The DPO's AI agent: register, DPIAs, rights, breaches — the DPO decides
Keeping a register current, preparing a DPIA, handling a rights request, documenting a breach, tracking forty processing contracts: the data protection officer's job is made of groundwork and of clocks that are already running — one month to answer a rights request, seventy-two hours to notify a breach. Your agent keeps that groundwork current and hands over every file complete, sourced and dated. Hosted in France, running locally or on an isolated resource. The DPO decides.
Updated on
Of the 78 existing sheets: 9 state no retention period and 5 do not name their legal basis, although Article 30 of the GDPR expects both.
The 18 missing sheets are drafted, each with the document it was drawn from and the date it was observed. You review them, you settle them.
⛓ Sourced · processing contracts, application accounts, internal tickets
What I have already done: checked that the requester is identifiable in your databases, retrieved their data across the four connected systems, set aside the elements concerning third parties, and prepared the extract for review. The due date is shown on the file. The answer goes out under your signature.
✎ Framework · Article 12 GDPR deadline, file ready for review
A Blue Lemon Agent DPO support agent keeps the record of processing activities up to date (Article 30 of the GDPR), prepares DPIAs (Article 35), handles rights requests within the one-month deadline of Article 12, documents personal data breaches under the 72-hour deadline of Article 33, and tracks the processing contracts of Article 28. Every line carries its source and the date it was observed. Hosted in France, running locally or on an isolated resource, architecture designed to reduce exposure to extraterritorial legislation, location alone not being enough to guarantee immunity: your register, your incidents and your contracts stay with you. The DPO decides.
Reference points describing our offer, not results measured at a client. The scale of the gain is confirmed by a pilot on your own scope.
Why the DPO role is decided by upkeep and by deadlines
A register ages on its own: every new tool, every supplier, every campaign adds a processing operation that nobody records. And two clocks run without waiting for anyone to be available — one month to answer a rights request, seventy-two hours to notify a breach.
! The challenge
The DPO keeps a register that must reflect processing operations in motion and answers to enforceable deadlines. The CNIL states that the register is required by Article 30 of the GDPR (cnil.fr — the record of processing activities), that a rights request is answered at the latest within one month, extended to three months depending on complexity or the number of requests — Article 12 of the GDPR (cnil.fr — the right of access), and that a breach is notified as early as possible and within a maximum of 72 hours — Article 33 of the GDPR (cnil.fr — personal data breaches). The work is mechanical; what is missing is time.
✓ Our answer
The agent takes the groundwork: every week it checks the register against the processing operations actually in service, drafts the missing sheets with the document they were drawn from, prepares the DPIAs of Article 35 of the GDPR, opens each rights request on receipt with its due date displayed, and documents a breach while the incident is still warm. The DPO decides: settling a register sheet, concluding a DPIA and signing a notification are acts that bind the organisation and belong to the person designated under Articles 37 to 39 of the GDPR. Local inference or an isolated resource hosted in France: the register, the incidents and the processing contracts never leave the company.
Register, incidents and contracts: the organisation's most sensitive material
An agent that supports compliance handles the full map of your processing operations and the history of your incidents. Here is how the architecture protects them.
Local inference
The agent can run on a machine inside the company: neither the register nor the breach files leave the network.
Hosting in France
Otherwise, a dedicated, isolated resource hosted in France under French law — your compliance data: processing and access within the European Union targeted by the architecture.
Reduced extraterritorial exposure
Architecture designed to reduce exposure to extraterritorial legislation, location alone not being enough to guarantee immunity: the map of your processing operations depends on a subcontracting chain and remote access documented for the configuration chosen.
An isolated resource per client
No pooling: an environment strictly dedicated to your organisation, its register and its incidents.
Minimisation applied to the agent itself
Role-based access (RBAC), logging, encryption in transit and at rest — the compliance tool applies to itself what it checks elsewhere.
AI Act: governed deployment
A strictly supporting agent; no notification and no register entry validated automatically; traceability and human supervision end to end.
What depends on the architecture chosen These points are not general guarantees: they are settled deployment by deployment, in the quotation.
- The applicable location is that of the architecture set out in the quotation and verified before commissioning.
- Local execution is announced only for the configuration explicitly described and accepted in the quotation.
- The applicable isolation depends on the deployment mode set out in the quotation; no dedicated isolation is presumed.
- The encryption mechanisms in transit and at rest, their components and key management are those documented for the architecture chosen.
- Roles and permissions are configured and accepted for the identities and systems actually connected.
- The events logged, their content, their retention period and who may access them are defined for the deployment chosen.
See the agent at work
4 real situations, taken from those that come up most often. Pick one: the exchange unfolds as it would in your organisation.
A scripted demonstration. These exchanges show how the agent behaves — its sources, its refusals, what it leaves to your teams. Nothing is sent from this page, no model is queried here, and the matters named are fictional. That is precisely what we promise your data.
The behaviours shown here — monitoring, automation rules, routing and reminders — are configured with you during deployment, from your tools, your rules and your thresholds.
The architecture points named in these exchanges — location, local execution, isolation, encryption, role-based access, logging — are not a guarantee attached to the demonstration: they are those of the architecture set out in your quotation, and verified before commissioning.
The company in this demonstration
Fictional companyVireval — a homeware retail chain, 34 stores and an online shop
- Sector
- Specialist retail: furniture, décor, small appliances
- Headcount
- 610 staff, including a data protection officer at 60% of her time and one lawyer
- People served
- Consumers in France — 1.2 million active loyalty accounts
- Order of magnitude
- 78 sheets in the register, 41 processors under contract, 240 rights requests received last year
- Tools in place
- Register kept in a spreadsheet, contract vault, directory of application accounts, ticketing tool, loyalty CRM
- Who decides
- The data protection officer settles every register sheet, concludes the DPIAs and signs the notifications
- Room for improvement
- 18 processing operations in service are missing from the register, and 31 of the 240 rights requests were closed beyond one month
Vireval appointed its DPO three years ago. The register was built in one go at the time, then revisited twice a year, while the chain opened six stores, an online shop and a loyalty programme. The agent is connected to four systems — contract vault, directory of application accounts, ticketing tool, loyalty CRM — and works continuously; every sheet, every DPIA conclusion and every notification goes through the DPO.
This company, its figures and the exchanges that follow were invented for the demonstration. They illustrate a common situation; they describe no real client.
The 18 gaps, and where I get them from:
· 11 come from signed contracts that never reached the register — including the satisfaction survey tool, signed in March, and the recruitment platform, signed in January.
· 5 come from application accounts opened on services that handle customer or staff data, with no matching sheet.
· 2 come from your own internal tickets: a loyalty extract for a commercial campaign, repeated every quarter for eighteen months, and an attendance export to a shared spreadsheet.
And within the 78 existing sheets: 9 state no retention period, 5 do not name their legal basis. Yet Article 30 of the GDPR expects both on every line — the CNIL publishes the expected content on cnil.fr, page « le registre des activités de traitement ».
What I have already done: the 18 missing sheets are drafted, each with the document it was drawn from and the date it was observed. You review them, you settle them. register-gaps_78-sheets-96-operations.pdf18 unrecorded operations, 9 missing retention periods, 5 unnamed legal bases
⛓ Sourced · contract vault, directory of application accounts, ticketing tool, loyalty CRM
My method, in this order: I start from the contract vault — a signed processing contract implies a processing operation; then the directory of application accounts — an active account on a third-party service implies data flowing there; then the internal tickets, where recurring extracts show up by their repetition.
What I provide for each one: the name of the service, the reference and date of the document, the requesting department, the categories of people concerned, and the question that remains open when the document does not settle it. Of the 18, 14 are complete and 4 carry an open question — for instance, does the recruitment platform keep unsuccessful applications, and for how long?
What I propose to run: every Monday, I go back through the three sources and bring you the new entries. A contract signed on a Tuesday reaches the register the following Monday, not at the next audit. The attached table gives the 18 lines, with the document and the date in plain sight. unrecorded-processing_18-lines.csv14 complete, 4 with an open question
⛓ Sourced · 18 lines, each tied to its document and its date
Three examples, as I propose them:
· Inactive loyalty accounts — 3 years from the last purchase. Reason: that is what your own figures justify, 97% of repeat purchases happen within 26 months. Beyond that, the data no longer serves the purpose that justified it.
· Video surveillance recordings — 30 days. Reason: that is the maximum the CNIL commonly retains for this kind of system, and your 34 stores currently keep 90 days by factory default.
· Unsuccessful applications — 2 years after the last contact, unless the person objects.
The figure that does not flatter me: of those 9 sheets, 2 retention periods cannot be seriously proposed without a business decision I do not have — how long dematerialised receipts are kept depends on your commercial warranty policy, and I found no internal document that sets it. I left them open rather than filling them in, and I have prepared the exact question to put to the commercial department.
The complete sheet for the loyalty programme is attached, in the format you settle: purpose, named legal basis, categories, recipients, retention period, security measures, source and date. register-sheet_loyalty-programme.pdfComplete sheet, ready for the DPO to settle
✎ Framework · Article 30 GDPR — content of the register; retention periods proposed, reasoned and dated
Why it is due: Article 35 of the GDPR requires a DPIA where processing is likely to result in a high risk to the rights and freedoms of individuals. The CNIL holds that a DPIA is required in particular where at least two of its nine criteria are met (cnil.fr, « ce qu'il faut savoir sur l'analyse d'impact »). I count three here: systematic monitoring, large-scale collection, and an innovative technology applied to people who do not expect it.
What I have written: the systematic description of the processing as the supplier documents it, the assessment of necessity and proportionality against the stated purpose — measuring footfall by time slot —, the risk analysis, and seven measures to address them.
What the conclusion leaves you: a DPIA authorises nothing by itself. You conclude, the controller decides whether to install — and the written record protects you either way. dpia_customer-counting-34-stores.pdf3 of 9 criteria met · 7 measures proposed
✎ Framework · Article 35 GDPR; nine criteria published by the CNIL, three met
What I found in the 3 contractual documents: the technical notice describes detection on an image, with a silhouette template computed then erased, and an image held 1.4 seconds in memory. No image is written to disk. But the same notice mentions a « store journey » mode, disabled by default, that re-identifies the same silhouette from one camera to the next during the visit — at that point you are no longer counting, you are following.
The consequence, quantified: as long as the « journey » mode stays disabled, 2 of the 7 measures I proposed become moot and the residual risk falls from « high » to « moderate » on my scale. If it is enabled, the DPIA has to be redone and informing people can no longer fit on a pictogram at the entrance.
My proposal: have the supplier write into the amendment that the « journey » mode can only be enabled on your written instruction, and that its disabling is logged. I have drafted the clause; it runs to four lines, it sits on the last page of the file sent with my previous message. You approve it, legal takes it to signature.
⛓ Sourced · supplier technical notice and terms, 3 documents, read on the day of the request
Three ways to obtain hourly footfall, and what they cost in data:
· Entrance counters (beam or depth sensor, no image): they count crossings, not people. No personal data, therefore no DPIA due, and a register sheet that fits in ten lines.
· Till receipts mapped to the time slot: data you already hold, less precise on visitors who buy nothing — and your figures show 2.3 visitors per receipt, which is enough to plan rotas.
· Camera counting: the finest precision, and the file I have just written.
What I recommend, and why: image-free sensors across the 34 stores. Your stated need is hourly footfall to set rotas — all three serve it, only one opens no risk to address. If management wants the precision of video counting, the file is ready and the amendment clause is drafted: nothing is lost.
The decision is yours, and it can be taken now on compared facts, rather than in six months on a hunch.
✎ Framework · comparison at constant purpose — the least intrusive option that meets the need
The access request — received yesterday at 16:12, due on 18 September. The CNIL states that the organisation answers « dans les meilleurs délais et au plus tard dans un délai d'un mois », a period that « peut être porté à trois mois compte tenu de la complexité de la demande ou du nombre de demandes »: that is Article 12 of the GDPR, the right of access itself falling under Article 15 (cnil.fr, « le droit d'accès »).
What I have already done: found the person across all 4 connected systems, gathered 212 items — personnel file, payslips, internal support tickets, a loyalty account opened in a personal capacity —, set aside 38 items that concern third parties (exchanges naming other staff, appraisals of colleagues) and prepared the extract for review.
What I am flagging: her loyalty account belongs to a different processing operation from her personnel file. The request refers to « my data » without distinguishing — I suggest answering on both, rather than making someone who has already written once write a second time.
The file is attached, ready to review. The answer goes out under your signature. access-request_prepared-file.pdf212 items, 38 set aside · due date displayed
⛓ Sourced · 4 connected systems, 212 items found, 38 set aside (third-party data)
The timeline I have reconstructed, from their email, the logs they sent and your own exports: a production backup copied to the test environment on 3 August; the environment exposed without authentication from 3 to 18 August; 4,100 email addresses, 4,100 names and 1,260 phone numbers of customers who answered a survey; no payment data, no special category data.
The deadline: the CNIL writes that the controller « doit notifier cette violation à la CNIL, au plus tôt et dans un délai maximal de 72h » — Article 33 of the GDPR (cnil.fr, « les violations de données personnelles »). The countdown starts when you became aware of the breach, not when it happened: you are at H+3.
What I have prepared: the full draft notification, the risk assessment file, and the entry in the breach register — which Article 33 requires you to keep even for breaches that are not notified.
What is left for you: review, decide on informing the individuals, sign. breach_satisfaction-surveys_file.pdf4,100 people · notification and register prepared
⛓ Sourced · supplier email and logs, Vireval exports, timeline from 3 to 18 August
What the text says: Article 34 of the GDPR requires the breach to be communicated to the individuals concerned where it is likely to result in a high risk to their rights and freedoms.
What the facts weigh here:
· Aggravating — the data is directly contactable (address and phone), exposure lasted 15 days, and membership of the file reveals that the person is a customer of the chain.
· Mitigating — no passwords, no banking data, no special category data; the supplier's logs show 2 accesses from a single address, with no bulk download observed.
My opinion, and it is reasoned: I recommend informing them, despite the mitigation. The concrete risk is targeted phishing — a message quoting the customer's name and the chain works far better than an anonymous one — and information is precisely what defuses it. I have drafted the message to the individuals: what happened, what it changes for them, the exact step to take if a suspicious message arrives, and the DPO's contact details.
What happens if you sign tonight: notification lodged with the CNIL at H+11 out of 72, information to individuals going out tomorrow morning, and a file that shows a dated chain end to end. The signature stays yours — and it is what makes the file stand up.
✎ Framework · Article 34 GDPR — communication to individuals where the risk is high
What was produced: 96 register sheets up to date, of which 18 created and 14 corrected; 2 DPIAs written; 41 rights requests handled, 41 within the one-month deadline; 1 breach assessed, notified at H+11; 41 processing contracts reviewed.
The time given back, as I count it: 218 hours over the two months, which is more than six weeks of work on a 35-hour basis — mostly on searching the systems and shaping the files, almost none on judgement, which stays with you and must stay there.
The figure that does not flatter me: of the 18 sheets I created, you rejected 3. Two rightly — I had taken for a separate processing operation what was only a module of the CRM already recorded, and I duplicated it. The cause is identified: I was starting from the name of the application account, not from the vendor. That was fixed on 12 August — I now group accounts belonging to the same vendor before proposing, and the 7 sheets proposed since have produced no duplicates. The third you rejected on the merits, and you were right there too: the processing had been stopped in June, and the document I was reading was out of date. I have added the contract end date to my criteria. dpo-dashboard_two-months.pdf218 h given back · 41 of 41 requests within the deadline · 3 sheets rejected, cause fixed
⛓ Sourced · sheet log, rights files, breach register — 1 July to 31 August
What I checked on each one, against Article 28 of the GDPR, which requires a contract governing the processing carried out on your behalf: a written act, the subject matter and duration of the processing, the categories of data and of people, security obligations, the fate of the data at the end of the contract, and authorisation of sub-processors.
The result: 35 complete contracts; 6 to be revisited — 4 with no clause on the fate of the data at the end of the contract, 2 with no list of sub-processors. 3 suppliers host outside the European Union, all three with standard contractual clauses on file: that is not a breach, it is a point to document and to review.
What I have already done: the 6 letters requesting compliance are drafted, addressed by name, with the missing clause written out and enclosed with each letter. And I have set a review date on all 41, staggered so that 41 reminders do not land in the same month.
What I propose next: connect the processor review to the contract vault, so that a newly signed contract opens its review sheet the same day. You approve, I set it up. processors_41-contracts-review.csv35 complete · 6 to revisit · 3 non-EU hosting arrangements documented
⛓ Sourced · 41 contracts from the vault, Article 28 GDPR checklist
· I open the file on a rights request the second it arrives, with its due date calculated. And the reverse is true too: if the request turns out to be a duplicate or misaddressed, I close it and log it, leaving nothing in your pile.
· I go back through the three register sources every Monday and bring you the new entries, drafted. Recording them stays your act: I propose, you settle.
· I raise an alert 10 days before any deadline — a request's due date, a processor's review date, a retention period that has run out. An alert can be switched off per processing operation, and switched back on the same way.
Everything else waits for your decision, and the attached document says exactly what: settling a sheet, concluding a DPIA, signing a notification, answering an individual, terminating a contract. Five acts that bind the company, and that carry your signature — which is exactly what makes them stand up, and why I do not try to take them from you.
What I propose for the coming month: the privacy notices on your 12 customer forms, which I can rewrite from the register sheets now that they are current — each notice deriving from a sheet you settled, it will be accurate by construction. who-decides-what_dpo-support.pdf3 automatic acts · 5 acts reserved to the DPO
✎ Framework · automatic acts, reversible and logged; five acts reserved to the DPO
Your case is not here? That is exactly what a 15-minute conversation is for. Book the free audit →
The six flows of the DPO role, equipped
Each use corresponds to part of the work the agent prepares. All of them work in support: the DPO decides.
Record of processing activities
One sheet per processing operation: purpose, named legal basis, categories, recipients, retention period (Article 30 of the GDPR).
Unrecorded processing
Rebuilds the processing operations in service that are missing from the register, from contracts, application accounts and internal requests.
Impact assessments (DPIAs)
Description, necessity and proportionality, risks and proposed measures, in the form expected by Article 35 of the GDPR.
Rights requests
Identity, search across every system, an extract ready to review, the one-month deadline displayed (Article 12 of the GDPR).
Personal data breaches
Timeline, scope, risk assessment, draft notification and breach register, under the 72-hour deadline of Article 33.
Processor tracking
Article 28 GDPR contracts, hosting location, sub-processors, review dates and deadlines.
Need to go further?
These agents handle a different business process, with their own owner and their own price. They are added to this one.
Regulatory control
To apply your business rules file by file and trace every check, a dedicated agent completes the set.
Compliance / regulatory control agent from 721 € excl. VAT / month Regulatory control →Legal assistant
For contract and regulatory research beyond personal data, a dedicated agent takes over.
Legal agent (contract / case law search) from 930 € excl. VAT / month Legal assistant →In 15 minutes we identify the most relevant agent — without oversizing the project.
Where a DPO's time goes, and where it comes back
By taking on register upkeep, searching the systems and shaping the files, the effort moves towards judgement and decision. The scale of the gain depends on the number of processing operations, processors and requests received.
The stages of your AI agent project
Audit & scoping
15 minutes to target the use case with the best return.
Quote or direct sign-up
A catalogue offer is bought online; a specific need gets a costed quote.
Design
We design the agent and its guardrails.
Integration & testing
We connect your tools to the agent, which is itself hosted in France.
Rollout
Going live and training your team.
Operation
Continuous supervision and improvement.
A DPO support agent, installed and operated for you
An L3 agent: register, DPIAs, rights requests, breaches and processors, with the connectors and monthly maintenance of that level. Prices excluding VAT — annual subscription, the time it takes for the gains to settle in.
Setup + controlled subscription
- Installation, configuration and training for your teams
- Operation, human oversight, updates and support
- Sovereign hosting in France, a dedicated and isolated resource
All inclusive, no setup fee
- Setup included (installation, configuration, training)
- Operation, human oversight, updates and support
- Sovereign hosting in France, managed end to end
On site, you own it
- Hardware installed on your premises (you own it)
- French / European AI models run locally
- Secure remote maintenance (Pro support included)
Four guarantees that matter to the DPO role
Your questions, our answers
Does the agent replace the data protection officer?
Can the register it produces be relied on during an inspection?
Does the agent notify a breach to the CNIL itself?
How does it keep to the one-month deadline on a rights request?
Does it really prepare a DPIA, or only a form?
How many systems does the agent connect to?
Is our compliance data protected?
How long does it take to deploy the agent?
Other compliance agents
Let us estimate the potential on your register and your files
15 minutes to scope your processing operations, your processors and your deadlines — hosted in France, supervised, with no commitment.