A customer complaint pasted into a chatbot. A candidate CV summarized by a free tool. A support thread translated by something nobody vetted. Each paste is personal data reaching a processor your records have never heard of. This page covers what that means and how to get the facts.
No one intends a GDPR problem. The chain assembles itself from three innocent steps.
Names, emails, complaints, health mentions, salary figures: the everyday content of support tickets, HR notes and sales threads, pasted for a faster draft.
Data now sits with a company that appears in no processing records, under no DPA, selected by an individual employee in seconds.
Whether that data trains a model, moves jurisdictions or gets retained depends on terms nobody read. Our analysis: 85.5% of AI tools say nothing about training at all.
The multiplier: this is not one rogue employee but a standing pattern across departments. The department anatomy shows where personal data concentrates: HR, support and sales lead.
Generic-safe framing of the issues your DPO will recognize immediately. Each pairs with the evidence that grounds it.
The report's most GDPR-useful column is the training verdict with its check date. Here is how privacy teams actually use it.
| Verdict on a found tool | What it means for the analysis | Typical disposition |
|---|---|---|
| Does not train (dated) | A stated commitment exists to cite and monitor. | Candidate for sanctioning with a DPA; recheck at renewal. |
| Trains unless opted out | Past prompts may already be training data; the switch state is unknown per account. | Enterprise migration with opt-out verified, or block; note the exposure window. |
| Trains by default | Assume content entered is used; erasure requests may not reach it. | Usually block for personal-data workflows; document the decision. |
| Not stated | No commitments to rely on either way, the largest group at 85.5%. | Treat as unvetted processor; sanction only after direct vendor answers. |
The check date is what makes verdicts citable in a DPIA: "vendor terms reviewed as of this date" is an auditable statement. Undated impressions are not.
Three artifacts, each mapped to work the DPO already owns.
Observed tools versus recorded processors. Every gap is either a record to update or a flow to stop, and both are progress.
Tools with heavy use in personal-data departments, sorted by training verdict. The prioritization argument writes itself.
Dated, repeatable reports showing the organization measures this. Supervisory conversations go better with a file than with intentions.
The audit itself is built to be the easy row in your own records: hostnames, identities and timestamps in, upload discarded after the run, report deletable before its 90-day expiry, operated by an EU company in Munich.
The privacy-shaped version of sanction, control, block, in the order that reduces exposure fastest.
Train-by-default tools in HR, support and sales workflows get blocked or migrated first. Small user counts, outsized data sensitivity.
Popular tools move to enterprise tiers with DPAs and no-training terms, then onto the sanctioned list. The four gates apply verbatim.
Quarterly re-runs show unmapped flows declining and the sanctioned share rising. That trend line is the story you want on file.
The sample report demonstrates the tool table, verdict columns and per-user attribution on sample data. Ten minutes of reading replaces a quarter of speculation.
The GDPR angle tempts organizations toward stern emails. Three reasons measurement has to come first.
"Only use compliant tools" assumes staff can read terms that, most of the time, answer nothing. The sanctioned list does the evaluation for them.
Translating a customer email feels harmless; it is a cross-border disclosure to an unknown processor. Intuition misranks these; verdicts do not.
A rule nobody measures trains staff that the rule is decorative. The quarterly audit is what turns the memo into a system.
It sends personal data to a third party that is likely absent from your processing records and DPAs. Whether and how that violates anything is your counsel's call; that it happened is what the audit establishes.
It depends on the tool and terms, and it is exactly the analysis your DPO runs per vendor. The report's verdicts and provider mapping give that analysis its inputs.
Content absorbed into training is at best hard to retrieve, which is why the train-by-default verdict weighs so heavily and why prevention beats cleanup here.
It reads hostnames, identities and timestamps from your export, discards the upload after the run, and keeps only the report you control. Most privacy reviews approve that description quickly.
Treat silence as unvetted: no personal-data workflows until the vendor answers directly or an enterprise tier settles it. The statistics page covers the finding.
One 30-day export, one free preview, one meeting with the DPO. The counts alone reframe the priorities in an afternoon.
The logs already know which unmapped processors your staff reached. One upload gives your DPO the list.
Run the free audit