By Rafael Luque Ocaña

A completed example file: vendor, decisions and evidence from a dental clinic

Three documents filled in with the fictitious data of the dental demo: the vendor questionnaire, the decision log and the evidence file.

Three working documents, filled in with the data of the public demo account of a dental clinic. All the data is fictitious, and each document says so on its first page.

They follow on from the complete case of the clinic: there, the path from the inventory to a reviewable decision; here, how three of its pieces look once they're written down.

The vendor questionnaire, completed

Download the questionnaire. The questions the clinic puts to the vendor of its diagnostic imaging support system: what it is, what data it processes and where, what documentation it provides — including the Article 13 instructions for use — and what human oversight measures it indicates. And what remains open, which gets written down too.

The decision log, with a negative decision

Download the log. Three decisions with their context, the options ruled out and the rationale. One is negative: not extending the appointments chatbot to a first symptom triage, because emergency healthcare patient triage systems are in Annex III, point 5(d), and the clinic does not currently have the oversight that would require.

No rule asks for a log with this name. It's what makes it possible to explain later why a system does not do something it could.

The evidence file

Download the evidence file. Six pieces of evidence for the same system: the FRIA — carried out as good practice, because Article 27 does not bind a private clinic —, the DPIA, the Article 4 training records, the logs that Article 26(6) asks deployers of high-risk systems to keep, the Article 28 GDPR processing agreement, and the vendor's instructions for use.

Article 26 applies from 2 December 2027 for Annex III high-risk systems and from 2 August 2028 for Annex I systems; it does not reach Annex I, Section B products.

Each PDF in the file carries its integrity fingerprint: a SHA-256 digest that changes if a single byte changes. It shows that the document has not changed since it was generated; it says nothing about who reviewed it.

What they are not

They're not templates to copy as they stand: they're examples of how a file looks when it's filled in carefully. And they don't replace the classification of each system, which is the deployer's.

This article is for informational purposes only and does not constitute legal advice.

Frequently asked questions

Is the data in the three documents real?

No. It comes from the public demo account of a fictitious dental clinic, with invented systems, vendors, dates and fingerprints, and each document says so on its first page.

What is the integrity fingerprint of a PDF?

A SHA-256 digest of the file, which changes if a single byte changes. It shows that the document has not changed since it was generated; it says nothing about who reviewed it.

Does a private clinic have to carry out a FRIA?

Not under Article 27, which binds deployers that are bodies governed by public law or private entities providing public services, and deployers of systems referred to in points 5(b) and (c) of Annex III, always for Article 6(2) systems. In the example the clinic carried one out as good practice, and the evidence file says so.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Controller: ALETHEXIS, S.L. (NIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Retention: until you unsubscribe or after 24 months of inactivity. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es) or with the supervisory authority of your Member State (Article 77 GDPR). More information in the privacy policy.