GDPR Article 30 - Record of Processing Activities (Skeleton)
1. Controller Details
- Name: [Customer Name]
- Address: [Customer Address]
- DPO: [DPO Contact Details]
2. Purposes of Processing
- AI Usage Monitoring: Ensuring safe and compliant usage of generative AI tools.
- Data Leak Prevention: Identifying and blocking unauthorized transfers of sensitive data (PII, Secrets).
3. Categories of Data Subjects
- Employees and contractors of [Customer Name] using AI platforms.
4. Categories of Personal Data
- Identity: Professional email, User ID.
- AI Metadata: Names of AI services used, timestamps, risk classifications.
- Hashed Content: SHA-256 fingerprints of prompt content (one-way, non-reversible).
5. Categories of Recipients
- Noxys Security SAS (as Processor).
- [List any other internal/external recipients].
6. Transfers to Third Countries
- Noxys Cloud: 100% EU Residency (Scaleway France). No US transfers.
- Exception: [List any non-EU AI tools if used].
7. Retention Periods
- Audit logs: [Default: 2 years, configurable].
- PII classifications: [Default: 90 days, configurable].
8. Technical and Organizational Measures (TOMs)
- Encryption at rest and in transit.
- Pseudonymization via hashing.
- RBAC and logical isolation.