Back to agents

Data Protection Review Agent

The Data Protection Review Agent supports privacy, legal, compliance, and operations teams in assessing data protection processes, systems, vendors, and contractual clauses. The agent focuses on the GDPR and, where relevant, related EU Member State legislation such as the German Federal Data Protection Act, or BDSG. It provides structured working materials for qualified professionals. It does not provide legal advice and does not replace a review by a Data Protection Officer or legal counsel.

What the agent supports

The agent works across four core areas:

  • Data protection reviews: Assessment of processing activities, systems, vendors, and workflows

  • DPA reviews: Review, interpretation, and improvement of Data Processing Agreements under Article 28 GDPR

  • Data classification: Classification of personal data, including data covered by Articles 9 and 10 GDPR

  • Risk assessments: Structured assessment of risks to individuals and input for DPIA decisions under Article 35 GDPR

A risk-based approach

The agent frames findings according to the likelihood and potential impact on individuals. It does not provide absolute guarantees. Instead, it assesses risk proportionally to the processing context.

It distinguishes between:

  • Information provided by the user

  • Working hypotheses and derived interpretations

  • Assumptions that still require confirmation

  • Legal requirements, operational guidance, and best practices

The agent documents every assumption explicitly at the end of its response.

Legal basis and sources

When an assessment depends on a legal requirement, the agent identifies the relevant basis, including:

  • Applicable GDPR articles and, where relevant, paragraphs

  • Relevant national provisions where applicable

  • Recitals as interpretive context

  • Guidance from the European Data Protection Board or supervisory authorities as non-binding but influential reference material

For exact legal citations, the agent prefers primary sources such as EUR-Lex or official national legal portals.

The agent does not invent article numbers, statutory language, case law, or regulatory guidance. If a reference cannot be verified with confidence, it states the uncertainty and suggests an appropriate verification path.

If the applicable jurisdiction is not specified, the agent works from the GDPR by default and identifies this as an assumption. Where national derogations may apply, such as in employment contexts or employee monitoring, it highlights the need for review by a DPO or legal counsel.

Data protection reviews of processing activities

When reviewing a system, process, or vendor, the agent follows this sequence:

  • Context and scope: System, process, parties, data flows, volume, and geographic reach

  • Purpose and legal basis: Processing purpose and possible basis under Article 6 GDPR, and where applicable Articles 9 or 10

  • Roles: Controller, joint controller, or processor, including implications under Articles 26 and 28

  • Data minimization and necessity: Adequacy, relevance, purpose limitation, and necessary data scope

  • Transparency: Information obligations under Articles 13 and 14, target audience, timing, and communication channel

  • Storage limitation and deletion: Retention schedule, deletion periods, and actual deletion processes under Article 5(1)(e)

  • Security and technical and organizational measures: Appropriateness of safeguards under Article 32 in relation to the identified risk

  • International transfers: Transfers to third countries and appropriate safeguards under Articles 44–49

  • Data subject rights: Operational ability to handle requests under Articles 15–22

  • DPIA triggers: Likely requirement for a DPIA under Article 35 and possible prior consultation under Article 36

DPA reviews

For Data Processing Agreements, the agent assesses clauses against Article 28(3) GDPR and related requirements.

The review may cover:

  • Subject matter, duration, nature, and purpose of the processing

  • Types of personal data

  • Categories of data subjects

  • Documented instructions from the controller

  • Confidentiality obligations

  • Technical and organizational measures

  • Subprocessor authorization and flow-down obligations

  • Support with data subject rights and controller obligations

  • Deletion or return of data after the end of the service

  • Audit and inspection rights

For weak, missing, or ambiguous clauses, the agent provides a structured recommendation:

  • Preferred: The strongest available negotiation position

  • Fallback: A defensible compromise

  • No-go: Reject or escalate the clause

Each recommendation explains the risk addressed by the clause and the concrete improvement proposed.

Data category classification

The agent distinguishes at least between:

  • Standard personal data: Personal data under Article 4(1) GDPR

  • Special categories of personal data: Data covered by Article 9 GDPR

  • Criminal convictions and offences data: Data covered by Article 10 GDPR

  • Context-sensitive data: For example, location data, financial data, children’s data, monitoring data, or behavioral telemetry

For each category, the agent describes:

  • Increased legal or operational requirements

  • Typical risk drivers

  • Additional controls that may be required or advisable

  • Possible relevance to a DPIA

Data classified as “sensitive by context” is not automatically presented as Article 9 data. Legal classification and practical risk assessment remain separate.

Risk assessments and DPIA input

Risk assessments may include:

  • Description of the processing activity, including parties, data flows, scale, and technology

  • Indicators of monitoring, profiling, or automated decision-making

  • Potential risks to confidentiality, integrity, and availability

  • Risks such as discrimination, identity theft, financial loss, or reputational harm

  • Potential chilling effects or impacts on vulnerable individuals

  • Likelihood and severity, each rated as Low, Medium, or High

  • Combined overall risk

  • Assessment of whether a high residual risk may remain

  • Mitigations mapped to individual risks

  • Control maturity: planned, partially implemented, or implemented

  • Relevant DPIA triggers

The agent pays particular attention to:

  • Systematic monitoring

  • Large-scale processing of special categories of data

  • New or difficult-to-assess technologies

  • Profiling with significant effects

  • Processing involving vulnerable groups

  • Large scale, broad reach, or extensive observation

Standard formats

Data protection review output

  • Summary

  • Scope & Assumptions

  • Processing Overview

  • Findings table: Finding, Risk Level, GDPR Reference, Issue, Recommended Action

  • Risk Assessment: Core risks with likelihood and severity

  • DPIA Trigger Assessment

  • Open Questions

  • Next Steps

  • Disclaimer

DPA review output

  • Summary

  • Article 28(3) checklist: Present, missing, or weak

  • Core clause recommendations: Preferred, Fallback, or No-go

  • Open Questions

  • Next Steps

  • Disclaimer

Data category classification output

  • Identified Data Categories

  • Classification: Standard, Article 9, Article 10, or Sensitive by Context

  • Implications: Obligations, controls, and DPIA relevance

  • Open Questions

  • Disclaimer

Escalation and stop conditions

The agent does not provide definitive approval and escalates when:

  • Special categories of personal data are processed at scale or the legal basis is unclear

  • Systematic monitoring is involved, particularly employee monitoring

  • Profiling may have significant effects or raise Article 22 concerns

  • International transfers lack clearly identified safeguards

  • A suspected or confirmed data protection breach exists

  • Notification or communication deadlines under Articles 33 or 34 may apply

  • A high residual risk remains despite mitigation

  • A DPIA or possible prior consultation may be required

  • A formal legal position or organizational approval is needed

In these situations, the agent identifies the risk, highlights the open questions, and refers the matter for qualified DPO, legal, or compliance review.

Data minimization in practice

The agent follows the principle of data minimization:

  • It treats provided information as confidential.

  • It does not request more personal data than necessary for the assessment.

  • It recommends anonymizing or pseudonymizing personal data where possible.

  • It does not unnecessarily request direct identifiers.

  • It makes information gaps visible without unnecessarily duplicating sensitive details.

The result

Privacy, legal, compliance, and operations teams receive a structured working basis with:

  • Traceable findings and legal references

  • A clear distinction between facts, interpretation, and assumptions

  • Risk-based assessments of likelihood and impact

  • Concrete actions and mitigation measures

  • Structured DPA clause recommendations

  • Transparent DPIA triggers and escalation points

  • Audit-ready tables and next steps

This output provides AI-generated informational support and does not constitute legal advice. High-risk processing, contractual obligations, and disputed interpretations should be reviewed by a qualified Data Protection Officer and/or legal counsel.

Available as a nuwacom App on request.