GDPR Article 30 requires a record of processing activities. The EU AI Act mandates an AI inventory. If staff are using AI tools you do not know about, both obligations are unmet. A shadow AI audit closes the gap using the logs your network already writes.
Every AI tool that accepts text, files or voice input is a processing activity. If it is not in your ROPA, you have a compliance gap. If the vendor trains on inputs, you may have a data breach. The DPO needs the inventory before any of this can be assessed.
GDPR Article 30 requires every processing activity to be recorded. AI tools that process personal data without appearing in the ROPA are a direct compliance failure. The audit identifies which tools are missing from the register.
Many AI tools are headquartered or hosted outside the EEA. Data sovereignty flags in the report identify which tools involve international transfers. Each one requires an Article 46 transfer mechanism or SCCs.
AI vendors that train on user input by default are repurposing personal data for a new purpose without consent. The report flags which vendors train, which offer opt-out and which enterprise tiers avoid training entirely.
If a data subject exercises their right to erasure and the data has been used to train an AI model, erasure may be technically impossible. The DPO needs to know which tools this applies to before a request arrives.
| Obligation | Article / Section | Shadow AI Impact | Audit Evidence |
|---|---|---|---|
| Record of processing activities | GDPR Art. 30 | AI tools processing personal data not recorded | Complete tool list with processing categories |
| Lawful basis | GDPR Art. 6 | No legal basis assessed for AI tool data processing | Tool list + training flags to trigger basis review |
| Data protection impact assessment | GDPR Art. 35 | High-risk AI processing not assessed | Risk flags per tool identifying DPIA triggers |
| International transfers | GDPR Art. 46 | Data transferred to non-EEA tools without safeguards | Data sovereignty flags per tool with HQ location |
| Data minimisation | GDPR Art. 5(1)(c) | Staff pasting excess personal data into AI tools | Per-user tool access showing scope of exposure |
| AI system inventory | EU AI Act Art. 4/6 | AI systems not classified or registered | Full AI tool inventory with categories and vendors |
| AI literacy | EU AI Act Art. 4 | Staff using AI without adequate training | User count per tool showing adoption without guidance |
| Transparency | GDPR Art. 13/14 | Data subjects not informed of AI processing | Tool list for privacy notice updates |
For the full GDPR analysis, see GDPR and Shadow AI. For EU AI Act inventory requirements, see EU AI Act Compliance.
Run the shadow AI audit on your DNS or proxy logs. Get the complete list of AI tools your organisation accessed, with vendor names, categories and risk flags. This is your starting inventory.
Cross-reference the tool list against your ROPA. Any tool processing personal data that is not recorded is a gap. The training-verdict flags tell you which tools need immediate review for lawful basis.
Add discovered AI tools to the ROPA with the processing details from the report. Flag tools that require a DPIA (high-risk processing, cross-border transfers, training on inputs). Update privacy notices if needed.
Schedule quarterly re-audits to catch new tools. Compare each quarter's inventory against the ROPA. Any new tool not already recorded triggers the assessment workflow. The trend shows whether governance is effective.
GDPR Article 35 requires a DPIA when processing is "likely to result in a high risk." The audit report flags tools that meet common DPIA criteria.
AI tools used for scoring, ranking, filtering or recommending. If the output influences decisions about individuals (hiring, credit, access), a DPIA is likely required. The report identifies which tool categories involve automated processing.
AI tools used by a significant proportion of staff to process personal data. If 200 out of 500 employees use ChatGPT and some paste customer data, the scale triggers DPIA consideration. The per-user breakdown quantifies this.
Generative AI is "new technology" under EDPB guidelines. Combined with cross-border data transfers (data sovereignty flags in the report), this creates a strong DPIA trigger even for lower-volume processing.
Recruiters paste CVs into a generative AI tool to summarise candidates. The tool trains on inputs by default. Personal data (names, addresses, work history) enters a model the organisation does not control. Not in the ROPA. No lawful basis assessed. No DPIA. The audit flags the tool and the 12 users who accessed it.
Customer support records calls and runs them through an AI transcription tool. Call recordings contain personal data: names, account numbers, complaints. The transcription vendor is US-based with no SCCs. The audit flags the tool with a data-sovereignty warning and the 8 support agents who used it.
The marketing team uses an AI tool to generate personalised email content based on customer segments. Customer names and purchase history go into the tool. The vendor's free tier trains on all inputs. The audit identifies the tool and the data flow before the next campaign sends.
Financial analysts upload spreadsheets containing employee compensation data to an AI forecasting tool. Personal data (names, salaries, bonuses) is processed by a third-party AI system with no DPA in place. The audit catches the tool and the 3 analysts who accessed it.
For more scenarios like these, see Shadow AI Examples. For detection methods, see Shadow AI Detection Methods.
The audit gives you the inventory. The next step is policy and enforcement. We provide both.
We have prepared default allow, block and monitor rules across 20,399+ AI tools. Start with optimised defaults based on data protection risk: block tools that train on data by default, allow tools with confirmed enterprise tiers and opt-out. Set rules in minutes, not months.
Run the audit each quarter to verify policy effectiveness. Are blocked tools no longer appearing? Are new tools being adopted without assessment? The before/after comparison is the evidence supervisory authorities expect. The 5-report pack at $299 covers a full annual cycle.
One full audit: every AI tool, per-user breakdown, training verdicts, data sovereignty flags, PDF evidence pack and CSV for ROPA import.
Quarterly audits plus a spare. Track compliance posture over time and demonstrate continuous monitoring to supervisory authorities.
For DPOs managing multiple entities or running monthly compliance checks. Priority processing and monthly audit credits.
Not ready to buy? Run a free preview first. See what the audit finds before committing to a full report.
Article-by-article analysis of GDPR obligations affected by shadow AI usage.
AI inventory and literacy requirements under the EU AI Act.
The broader compliance perspective on shadow AI governance.
How to assess and quantify data leakage risk from shadow AI.
The audit processes network log data: timestamps, source IPs or usernames, and queried domains. The log export is read once and discarded. The resulting report contains tool names, risk flags and user mappings. Review your log export before uploading if you need to confirm what it contains.
Yes. The CSV export contains tool names, categories, vendor details and risk flags in a structured format you can import into any ROPA or GRC platform. The PDF is for evidence filing.
Running the audit on DNS logs (which your organisation already collects) is unlikely to require a DPIA. The processing is limited to domain-name matching against a known AI tool register. Consult your own risk assessment for confirmation.
If a DPA asks "do you know what AI tools your staff use?", the audit report is the answer. It shows you identified the tools, assessed the risk flags and have evidence of ongoing monitoring. That is the accountability story Article 5(2) requires.
The log export you upload can be anonymised before uploading. Replace usernames with pseudonyms and IPs with hashed values. The tool detection works on domains, not user identifiers.
Reports are stored on EU-based infrastructure. The log export is processed in memory and discarded. Only the resulting report is persisted for 90 days in your account.
One log export. One scan. A complete AI processing inventory with training verdicts, data sovereignty flags and DPIA triggers.