Corelyx

DPIA generator for AI systems

DPIA Generator

Generate a GDPR Data Protection Impact Assessment draft for AI workflows that process personal data. The generated output is a working draft for governance review and should be validated by the accountable business, technical, legal, and compliance owners.

Public preview only — nothing here is saved.

This automatically generated draft is not attached to a workflow or account. To keep workflow-specific revisions, review changes, and record completion, sign in and use the workflow's DPIA page in Governance.

# DPIA Working Draft: AI customer support triage

> **Status:** Draft for human review. This document was generated automatically from the information provided. Confirm it against the workflow's actual data flow and governance evidence. It is not legal advice, an approval, or a completed DPIA.

## How to use this draft
1. Confirm that the purpose, people, data, providers, and automated decisions below are accurate.
2. Replace broad or missing statements with facts specific to this workflow.
3. Have the accountable business, technical, privacy/DPO, and legal reviewers assess the risks and controls.
4. Record completion only after the reviewers agree that the assessment is accurate and residual risk is accepted or escalated.

## 1. Processing purpose
Classify customer requests, draft internal recommendations, and route complex cases to support specialists.

## 2. Personal-data scope

### Data categories
- Name
- email address
- support message
- account metadata

### People affected
- Customers
- support agents

### How the workflow uses personal data
The workflow uses message content to classify intent and generate an internal support summary.

## 3. Automated decision-making
No solely automated consequential decision-making is documented in this draft.

## 4. Providers and external systems
- Corelyx
- model provider
- support inbox provider

## 5. Necessity assessment
The processing should be limited to data necessary for the documented workflow purpose. Each node should have a defined input, output, retention need, and owner.

## 6. Proportionality assessment
The workflow should use the least intrusive data source, minimise prompt content, avoid unnecessary special-category data, and provide human oversight where the output affects people.

## 7. Risk analysis
- Unnecessary personal-data exposure in prompts or connector payloads.
- Inaccurate, biased, or poorly explained AI recommendations.
- Excessive retention of prompts, outputs, or decision evidence.
- Insufficient review before customer, employee, patient, or candidate impact.

## 8. Mitigation measures
- Minimise personal data before AI/model calls.
- Use human approval before consequential actions.
- Restrict access to workflow logs and generated reports.
- Retain prompts and outputs only where necessary.
- Record model/provider metadata and reviewer decisions.

## 9. Residual risks
- Model output may be inaccurate or biased.
- Data-source quality may affect recommendations.
- Third-party provider configuration may change.

## 10. Review and decision
- [ ] Workflow facts and data flows verified
- [ ] Necessity and proportionality assessed
- [ ] Risks and mitigations reviewed by the privacy owner or DPO
- [ ] Residual risk accepted or escalated
- [ ] Required notices and human oversight confirmed

### Reviewer record
- Business owner: Not recorded in this draft
- Technical owner: Not recorded in this draft
- Privacy/DPO reviewer: Not recorded in this draft
- Legal reviewer (where required): Not recorded in this draft
- Decision and rationale: Pending human review

If high residual risk cannot be mitigated, obtain qualified advice on prior consultation with the competent supervisory authority before processing begins.

Problem

AI workflows are often created faster than organizations can inventory, classify, document, monitor, audit, review, and govern them.

Regulatory relevance

GDPR and the EU AI Act both reward clear records, risk assessment, human oversight, logging, and accountable review processes.

Corelyx solution

Inside Corelyx, these draft reports become workflow-native evidence connected to schemas, approvals, execution logs, and exports.

DPIA Generator | Corelyx