
For your company
Governance & Compliance
Module · GDPR meets the prompt box
The AI Privacy Operations Check
Your privacy programme was built for databases and forms, not for staff pasting customer emails into a chatbot. AI does not suspend data protection law; it just moves the processing somewhere your controls may not reach. This module checks the five places where GDPR discipline meets AI reality: processor contracts, data minimisation in prompts, subject-request traceability, impact assessments, and retention in the logs.
What the five levels look like
Every dimension in this assessment is scored 1 to 5. This is what the levels mean, dimension by dimension. The graded report diagnoses where your own answers land and what to do about it.
Processors are contracted
- 1No contracts
- 2Terms of service only
- 3Some tools covered
- 4Most tools covered
- 5Every processor covered
At the low end: Personal data flowing to an AI vendor with no processing agreement is an unlawful transfer you signed up for by omission. List the AI tools in use and get the agreements signed before the next customer record goes in. What good looks like: Full processor coverage is the baseline most companies skip. Keep it wired to procurement so a new AI tool cannot go live without its agreement in place first.
Prompts stay minimal
- 1No limits
- 2Guidance ignored
- 3Written rule
- 4Rule plus training
- 5Enforced by tooling
At the low end: With nothing between staff and the prompt box, every task is a chance to over-share personal data by habit. Publish a short rule on what may and may not be pasted, and put it where the work happens. What good looks like: Tooling that strips or blocks excess personal data is the strongest form of minimisation. Review what it catches so the filters keep pace with the tools people actually reach for.
You can answer requests
- 1Cannot trace AI
- 2Manual guesswork
- 3Partial records
- 4Documented for most
- 5Fully traceable
At the low end: If AI processing leaves no trace, every data subject request is one you answer with a guess. Start logging which tools receive personal data and what they return, so the account exists before the request arrives. What good looks like: Full traceability across the AI steps is what makes a subject request routine rather than a fire drill. Test the erasure path end to end; a record you cannot act on is only half the duty.
Risky uses assessed
- 1Never considered
- 2None done
- 3One generic DPIA
- 4Done for some cases
- 5Done and maintained
At the low end: Running high-risk AI on personal data with no impact assessment is a breach of the process the law requires, before any actual harm. Identify your highest-risk use case and assess that one first; the template is a day of work, not a project. What good looks like: Maintained, per-use-case assessments are exactly what the regulator expects to see. Revisit them when a use case changes scope; a DPIA describing last year's system is evidence of drift, not diligence.
Logs do not hoard
- 1Kept forever
- 2No policy
- 3Policy, not applied
- 4Applied to some
- 5Enforced everywhere
At the low end: AI logs kept forever are a breach waiting for the incident that exposes them. Set a retention period tied to why you keep the data, and turn on deletion for the highest-volume logs first. What good looks like: Enforced retention across prompts, outputs and logs keeps your exposure bounded as usage grows. Audit it periodically; a job that silently stops deleting is how a solved problem comes back.