+33 (0)1 87 66 00 65 · Monday to Friday, 9am–6pm Free audit (15 min)
● Business offer — DPO / GDPR support

The DPO's AI agent: register, DPIAs, rights, breaches — the DPO decides

Keeping a register current, preparing a DPIA, handling a rights request, documenting a breach, tracking forty processing contracts: the data protection officer's job is made of groundwork and of clocks that are already running — one month to answer a rights request, seventy-two hours to notify a breach. Your agent keeps that groundwork current and hands over every file complete, sourced and dated. Hosted in France, running locally or on an isolated resource. The DPO decides.

Hosted in France Register and incidents protected GDPR & AI Act: governed deployment The DPO decides

Updated on

Deployed in a few weeks
DPO / GDPR support · hosted in France
Where does our register stand against what is actually running?
78 sheets in the register, 96 processing operations found in service. 18 are not recorded — I rebuilt them from your signed processing contracts, your open application accounts and the internal requests of the last twelve months.
Of the 78 existing sheets: 9 state no retention period and 5 do not name their legal basis, although Article 30 of the GDPR expects both.
The 18 missing sheets are drafted, each with the document it was drawn from and the date it was observed. You review them, you settle them.
⛓ Sourced · processing contracts, application accounts, internal tickets
An access request arrived yesterday. How long do we have?
One month, and the file is already open. The CNIL states that the organisation answers « dans les meilleurs délais et au plus tard dans un délai d'un mois », a period that « peut être porté à trois mois compte tenu de la complexité de la demande ou du nombre de demandes » — Article 12 of the GDPR, the right of access itself falling under Article 15.
What I have already done: checked that the requester is identifiable in your databases, retrieved their data across the four connected systems, set aside the elements concerning third parties, and prepared the extract for review. The due date is shown on the file. The answer goes out under your signature.
✎ Framework · Article 12 GDPR deadline, file ready for review
Local inference · no data outside the EU
Register and incidents hosted in France
Sovereign by constructionLocal inference or hosting in France
GDPR & AI Act: governed deploymentTraceability & human supervision
TurnkeyDesigned, installed and operated for you
The DPO decidesThe agent prepares, it never notifies alone
✦ In brief

A Blue Lemon Agent DPO support agent keeps the record of processing activities up to date (Article 30 of the GDPR), prepares DPIAs (Article 35), handles rights requests within the one-month deadline of Article 12, documents personal data breaches under the 72-hour deadline of Article 33, and tracks the processing contracts of Article 28. Every line carries its source and the date it was observed. Hosted in France, running locally or on an isolated resource, architecture designed to reduce exposure to extraterritorial legislation, location alone not being enough to guarantee immunity: your register, your incidents and your contracts stay with you. The DPO decides.

100 %
hosted in France in the target architecture
0
transfer outside the EU in the target architecture
5
compliance flows covered on this scope
0
notification sent without a human decision

Reference points describing our offer, not results measured at a client. The scale of the gain is confirmed by a pilot on your own scope.

The context

Why the DPO role is decided by upkeep and by deadlines

A register ages on its own: every new tool, every supplier, every campaign adds a processing operation that nobody records. And two clocks run without waiting for anyone to be available — one month to answer a rights request, seventy-two hours to notify a breach.

! The challenge

The DPO keeps a register that must reflect processing operations in motion and answers to enforceable deadlines. The CNIL states that the register is required by Article 30 of the GDPR (cnil.fr — the record of processing activities), that a rights request is answered at the latest within one month, extended to three months depending on complexity or the number of requests — Article 12 of the GDPR (cnil.fr — the right of access), and that a breach is notified as early as possible and within a maximum of 72 hoursArticle 33 of the GDPR (cnil.fr — personal data breaches). The work is mechanical; what is missing is time.

Our answer

The agent takes the groundwork: every week it checks the register against the processing operations actually in service, drafts the missing sheets with the document they were drawn from, prepares the DPIAs of Article 35 of the GDPR, opens each rights request on receipt with its due date displayed, and documents a breach while the incident is still warm. The DPO decides: settling a register sheet, concluding a DPIA and signing a notification are acts that bind the organisation and belong to the person designated under Articles 37 to 39 of the GDPR. Local inference or an isolated resource hosted in France: the register, the incidents and the processing contracts never leave the company.

The decisive point

Register, incidents and contracts: the organisation's most sensitive material

An agent that supports compliance handles the full map of your processing operations and the history of your incidents. Here is how the architecture protects them.

Local inference

The agent can run on a machine inside the company: neither the register nor the breach files leave the network.

Hosting in France

Otherwise, a dedicated, isolated resource hosted in France under French law — your compliance data: processing and access within the European Union targeted by the architecture.

Reduced extraterritorial exposure

Architecture designed to reduce exposure to extraterritorial legislation, location alone not being enough to guarantee immunity: the map of your processing operations depends on a subcontracting chain and remote access documented for the configuration chosen.

An isolated resource per client

No pooling: an environment strictly dedicated to your organisation, its register and its incidents.

Minimisation applied to the agent itself

Role-based access (RBAC), logging, encryption in transit and at rest — the compliance tool applies to itself what it checks elsewhere.

AI Act: governed deployment

A strictly supporting agent; no notification and no register entry validated automatically; traceability and human supervision end to end.

What depends on the architecture chosen These points are not general guarantees: they are settled deployment by deployment, in the quotation.

  • The applicable location is that of the architecture set out in the quotation and verified before commissioning.
  • Local execution is announced only for the configuration explicitly described and accepted in the quotation.
  • The applicable isolation depends on the deployment mode set out in the quotation; no dedicated isolation is presumed.
  • The encryption mechanisms in transit and at rest, their components and key management are those documented for the architecture chosen.
  • Roles and permissions are configured and accepted for the identities and systems actually connected.
  • The events logged, their content, their retention period and who may access them are defined for the deployment chosen.
For the most sensitive processing — health data, incident files, litigation —, SecNumCloud and HDS options are available depending on your requirements. A single architecture is designed to answer both the GDPR and extraterritorial exposure. Our reading of the law applicable to AI agents is set out on AI agents and personal data. Designed for deployment in line with the GDPR and the AI Act, after the processing, roles and context-specific risks have been assessed.
Demonstration

See the agent at work

4 real situations, taken from those that come up most often. Pick one: the exchange unfolds as it would in your organisation.

A scripted demonstration. These exchanges show how the agent behaves — its sources, its refusals, what it leaves to your teams. Nothing is sent from this page, no model is queried here, and the matters named are fictional. That is precisely what we promise your data.
The behaviours shown here — monitoring, automation rules, routing and reminders — are configured with you during deployment, from your tools, your rules and your thresholds.
The architecture points named in these exchanges — location, local execution, isolation, encryption, role-based access, logging — are not a guarantee attached to the demonstration: they are those of the architecture set out in your quotation, and verified before commissioning.

The company in this demonstration

Fictional company

Vireval — a homeware retail chain, 34 stores and an online shop

Sector
Specialist retail: furniture, décor, small appliances
Headcount
610 staff, including a data protection officer at 60% of her time and one lawyer
People served
Consumers in France — 1.2 million active loyalty accounts
Order of magnitude
78 sheets in the register, 41 processors under contract, 240 rights requests received last year
Tools in place
Register kept in a spreadsheet, contract vault, directory of application accounts, ticketing tool, loyalty CRM
Who decides
The data protection officer settles every register sheet, concludes the DPIAs and signs the notifications
Room for improvement
18 processing operations in service are missing from the register, and 31 of the 240 rights requests were closed beyond one month

Vireval appointed its DPO three years ago. The register was built in one go at the time, then revisited twice a year, while the chain opened six stores, an online shop and a loyalty programme. The agent is connected to four systems — contract vault, directory of application accounts, ticketing tool, loyalty CRM — and works continuously; every sheet, every DPIA conclusion and every notification goes through the DPO.

This company, its figures and the exchanges that follow were invented for the demonstration. They illustrate a common situation; they describe no real client.

DPO / GDPR support · hosted in France
Overnight I checked your register against what is actually running in the company: 78 sheets recorded, 96 processing operations found in service.
The 18 gaps, and where I get them from:
· 11 come from signed contracts that never reached the register — including the satisfaction survey tool, signed in March, and the recruitment platform, signed in January.
· 5 come from application accounts opened on services that handle customer or staff data, with no matching sheet.
· 2 come from your own internal tickets: a loyalty extract for a commercial campaign, repeated every quarter for eighteen months, and an attendance export to a shared spreadsheet.
And within the 78 existing sheets: 9 state no retention period, 5 do not name their legal basis. Yet Article 30 of the GDPR expects both on every line — the CNIL publishes the expected content on cnil.fr, page « le registre des activités de traitement ».
What I have already done: the 18 missing sheets are drafted, each with the document it was drawn from and the date it was observed. You review them, you settle them. register-gaps_78-sheets-96-operations.pdf18 unrecorded operations, 9 missing retention periods, 5 unnamed legal bases
⛓ Sourced · contract vault, directory of application accounts, ticketing tool, loyalty CRM
Where exactly do the 18 come from? I do not want to record a processing operation that does not exist.
Each one rests on a dated document you can open, and none rests on an inference.
My method, in this order: I start from the contract vault — a signed processing contract implies a processing operation; then the directory of application accounts — an active account on a third-party service implies data flowing there; then the internal tickets, where recurring extracts show up by their repetition.
What I provide for each one: the name of the service, the reference and date of the document, the requesting department, the categories of people concerned, and the question that remains open when the document does not settle it. Of the 18, 14 are complete and 4 carry an open question — for instance, does the recruitment platform keep unsuccessful applications, and for how long?
What I propose to run: every Monday, I go back through the three sources and bring you the new entries. A contract signed on a Tuesday reaches the register the following Monday, not at the next audit. The attached table gives the 18 lines, with the document and the date in plain sight. unrecorded-processing_18-lines.csv14 complete, 4 with an open question
⛓ Sourced · 18 lines, each tied to its document and its date
And the 9 sheets with no retention period — what do you propose?
Nine retention periods written out, each with the reason that grounds it — and I will tell you which one I find too long.
Three examples, as I propose them:
· Inactive loyalty accounts — 3 years from the last purchase. Reason: that is what your own figures justify, 97% of repeat purchases happen within 26 months. Beyond that, the data no longer serves the purpose that justified it.
· Video surveillance recordings — 30 days. Reason: that is the maximum the CNIL commonly retains for this kind of system, and your 34 stores currently keep 90 days by factory default.
· Unsuccessful applications — 2 years after the last contact, unless the person objects.
The figure that does not flatter me: of those 9 sheets, 2 retention periods cannot be seriously proposed without a business decision I do not have — how long dematerialised receipts are kept depends on your commercial warranty policy, and I found no internal document that sets it. I left them open rather than filling them in, and I have prepared the exact question to put to the commercial department.
The complete sheet for the loyalty programme is attached, in the format you settle: purpose, named legal basis, categories, recipients, retention period, security measures, source and date. register-sheet_loyalty-programme.pdfComplete sheet, ready for the DPO to settle
✎ Framework · Article 30 GDPR — content of the register; retention periods proposed, reasoned and dated
Local inference · no data outside the EU

Your case is not here? That is exactly what a 15-minute conversation is for. Book the free audit

Use cases

The six flows of the DPO role, equipped

Each use corresponds to part of the work the agent prepares. All of them work in support: the DPO decides.

Included in your agent The 6 capabilities essential to this promise are included, at no extra cost.
From 668 € excl. VAT / month

Record of processing activities

One sheet per processing operation: purpose, named legal basis, categories, recipients, retention period (Article 30 of the GDPR).

Unrecorded processing

Rebuilds the processing operations in service that are missing from the register, from contracts, application accounts and internal requests.

Impact assessments (DPIAs)

Description, necessity and proportionality, risks and proposed measures, in the form expected by Article 35 of the GDPR.

Rights requests

Identity, search across every system, an extract ready to review, the one-month deadline displayed (Article 12 of the GDPR).

Personal data breaches

Timeline, scope, risk assessment, draft notification and breach register, under the 72-hour deadline of Article 33.

Processor tracking

Article 28 GDPR contracts, hosting location, sub-processors, review dates and deadlines.

Controls and safeguards These 7 controls are built into the agent: they frame what it does, whatever plan you pick. They are not chosen and are not added to your order.
Human validation, exceptions and escalation Status, safe closure and audit trail Sources, access rights and handling of questions with no answer Work from a versioned corpus with citations and the law as it stood on a given date Preserve confidentiality, compartmentalisation and access logging Manage deadlines, versions, evidence and human validation Flag uncertainties and reserve advice, decision and signature for the lawyer
The gain

Where a DPO's time goes, and where it comes back

By taking on register upkeep, searching the systems and shaping the files, the effort moves towards judgement and decision. The scale of the gain depends on the number of processing operations, processors and requests received.

Keeping and updating the record of processing
Today · done by hand
Sheets proposed, to be settled
Handling a rights request
Today · done by hand
File ready to review
Building the file on a breach
Today · done by hand
Timeline and draft notification
A qualitative, non-contractual comparison: the proportions shown illustrate the shift of work towards review, they represent no measurement. Settling a register sheet, concluding a DPIA and signing a notification remain acts of the DPO and the controller.
How it works

The stages of your AI agent project

1

Audit & scoping

15 minutes to target the use case with the best return.

2

Quote or direct sign-up

A catalogue offer is bought online; a specific need gets a costed quote.

3

Design

We design the agent and its guardrails.

4

Integration & testing

We connect your tools to the agent, which is itself hosted in France.

5

Rollout

Going live and training your team.

6

Operation

Continuous supervision and improvement.

Pricing

A DPO support agent, installed and operated for you

An L3 agent: register, DPIAs, rights requests, breaches and processors, with the connectors and monthly maintenance of that level. Prices excluding VAT — annual subscription, the time it takes for the gains to settle in.

Agility

Setup + controlled subscription

7,320 € excl. VAT setup
then 668 € excl. VAT/month — you invest at installation and pay a reduced subscription. Ideal for keeping the cost under control over time.
  • Installation, configuration and training for your teams
  • Operation, human oversight, updates and support
  • Sovereign hosting in France, a dedicated and isolated resource
Order →
The simplest Serenity

All inclusive, no setup fee

1,078 € excl. VAT /month
all inclusive, immediate start. No upfront investment: a single subscription. Ideal for starting quickly and simply.
  • Setup included (installation, configuration, training)
  • Operation, human oversight, updates and support
  • Sovereign hosting in France, managed end to end
Order →
100% Sovereign

On site, you own it

11,405 € excl. VAT setup
then 888 € excl. VAT/month · + hardware from 2,491 € (one-off purchase, in addition) — a sovereign computer installed on your premises, maintained remotely. Models run locally, your data returned at the end of the contract. 36-month commitment.
  • Hardware installed on your premises (you own it)
  • French / European AI models run locally
  • Secure remote maintenance (Pro support included)
Order →
Not included in the packages: AI consumption (model tokens), re-invoiced at real cost with no margin, and tracked in real time in your client area. Maintenance and supervision subscription for an initial term of 12 months for the Agility package, 24 months for the Serenity package and 36 months for the 100% Sovereign package, renewable; support levels (SLA 72 h / 24 h / 4 h) optional. Bespoke development, additional integrations or exceptional volumes are quoted separately. Support Monday to Friday, 9am to 6pm. Prices exclude VAT.
AI model: none of the AI models offered currently carries a fixed surcharge. When the selected model carries a cost, that cost is shown when you choose it, before you order, and re-invoiced at the cost incurred, with no mark-up; usage is billed at the publisher's price. Publishers' prices are published in US dollars: the amount re-invoiced is the amount in euros actually borne by Blue Lemon Agent on the publisher's invoice, at that invoice's exchange rate, with no commission or mark-up.
Included components and additional components Components included in the base offer: the Blue Lemon Agent software foundation, the AI models listed in the order journey, the standard channels (Microsoft Teams, Slack, WhatsApp Business, email, website chat, calendars, Microsoft 365 / Google Workspace, file storage, market VoIP telephony, professional social-media pages and accounts, Google Business Profile), hosting in France for the package chosen, backups, supervision, updates and support. If adapting the AI agent to your constraints, your needs or your requests requires other paid components — a third-party publisher's software licence, paid API access to one of your applications, hosting of health data, for which French law requires an HDS-certified host (art. L. 1111-8 of the French Public Health Code), SecNumCloud-qualified hosting, a speech synthesis service, particular hardware —, they are offered to you as an option or on quotation and re-invoiced at the cost incurred; nothing is committed without your written agreement. Where the artificial intelligence model you choose entails an additional cost, that cost is shown to you before you order and re-invoiced to you at the cost incurred, with no margin.
What to expect
Go-live 2 to 3 weeks
Agent designed, channels connected, team trained.
Steady state 4 to 7 weeks
After a few weeks of real use, once the agent's behaviour matches what you expect. Indicative estimate, adjusted to the options you keep. It is not a delivery commitment.
Our commitment

Four guarantees that matter to the DPO role

Your register never leavesLocal inference or an isolated resource hosted in France; neither the register nor the incident files are entrusted to a foreign third party.
Data in France, under French lawRegister, DPIAs, rights and breach files: minimisation and location in France, architecture designed to reduce exposure to extraterritorial legislation, location alone not being enough to guarantee immunity.
The DPO decidesThe agent prepares and presents; settling a sheet, concluding a DPIA and signing a notification remain human acts.
Every line carries its sourceContract, application account or ticket: the origin and the date of the observation accompany every element produced, in line with the AI Act's traceability requirements.
Frequently asked questions

Your questions, our answers

Does the agent replace the data protection officer?
No. The DPO role is a designated role, held by a person, with the tasks and independence set out in Articles 37 to 39 of the GDPR. The agent takes on the groundwork — keeping the register, searching the systems, shaping the files — and hands it over ready to be settled. The DPO decides.
Can the register it produces be relied on during an inspection?
The register remains the organisation's own, kept under the controller's responsibility and settled by the DPO. The agent handles its day-to-day upkeep: each line carries the document it was drawn from and the date it was observed, which is precisely what an inspection sets out to check. The register is required by Article 30 of the GDPR.
Does the agent notify a breach to the CNIL itself?
No. It reconstructs the timeline, delimits the scope, assesses the risk to individuals, drafts the notification and feeds the breach register, with the seventy-two-hour deadline of Article 33 of the GDPR displayed. The notification goes out under the organisation's signature; informing the individuals concerned, where the risk is high, falls under Article 34.
How does it keep to the one-month deadline on a rights request?
It opens the file on receipt, checks what is missing to establish the requester's identity, searches for the data in every connected system, sets aside the elements concerning third parties and presents an extract ready to review. The one-month deadline of Article 12 of the GDPR is shown on the file with its due date; the extension to three months, provided for by the same article, is proposed with its justification where the request warrants it.
Does it really prepare a DPIA, or only a form?
It produces the file expected by Article 35 of the GDPR: a systematic description of the processing, an assessment of necessity and proportionality, an analysis of the risks to individuals and the measures proposed to address them. It also states which of the nine criteria published by the CNIL are met, since that is what triggers the obligation. Concluding the DPIA belongs to the controller, with the DPO's advice.
How many systems does the agent connect to?
This use case sits at level L3 of our grid: four connectors are included, together with the matching monthly maintenance. The scope — register, DPIAs, rights requests, breaches, processors — usually calls for about that many. The connections retained are settled during the free audit.
Is our compliance data protected?
Yes. The agent and its data are hosted in France, running locally or on an isolated resource, with the deployment objective of processing and access operated within the European Union and an architecture designed to reduce exposure to extraterritorial legislation, location alone not being enough to guarantee immunity, in compliance with the GDPR. Your registers, incidents and contracts are never used to train a third-party model.
How long does it take to deploy the agent?
A few weeks depending on the number of systems to connect and the state of the existing register, after a free audit that delimits the scope, then a design, integration and testing phase before going live.
Let's talk

Let us estimate the potential on your register and your files

15 minutes to scope your processing operations, your processors and your deadlines — hosted in France, supervised, with no commitment.