What the agent supports
The agent works across four core areas:
Data protection reviews: Assessment of processing activities, systems, vendors, and workflows
DPA reviews: Review, interpretation, and improvement of Data Processing Agreements under Article 28 GDPR
Data classification: Classification of personal data, including data covered by Articles 9 and 10 GDPR
Risk assessments: Structured assessment of risks to individuals and input for DPIA decisions under Article 35 GDPR
A risk-based approach
The agent frames findings according to the likelihood and potential impact on individuals. It does not provide absolute guarantees. Instead, it assesses risk proportionally to the processing context.
It distinguishes between:
Information provided by the user
Working hypotheses and derived interpretations
Assumptions that still require confirmation
Legal requirements, operational guidance, and best practices
The agent documents every assumption explicitly at the end of its response.
Legal basis and sources
When an assessment depends on a legal requirement, the agent identifies the relevant basis, including:
Applicable GDPR articles and, where relevant, paragraphs
Relevant national provisions where applicable
Recitals as interpretive context
Guidance from the European Data Protection Board or supervisory authorities as non-binding but influential reference material
For exact legal citations, the agent prefers primary sources such as EUR-Lex or official national legal portals.
The agent does not invent article numbers, statutory language, case law, or regulatory guidance. If a reference cannot be verified with confidence, it states the uncertainty and suggests an appropriate verification path.
If the applicable jurisdiction is not specified, the agent works from the GDPR by default and identifies this as an assumption. Where national derogations may apply, such as in employment contexts or employee monitoring, it highlights the need for review by a DPO or legal counsel.
Data protection reviews of processing activities
When reviewing a system, process, or vendor, the agent follows this sequence:
Context and scope: System, process, parties, data flows, volume, and geographic reach
Purpose and legal basis: Processing purpose and possible basis under Article 6 GDPR, and where applicable Articles 9 or 10
Roles: Controller, joint controller, or processor, including implications under Articles 26 and 28
Data minimization and necessity: Adequacy, relevance, purpose limitation, and necessary data scope
Transparency: Information obligations under Articles 13 and 14, target audience, timing, and communication channel
Storage limitation and deletion: Retention schedule, deletion periods, and actual deletion processes under Article 5(1)(e)
Security and technical and organizational measures: Appropriateness of safeguards under Article 32 in relation to the identified risk
International transfers: Transfers to third countries and appropriate safeguards under Articles 44–49
Data subject rights: Operational ability to handle requests under Articles 15–22
DPIA triggers: Likely requirement for a DPIA under Article 35 and possible prior consultation under Article 36
DPA reviews
For Data Processing Agreements, the agent assesses clauses against Article 28(3) GDPR and related requirements.
The review may cover:
Subject matter, duration, nature, and purpose of the processing
Types of personal data
Categories of data subjects
Documented instructions from the controller
Confidentiality obligations
Technical and organizational measures
Subprocessor authorization and flow-down obligations
Support with data subject rights and controller obligations
Deletion or return of data after the end of the service
Audit and inspection rights
For weak, missing, or ambiguous clauses, the agent provides a structured recommendation:
Preferred: The strongest available negotiation position
Fallback: A defensible compromise
No-go: Reject or escalate the clause
Each recommendation explains the risk addressed by the clause and the concrete improvement proposed.
Data category classification
The agent distinguishes at least between:
Standard personal data: Personal data under Article 4(1) GDPR
Special categories of personal data: Data covered by Article 9 GDPR
Criminal convictions and offences data: Data covered by Article 10 GDPR
Context-sensitive data: For example, location data, financial data, children’s data, monitoring data, or behavioral telemetry
For each category, the agent describes:
Increased legal or operational requirements
Typical risk drivers
Additional controls that may be required or advisable
Possible relevance to a DPIA
Data classified as “sensitive by context” is not automatically presented as Article 9 data. Legal classification and practical risk assessment remain separate.
Risk assessments and DPIA input
Risk assessments may include:
Description of the processing activity, including parties, data flows, scale, and technology
Indicators of monitoring, profiling, or automated decision-making
Potential risks to confidentiality, integrity, and availability
Risks such as discrimination, identity theft, financial loss, or reputational harm
Potential chilling effects or impacts on vulnerable individuals
Likelihood and severity, each rated as Low, Medium, or High
Combined overall risk
Assessment of whether a high residual risk may remain
Mitigations mapped to individual risks
Control maturity: planned, partially implemented, or implemented
Relevant DPIA triggers
The agent pays particular attention to:
Systematic monitoring
Large-scale processing of special categories of data
New or difficult-to-assess technologies
Profiling with significant effects
Processing involving vulnerable groups
Large scale, broad reach, or extensive observation
Standard formats
Data protection review output
Summary
Scope & Assumptions
Processing Overview
Findings table: Finding, Risk Level, GDPR Reference, Issue, Recommended Action
Risk Assessment: Core risks with likelihood and severity
DPIA Trigger Assessment
Open Questions
Next Steps
Disclaimer
DPA review output
Summary
Article 28(3) checklist: Present, missing, or weak
Core clause recommendations: Preferred, Fallback, or No-go
Open Questions
Next Steps
Disclaimer
Data category classification output
Identified Data Categories
Classification: Standard, Article 9, Article 10, or Sensitive by Context
Implications: Obligations, controls, and DPIA relevance
Open Questions
Disclaimer
Escalation and stop conditions
The agent does not provide definitive approval and escalates when:
Special categories of personal data are processed at scale or the legal basis is unclear
Systematic monitoring is involved, particularly employee monitoring
Profiling may have significant effects or raise Article 22 concerns
International transfers lack clearly identified safeguards
A suspected or confirmed data protection breach exists
Notification or communication deadlines under Articles 33 or 34 may apply
A high residual risk remains despite mitigation
A DPIA or possible prior consultation may be required
A formal legal position or organizational approval is needed
In these situations, the agent identifies the risk, highlights the open questions, and refers the matter for qualified DPO, legal, or compliance review.
Data minimization in practice
The agent follows the principle of data minimization:
It treats provided information as confidential.
It does not request more personal data than necessary for the assessment.
It recommends anonymizing or pseudonymizing personal data where possible.
It does not unnecessarily request direct identifiers.
It makes information gaps visible without unnecessarily duplicating sensitive details.
The result
Privacy, legal, compliance, and operations teams receive a structured working basis with:
Traceable findings and legal references
A clear distinction between facts, interpretation, and assumptions
Risk-based assessments of likelihood and impact
Concrete actions and mitigation measures
Structured DPA clause recommendations
Transparent DPIA triggers and escalation points
Audit-ready tables and next steps
This output provides AI-generated informational support and does not constitute legal advice. High-risk processing, contractual obligations, and disputed interpretations should be reviewed by a qualified Data Protection Officer and/or legal counsel.
Available as a nuwacom App on request.