Compliance / GDPR

GDPR meets the paste buffer: employees and AI tools

A customer complaint pasted into a chatbot. A candidate CV summarized by a free tool. A support thread translated by something nobody vetted. Each paste is personal data reaching a processor your records have never heard of. This page covers what that means and how to get the facts.

Evidence support, not legal advice: your DPO and counsel own the GDPR analysis. The audit's job is telling them what is actually happening on the network.
The mechanism

How ordinary work becomes an unmapped processing chain

No one intends a GDPR problem. The chain assembles itself from three innocent steps.

Step 1

Personal data enters a prompt

Names, emails, complaints, health mentions, salary figures: the everyday content of support tickets, HR notes and sales threads, pasted for a faster draft.

Step 2

The vendor becomes a de facto processor

Data now sits with a company that appears in no processing records, under no DPA, selected by an individual employee in seconds.

Step 3

The terms decide the damage

Whether that data trains a model, moves jurisdictions or gets retained depends on terms nobody read. Our analysis: 85.5% of AI tools say nothing about training at all.

The multiplier: this is not one rogue employee but a standing pattern across departments. The department anatomy shows where personal data concentrates: HR, support and sales lead.

The questions

Five GDPR questions shadow AI forces

Generic-safe framing of the issues your DPO will recognize immediately. Each pairs with the evidence that grounds it.

Are our processing records complete?

  • Records of processing activities cannot list processors nobody knows about.
  • Evidence: the audit's tool table is the observed list to reconcile records against.

Do we have a basis and a contract for these flows?

  • Shadow tools have no DPA and were never assessed for a legal basis.
  • Evidence: per-tool user counts show which flows are habitual versus one-off, which orders the remediation queue.

Where does the data go?

  • Transfers and jurisdiction questions attach to tools individually.
  • Evidence: the report's data-sovereignty flag per tool surfaces the jurisdiction candidates for counsel's transfer analysis.

Could we honor a deletion request?

  • Erasure obligations are hard to meet for data inside a vendor you do not know you use, and may be impossible for content already used in training.
  • Evidence: training verdicts with check dates separate the recoverable from the possibly-not.

Would we know about a breach?

  • Incident duties assume you can identify affected processors quickly.
  • Evidence: a current inventory is the difference between a 72-hour clock you can work with and one you cannot.

What do we tell data subjects?

  • Transparency duties are awkward when the honest answer is "we are not sure which tools touched your data".
  • Evidence: the sanctioned split shows how much processing runs through vetted versus unvetted channels.
Verdicts as input

Dated training verdicts in processing analysis

The report's most GDPR-useful column is the training verdict with its check date. Here is how privacy teams actually use it.

Verdict on a found toolWhat it means for the analysisTypical disposition
Does not train (dated)A stated commitment exists to cite and monitor.Candidate for sanctioning with a DPA; recheck at renewal.
Trains unless opted outPast prompts may already be training data; the switch state is unknown per account.Enterprise migration with opt-out verified, or block; note the exposure window.
Trains by defaultAssume content entered is used; erasure requests may not reach it.Usually block for personal-data workflows; document the decision.
Not statedNo commitments to rely on either way, the largest group at 85.5%.Treat as unvetted processor; sanction only after direct vendor answers.

The check date is what makes verdicts citable in a DPIA: "vendor terms reviewed as of this date" is an auditable statement. Undated impressions are not.

For the DPO

What the audit hands the privacy office

Three artifacts, each mapped to work the DPO already owns.

The reconciliation list

Observed tools versus recorded processors. Every gap is either a record to update or a flow to stop, and both are progress.

The DPIA trigger list

Tools with heavy use in personal-data departments, sorted by training verdict. The prioritization argument writes itself.

The audit trail

Dated, repeatable reports showing the organization measures this. Supervisory conversations go better with a file than with intentions.

The audit itself is built to be the easy row in your own records: hostnames, identities and timestamps in, upload discarded after the run, report deletable before its 90-day expiry, operated by an EU company in Munich.

Remediation order

From findings to fewer unmapped flows

The privacy-shaped version of sanction, control, block, in the order that reduces exposure fastest.

1. Stop the worst flows

Train-by-default tools in HR, support and sales workflows get blocked or migrated first. Small user counts, outsized data sensitivity.

2. Contract the keepers

Popular tools move to enterprise tiers with DPAs and no-training terms, then onto the sanctioned list. The four gates apply verbatim.

3. Measure the shrinkage

Quarterly re-runs show unmapped flows declining and the sanctioned share rising. That trend line is the story you want on file.

Show the DPO a finished evidence pack

The sample report demonstrates the tool table, verdict columns and per-user attribution on sample data. Ten minutes of reading replaces a quarter of speculation.

Open the sample report
Staff reality

Why policy memos alone never fixed this

The GDPR angle tempts organizations toward stern emails. Three reasons measurement has to come first.

People cannot follow what they cannot evaluate

"Only use compliant tools" assumes staff can read terms that, most of the time, answer nothing. The sanctioned list does the evaluation for them.

The riskiest flows look the most innocent

Translating a customer email feels harmless; it is a cross-border disclosure to an unknown processor. Intuition misranks these; verdicts do not.

Enforcement without visibility is theater

A rule nobody measures trains staff that the rule is decorative. The quarterly audit is what turns the memo into a system.

FAQ

GDPR and AI tool questions

Is pasting personal data into a chatbot a GDPR issue?

It sends personal data to a third party that is likely absent from your processing records and DPAs. Whether and how that violates anything is your counsel's call; that it happened is what the audit establishes.

Are AI vendors processors or controllers?

It depends on the tool and terms, and it is exactly the analysis your DPO runs per vendor. The report's verdicts and provider mapping give that analysis its inputs.

Can data used for training be deleted?

Content absorbed into training is at best hard to retrieve, which is why the train-by-default verdict weighs so heavily and why prevention beats cleanup here.

Does the audit itself process employee data?

It reads hostnames, identities and timestamps from your export, discards the upload after the run, and keeps only the report you control. Most privacy reviews approve that description quickly.

What should we do about the 85.5% silent-terms tools?

Treat silence as unvetted: no personal-data workflows until the vendor answers directly or an enterprise tier settles it. The statistics page covers the finding.

How do we start without boiling the ocean?

One 30-day export, one free preview, one meeting with the DPO. The counts alone reframe the priorities in an afternoon.

Your processing records have a blind spot

The logs already know which unmapped processors your staff reached. One upload gives your DPO the list.

Run the free audit