World Model Readiness
Engraved governance instrument

For your company

Governance & Compliance

Module · GDPR meets the prompt box

The AI Privacy Operations Check

Your privacy programme was built for databases and forms, not for staff pasting customer emails into a chatbot. AI does not suspend data protection law; it just moves the processing somewhere your controls may not reach. This module checks the five places where GDPR discipline meets AI reality: processor contracts, data minimisation in prompts, subject-request traceability, impact assessments, and retention in the logs.

Question 1 of 5 · Processors are contracted

Do you have a data processing agreement with every AI tool that touches personal data?

Every vendor that processes personal data on your behalf needs an Article 28 contract, not just terms of service. Free browser chatbots and plugins count as processors the moment a customer name goes in. Without the contract, you are the one exposed when the regulator asks who authorised it.

Question 2 of 5 · Prompts stay minimal

Is anything stopping staff from pasting more personal data than a task needs into AI tools?

Data minimisation is a legal duty, and the prompt box is where it quietly fails. People paste the whole email thread when a summary needs two lines, the full spreadsheet when one column would do. A rule people know beats a rule that only exists in the policy PDF.

Question 3 of 5 · You can answer requests

When someone asks what you did with their data, can you account for the AI steps?

A subject access or erasure request covers every processing step, including the ones an AI tool performed. If you cannot say what was sent, to which tool, and whether it can be deleted, you cannot answer the request honestly. 'We are not sure what the AI kept' is not a defensible reply.

Question 4 of 5 · Risky uses assessed

Have you run a data protection impact assessment for your riskier AI use cases?

A DPIA is mandatory where processing is likely to be high risk, and AI on personal data at scale usually qualifies. It is not paperwork for its own sake: it forces you to see the risk before deployment, not after a complaint. One generic assessment across everything is a way of doing none.

Question 5 of 5 · Logs do not hoard

Do the personal data sitting in your AI logs and prompt history have a deletion schedule?

Prompts, outputs and tool logs quietly accumulate personal data, and storage limitation applies to them too. Indefinite retention turns a helpful audit trail into a growing breach surface. The question is whether anything actually deletes, or whether the logs just grow.

For the statistics · one click each

Three questions for the public picture

These do not affect your score. They feed the anonymised, aggregated statistics; groups under 8 respondents are never shown.

How many of your AI tools have a signed data processing agreement?

None
Some
Most
All of them
We do not know

Have you completed a data protection impact assessment for any AI use case?

None
Planned
For some use cases
For all high-risk uses
Not sure

How often does personal data end up in prompts to public AI tools?

Never, we are confident
Rarely
Often
Routinely
We cannot tell

Your context

Used to calibrate the report. Company size and sector remain in the anonymized dataset; your email does not.

What the five levels look like

Every dimension in this assessment is scored 1 to 5. This is what the levels mean, dimension by dimension. The graded report diagnoses where your own answers land and what to do about it.

Processors are contracted

  1. 1No contracts
  2. 2Terms of service only
  3. 3Some tools covered
  4. 4Most tools covered
  5. 5Every processor covered

At the low end: Personal data flowing to an AI vendor with no processing agreement is an unlawful transfer you signed up for by omission. List the AI tools in use and get the agreements signed before the next customer record goes in. What good looks like: Full processor coverage is the baseline most companies skip. Keep it wired to procurement so a new AI tool cannot go live without its agreement in place first.

Prompts stay minimal

  1. 1No limits
  2. 2Guidance ignored
  3. 3Written rule
  4. 4Rule plus training
  5. 5Enforced by tooling

At the low end: With nothing between staff and the prompt box, every task is a chance to over-share personal data by habit. Publish a short rule on what may and may not be pasted, and put it where the work happens. What good looks like: Tooling that strips or blocks excess personal data is the strongest form of minimisation. Review what it catches so the filters keep pace with the tools people actually reach for.

You can answer requests

  1. 1Cannot trace AI
  2. 2Manual guesswork
  3. 3Partial records
  4. 4Documented for most
  5. 5Fully traceable

At the low end: If AI processing leaves no trace, every data subject request is one you answer with a guess. Start logging which tools receive personal data and what they return, so the account exists before the request arrives. What good looks like: Full traceability across the AI steps is what makes a subject request routine rather than a fire drill. Test the erasure path end to end; a record you cannot act on is only half the duty.

Risky uses assessed

  1. 1Never considered
  2. 2None done
  3. 3One generic DPIA
  4. 4Done for some cases
  5. 5Done and maintained

At the low end: Running high-risk AI on personal data with no impact assessment is a breach of the process the law requires, before any actual harm. Identify your highest-risk use case and assess that one first; the template is a day of work, not a project. What good looks like: Maintained, per-use-case assessments are exactly what the regulator expects to see. Revisit them when a use case changes scope; a DPIA describing last year's system is evidence of drift, not diligence.

Logs do not hoard

  1. 1Kept forever
  2. 2No policy
  3. 3Policy, not applied
  4. 4Applied to some
  5. 5Enforced everywhere

At the low end: AI logs kept forever are a breach waiting for the incident that exposes them. Set a retention period tied to why you keep the data, and turn on deletion for the highest-volume logs first. What good looks like: Enforced retention across prompts, outputs and logs keeps your exposure bounded as usage grows. Audit it periodically; a job that silently stops deleting is how a solved problem comes back.