The documents on a website may be in perfect order while the actual processing of personal data is not: the data goes to contractors, to foreign services and to external models that the policy says nothing about. We look at what actually happens and bring the documents into line with the processes, not the other way round.

What is included

  • A review of the actual processing operations
  • A list of discrepancies, each with a severity rating and a recommendation
  • Internal regulations, orders and forms that close those discrepancies
  • Processing instructions for processors and contractors who gain access to the data
  • A consent and a notification for cross-border transfer, which give the right to work with foreign services

Case study

An AI service whose documents described the wrong process

The request

The DomIQ service takes users’ requests in a messaging app, processes them with artificial intelligence, passes them to a contractor and holds the payment until the work is confirmed. The service had personal data documents, but they were written before the product took this form.

What we did

We audited the processing operations using a questionnaire and interviews with the team. We found that the data is processed for three independent purposes, that it is passed to three external model providers and that the vetting of contractors is outsourced to a third-party service – and that none of this was reflected in the documents. We prepared a report listing the discrepancies, rewrote the policy and prepared a consent, as well as a separate consent to cross-border transfer.

The result

The documents now describe what actually happens. The questionnaire and the report form from this project became the practice’s template for subsequent audits.

Solve your matter

Tell us about your situation — we will offer a concrete solution.

Write to us