Challenge
Our data is not trusted
Origin and ownership are the same foundation here. Anyone who has that in order can answer most of the questions above.
Challenge
New frameworks around data and AI keep arriving, and they touch systems that have been running for years. The question is rarely whether you comply, but whether you can show it.
See the solution →
The situation
Most organisations already do a lot right. Thought has gone into access, into retention periods, into who may see which data. What is missing is the record: the moment someone asks how a decision came about, which data went into it and who signed off, the searching begins.
This sharpens as more becomes automated. A person, too, cannot always recount afterwards which information they used, but with a system it is reconstructable, provided the system was designed for it. Without recorded data and model versions only approximation remains, and that rarely holds up in an audit.
Because it looks like a legal topic for a long time. It gets assigned to the lawyer or the compliance officer, while the answers sit in the systems and therefore with the people who build them. Those two groups usually only meet when a deadline or an audit comes into view.
The second reason is that it produces nothing you can show. There is no new functionality, only the assurance that something will not go wrong later, and that loses against almost any other project, until the moment it does go wrong.
Twentynext does not give legal advice and does not determine which frameworks apply to your organisation. That belongs with your legal or compliance function. What we do is the technical side: making sure the questions they ask can actually be answered from your systems.
How this plays out in government and non-profit is on the sector page.
What helps
Which requirements apply exactly differs per sector, per type of data and per role a system plays: your legal function determines that, not us. The four questions below are not a summary of the rules but a first technical inventory. If the answer to all four is “we don’t know”, you know where to start.
Do you know which data sits where?
Not broadly, but specifically: which personal data sits in which system, how did it get there and how long does it stay. Without that overview no further question can be answered.
Can you reconstruct a decision?
If a system produced an outcome last quarter, can you show which data and which version of the model it rested on?
Is someone accountable?
Per system, by name. Shared responsibility between IT and the business often means in practice that nobody has the overview at the moment it is needed.
Where does a human intervene?
For which automated outcomes does a person review, and does that person have the knowledge and the authority to overrule it? Reviewing without a mandate does not count. It is also rarely written down anywhere.
Further reading
Challenge
Origin and ownership are the same foundation here. Anyone who has that in order can answer most of the questions above.
Solution
Where definitions, lineage and ownership are recorded: the layer every question about accountability falls back on.
Service
Working out what needs to happen, in what order, including which of the four questions above is most urgent for you.
Work with us
The people who build it also run it afterwards. Eindhoven, since 2014.

Martijn van Grieken
Director Data & AI
We use Google Tag Manager to measure visits and Leadinfo to recognise which company is visiting. Neither loads unless you agree. If you choose essential only, the site works as normal and we measure nothing. If you arrived via an advertisement in ChatGPT, we also use the OpenAI measurement pixel to attribute conversions to that advertisement. Cookie statement · Privacy statement