Advisory · Training · Formal rules

    KROG RULES

    We turn the rules you are bound by — the AI Act, the GDPR, your own contracts — into something you can actually prove you follow.

    Most organisations describe compliance in prose: policies, memos, slide decks. None of it can be checked. We write the same rules as formal, machine-readable logic — every obligation, exception and deadline made explicit — so your documentation holds up in front of an auditor, a regulator or a court. Then we teach your people to do it themselves.

    01 · The fundamental problem

    Compliance you can assert, or compliance you can prove

    Regulation is written as rules. Organisations answer with narrative. The gap between the two is where fines, failed audits and unenforceable contracts live.

    Where it breaks today

    • · Nobody can say which obligation a given control actually satisfies.
    • · Exceptions and derogations are claimed, never reasoned through.
    • · Documentation is written once, then silently goes out of date as the law changes.
    • · Contracts and policies use the same words to mean different things.
    • · No record of which version of the law a decision was made against.

    What we deliver instead

    • · Every rule formalised as a position: who must do what, when, and under which exception.
    • · Documentation generated from facts, with its own derivation attached.
    • · A shared vocabulary so systems, contracts and records agree on meaning.
    • · The exact article, paragraph and point behind every claim.
    • · Your team trained to run it without us.

    02 · Services

    What you can buy

    Advisory engagements and courses across data, technology, AI, security and governance. All areas are open for new engagements.

    Available

    Data Governance

    Advisory and courses on GDPR accountability, certification under GDPR-CARPA, processor arrangements, transfers, and the documentation that has to hold up under audit.
    Available

    AI Governance

    Governance of AI systems: conformity under the AI Act, risk classification, documentation, human oversight, and the evidence trail behind automated decisions.
    Available

    Agentic Governance

    Authorisation for autonomous agents: what an agent may do, on whose behalf, under which mandate, and how each action is bound to a rule that can be checked afterwards.
    Available

    Security

    Security as a governance question — risk analysis, treatment, audit and follow-up — expressed so that controls can be tied to the obligations they satisfy.
    Available

    Standard, machine-readable and interoperable vocabularies and artifacts

    Shared vocabularies, taxonomies and artifacts so that policies, records and contracts mean the same thing across systems and organisations — and can be exchanged without translation loss.
    Available

    Contract Formalization, Analysis and Engineering

    Turning contract text into precise structure: rights, obligations, prohibitions and deadlines made explicit, analysed for gaps and asymmetry, and engineered rather than copy-pasted.

    03 · Courses

    GDPR-CARPA course topics

    GDPR-CARPA is the certification scheme under GDPR Article 42 approved by the CNPD in Luxembourg — 70 criteria across 30 subjects. The teaching follows the criteria set section by section, and can be run in-house for your team.

    Course catalogue on KROG Network

    Section I

    Accountability and governance

    • ·The target of evaluation
    • ·Policies and procedures
    • ·The record of processing activities
    • ·Facilitating data subjects' rights
    • ·The data protection officer
    • ·Data breaches
    • ·Awareness and competencies

    Section II-a

    Lawfulness, transparency and rights

    • ·Identifying and reviewing a legal basis
    • ·The five bases other than consent
    • ·Consent
    • ·Special categories of data
    • ·Objection, restriction, automated decisions
    • ·Transparency
    • ·Access, portability and transfers

    Section II-b–f

    Data quality, storage and security

    • ·Purpose limitation and minimisation
    • ·Accuracy and rectification
    • ·Storage limitation and erasure
    • ·Security: risk analysis and treatment
    • ·Audit and follow-up
    • ·DPIA and prior consultation
    • ·Outsourcing

    Section III

    The processor's obligations

    • ·The contract and documented instructions
    • ·Security
    • ·Audit and follow-up
    • ·Subcontracting
    • ·Transfers and the end of service

    The mechanism

    How certification is examined

    • ·Eligibility and the target of evaluation
    • ·ISAE 3000 and what the auditor tests
    • ·Nonconformities and the decision
    • ·The certificate

    Beyond the criteria

    What CARPA does not reach

    • ·AI Act conformity
    • ·Machine-readable documentation

    04 · The engine

    The KROG rule language

    Behind every engagement sits a formal semantics and rule language for rights, obligations and governance — machine-checkable and translatable across domains. It is what makes the documentation provable rather than merely persuasive.

    Read the specification

    (K ∩ R ∩ O) ⊆ G

    05 · Contact

    Start with one article, one contract, one audit

    For advisory engagements, in-house training or course enrolment, write to hello@signatu.com. Curious who is behind this? About Georg Philip Krog.