Skip to main content

GDPR Article 30 - Record of Processing Activities (Skeleton)

1. Controller Details

  • Name: [Customer Name]
  • Address: [Customer Address]
  • DPO: [DPO Contact Details]

2. Purposes of Processing

  • AI Usage Monitoring: Ensuring safe and compliant usage of generative AI tools.
  • Data Leak Prevention: Identifying and blocking unauthorized transfers of sensitive data (PII, Secrets).

3. Categories of Data Subjects

  • Employees and contractors of [Customer Name] using AI platforms.

4. Categories of Personal Data

  • Identity: Professional email, User ID.
  • AI Metadata: Names of AI services used, timestamps, risk classifications.
  • Hashed Content: SHA-256 fingerprints of prompt content (one-way, non-reversible).

5. Categories of Recipients

  • Noxys Security SAS (as Processor).
  • [List any other internal/external recipients].

6. Transfers to Third Countries

  • Noxys Cloud: 100% EU Residency (Scaleway France). No US transfers.
  • Exception: [List any non-EU AI tools if used].

7. Retention Periods

  • Audit logs: [Default: 2 years, configurable].
  • PII classifications: [Default: 90 days, configurable].

8. Technical and Organizational Measures (TOMs)

  • Encryption at rest and in transit.
  • Pseudonymization via hashing.
  • RBAC and logical isolation.