Act and GDPR requirements.
1. Executive summary
- Consent
- Verifiable consent records for every platform-collected asset
- Languages
- 150+ languages delivered through enterprise engagements
- Evidence
- Single evidence bundle per delivery; JSON/CSV exports plus human-readable summaries
- Lineage
- Chain-of-custody from collection to delivery with timestamps and versions
- Erasure
- Right-to-erasure workflows with deletion evidence
- Scope
- Documentation depth and artifacts defined during scoping
2. The problem this solves
"Where did this record come from, who consented, and what changed?"
Most teams answer with partial logs, screenshots, and conflicting spreadsheets. The result: delayed launches, failed procurement reviews, and legal exposure. Engineering gets pulled in to reconstruct lineage across pipelines, vendors, and notebooks, weeks later, when evidence is already incomplete.
Training data with disputed consent creates legal exposure that surfaces during due diligence. Provenance documentation delivered with the dataset closes that gap before it opens.
3. What ships with every dataset
Provenance is delivered as a single evidence bundle instead of ad hoc screenshots and spreadsheets:
- Consent records linked to each delivered asset and version
- Chain-of-custody from source to delivery with timestamps
- Audit-ready exports: JSON/CSV plus human-readable summaries
- Version history and documented handling of exceptions
The bundle shows chain-of-custody and consent records tied to versions and timestamps, so procurement and compliance reviews reference one artifact set rather than reconstructed fragments.
4. Record-level lineage
Any delivered asset, version, and derivative can be traced through the documented processing chain: who collected it, under which consent framework, which QA gates it passed, and when it was packaged for delivery.
Access to data during production is role-based and logged, and reviewer workflows are documented so compliance teams can verify who handled which records. During an incident review, the documentation supports verifying whether a record or version was used downstream.
5. Regulatory mapping
| Framework | What the documentation covers |
|---|---|
| EU AI Act | Article 10 data governance: evidence for training data origin, consent status, and processing history, structured for conformity assessment reference |
| GDPR | Article 28 DPA available; consent records per asset; right-to-erasure workflows with deletion evidence |
| Scope | Documentation supports data governance review; it is not a certification and does not replace the deployer's statutory obligations |
6. Security and data handling
Encryption: In transit and at rest, with audit logging of administrative actions.
Access control: Granular, role-based access with reviewer workflows designed for compliance teams.
Residency: EEA residency by default; residency and deployment requirements are defined per engagement and documented in the DPA.
7. Frequently asked questions
What is included in an evidence bundle?
The evidence bundle can include provenance records for each delivered asset, consent documentation with timestamps and version references, chain-of-custody records from collection to delivery, QA results, an exception log, and version history. The exact artifacts are fixed during scoping.
How does this support EU AI Act Article 10?
EU AI Act Article 10 requires documented data governance for high-risk systems. YPAI delivers evidence for training data origin, consent status, and processing history, structured so your team can reference it during conformity assessment. YPAI does not perform conformity assessments or certify compliance.
How are GDPR erasure requests evidenced?
Erasure workflows produce deletion evidence: which records were affected, when the deletion was executed, and the attestation delivered to the client. Procedures and timelines are defined in the DPA.
When is the documentation delivered?
Provenance and audit documentation is delivered with the dataset it governs. Documentation scope, formats, and any interim reporting are agreed during scoping and defined in the engagement agreement.
Can we review the documentation before committing?
Yes. Redacted sample provenance documentation and export examples are available during scoping, so legal and compliance stakeholders can review the evidence format before an engagement begins.
We map the evidence your review process requires and provide redacted sample documentation and export examples during scoping.