Data Protection

Shadow AI Audit for Data Protection Officers

GDPR Article 30 requires a record of processing activities. The EU AI Act mandates an AI inventory. If staff are using AI tools you do not know about, both obligations are unmet. A shadow AI audit closes the gap using the logs your network already writes.

20,399+AI tools tracked
Art. 30ROPA evidence
Art. 35DPIA triggers flagged
EU AI ActInventory compliance
The DPO Problem

You cannot protect data you do not know is leaving

Every AI tool that accepts text, files or voice input is a processing activity. If it is not in your ROPA, you have a compliance gap. If the vendor trains on inputs, you may have a data breach. The DPO needs the inventory before any of this can be assessed.

ROPA gaps

GDPR Article 30 requires every processing activity to be recorded. AI tools that process personal data without appearing in the ROPA are a direct compliance failure. The audit identifies which tools are missing from the register.

Transfer risks

Many AI tools are headquartered or hosted outside the EEA. Data sovereignty flags in the report identify which tools involve international transfers. Each one requires an Article 46 transfer mechanism or SCCs.

Training exposure

AI vendors that train on user input by default are repurposing personal data for a new purpose without consent. The report flags which vendors train, which offer opt-out and which enterprise tiers avoid training entirely.

If a data subject exercises their right to erasure and the data has been used to train an AI model, erasure may be technically impossible. The DPO needs to know which tools this applies to before a request arrives.

Regulatory Mapping

How shadow AI findings map to data protection obligations

ObligationArticle / SectionShadow AI ImpactAudit Evidence
Record of processing activitiesGDPR Art. 30AI tools processing personal data not recordedComplete tool list with processing categories
Lawful basisGDPR Art. 6No legal basis assessed for AI tool data processingTool list + training flags to trigger basis review
Data protection impact assessmentGDPR Art. 35High-risk AI processing not assessedRisk flags per tool identifying DPIA triggers
International transfersGDPR Art. 46Data transferred to non-EEA tools without safeguardsData sovereignty flags per tool with HQ location
Data minimisationGDPR Art. 5(1)(c)Staff pasting excess personal data into AI toolsPer-user tool access showing scope of exposure
AI system inventoryEU AI Act Art. 4/6AI systems not classified or registeredFull AI tool inventory with categories and vendors
AI literacyEU AI Act Art. 4Staff using AI without adequate trainingUser count per tool showing adoption without guidance
TransparencyGDPR Art. 13/14Data subjects not informed of AI processingTool list for privacy notice updates

For the full GDPR analysis, see GDPR and Shadow AI. For EU AI Act inventory requirements, see EU AI Act Compliance.

DPO Action Plan

From audit to ROPA update in four steps

Discover

Run the shadow AI audit on your DNS or proxy logs. Get the complete list of AI tools your organisation accessed, with vendor names, categories and risk flags. This is your starting inventory.

Assess

Cross-reference the tool list against your ROPA. Any tool processing personal data that is not recorded is a gap. The training-verdict flags tell you which tools need immediate review for lawful basis.

Update registers

Add discovered AI tools to the ROPA with the processing details from the report. Flag tools that require a DPIA (high-risk processing, cross-border transfers, training on inputs). Update privacy notices if needed.

Sustain

Schedule quarterly re-audits to catch new tools. Compare each quarter's inventory against the ROPA. Any new tool not already recorded triggers the assessment workflow. The trend shows whether governance is effective.

DPIA Triggers

Which shadow AI tools require a data protection impact assessment

GDPR Article 35 requires a DPIA when processing is "likely to result in a high risk." The audit report flags tools that meet common DPIA criteria.

Automated decision-making

AI tools used for scoring, ranking, filtering or recommending. If the output influences decisions about individuals (hiring, credit, access), a DPIA is likely required. The report identifies which tool categories involve automated processing.

Large-scale processing

AI tools used by a significant proportion of staff to process personal data. If 200 out of 500 employees use ChatGPT and some paste customer data, the scale triggers DPIA consideration. The per-user breakdown quantifies this.

Cross-border + new technology

Generative AI is "new technology" under EDPB guidelines. Combined with cross-border data transfers (data sovereignty flags in the report), this creates a strong DPIA trigger even for lower-volume processing.

Practical Scenarios

What DPOs find in practice

HR uses an AI screening tool

Recruiters paste CVs into a generative AI tool to summarise candidates. The tool trains on inputs by default. Personal data (names, addresses, work history) enters a model the organisation does not control. Not in the ROPA. No lawful basis assessed. No DPIA. The audit flags the tool and the 12 users who accessed it.

Support team uses an AI transcriber

Customer support records calls and runs them through an AI transcription tool. Call recordings contain personal data: names, account numbers, complaints. The transcription vendor is US-based with no SCCs. The audit flags the tool with a data-sovereignty warning and the 8 support agents who used it.

Marketing uses AI for personalisation

The marketing team uses an AI tool to generate personalised email content based on customer segments. Customer names and purchase history go into the tool. The vendor's free tier trains on all inputs. The audit identifies the tool and the data flow before the next campaign sends.

Finance uploads spreadsheets

Financial analysts upload spreadsheets containing employee compensation data to an AI forecasting tool. Personal data (names, salaries, bonuses) is processed by a third-party AI system with no DPA in place. The audit catches the tool and the 3 analysts who accessed it.

For more scenarios like these, see Shadow AI Examples. For detection methods, see Shadow AI Detection Methods.

Enforcement

From discovery to policy enforcement

The audit gives you the inventory. The next step is policy and enforcement. We provide both.

Default policy rules

We have prepared default allow, block and monitor rules across 20,399+ AI tools. Start with optimised defaults based on data protection risk: block tools that train on data by default, allow tools with confirmed enterprise tiers and opt-out. Set rules in minutes, not months.

Quarterly compliance check

Run the audit each quarter to verify policy effectiveness. Are blocked tools no longer appearing? Are new tools being adopted without assessment? The before/after comparison is the evidence supervisory authorities expect. The 5-report pack at $299 covers a full annual cycle.

Pricing

Data protection evidence from $99

Single report - $99

One full audit: every AI tool, per-user breakdown, training verdicts, data sovereignty flags, PDF evidence pack and CSV for ROPA import.

Buy single report →

5-pack - $299

Quarterly audits plus a spare. Track compliance posture over time and demonstrate continuous monitoring to supervisory authorities.

Buy 5-pack →

Monthly - from $99/mo

For DPOs managing multiple entities or running monthly compliance checks. Priority processing and monthly audit credits.

See plans →

Not ready to buy? Run a free preview first. See what the audit finds before committing to a full report.

Related

Resources for data protection officers

GDPR and shadow AI

Article-by-article analysis of GDPR obligations affected by shadow AI usage.

EU AI Act compliance

AI inventory and literacy requirements under the EU AI Act.

For compliance officers

The broader compliance perspective on shadow AI governance.

AI data leakage assessment

How to assess and quantify data leakage risk from shadow AI.

FAQ

Questions from DPOs

Does the audit itself process personal data?

The audit processes network log data: timestamps, source IPs or usernames, and queried domains. The log export is read once and discarded. The resulting report contains tool names, risk flags and user mappings. Review your log export before uploading if you need to confirm what it contains.

Can I import the results into our ROPA tool?

Yes. The CSV export contains tool names, categories, vendor details and risk flags in a structured format you can import into any ROPA or GRC platform. The PDF is for evidence filing.

Do I need a DPIA before running the audit?

Running the audit on DNS logs (which your organisation already collects) is unlikely to require a DPIA. The processing is limited to domain-name matching against a known AI tool register. Consult your own risk assessment for confirmation.

How does this help with a supervisory authority inquiry?

If a DPA asks "do you know what AI tools your staff use?", the audit report is the answer. It shows you identified the tools, assessed the risk flags and have evidence of ongoing monitoring. That is the accountability story Article 5(2) requires.

Can I anonymise the user data?

The log export you upload can be anonymised before uploading. Replace usernames with pseudonyms and IPs with hashed values. The tool detection works on domains, not user identifiers.

Is data stored in the EEA?

Reports are stored on EU-based infrastructure. The log export is processed in memory and discarded. Only the resulting report is persisted for 90 days in your account.

Close the ROPA gap before the supervisory authority asks

One log export. One scan. A complete AI processing inventory with training verdicts, data sovereignty flags and DPIA triggers.