dsgvo

GDPR Audit Checklist for AI Tools: 12 Points in 15 Minutes

26. August 2026 · EN

A practical checklist to evaluate any AI tool for GDPR compliance in 15 minutes. With specific questions to ask vendors.

GDPR Audit Checklist for AI Tools: 12 Points in 15 Minutes

You want to introduce an AI tool — call-center agent, email assistant, voice bot — and you need a GDPR assessment. But you don’t have a Data Protection Officer (DPO) who can run week-long audits. This checklist is for SMBs: pragmatic, fast, complete enough for most B2B use cases.

When do I actually need a GDPR audit?

Whenever the AI tool processes personal data. In B2B contexts, that’s typically:

  • Email addresses, names, phone numbers of customers
  • Contents of customer emails
  • Call contents (transcribed)
  • Chat messages

Internal staff data (e.g. who handled which inquiry) counts too.

Exceptions: Fully anonymised data, internal tools without customer data, or aggregate statistics without personal reference. In all other cases: run the audit.

The 12-Point Checklist

Hosting & Third-Country Transfer

  • 1. Where is it hosted? EU/EEA is required. USA, UK (post-Brexit), third countries = problem.
  • 2. Is there a Data Processing Agreement (DPA)? Vendor must offer it unprompted. Missing = red flag.
  • 3. Transfer Impact Assessment (TIA)? Mandatory for third-country transfers. Ask for it.

Data Processing

  • 4. Are training data created from my data? OpenAI et al. do NOT use customer data for training (in the API plan), but don’t rely on it — check the DPA.
  • 5. Where is data stored? How long? Logs, backups, telemetry. Default 30 days? Configurable?
  • 6. Who has access? Subcontractors, support teams, “quality assurance”. Demand a list.

Human-in-the-Loop

  • 7. Draft-Only mode available? AI suggests, human decides. Mandatory under Art. 22 GDPR (automated individual decision-making).
  • 8. Can fully-autonomous mode be disabled? Some vendors advertise “fully autonomous” — that’s almost always problematic in a B2B customer context.

Audit & Logging

  • 9. Complete audit trails? Every prompt, every response, every human change. Timestamps, user IDs, context.
  • 10. Can you export the audit data? In case of dispute, you must be able to prove what the AI said when.

Deletion Concept

  • 11. Data deletion on request? Within 30 days of contract end? Get it in writing.
  • 12. Encryption at-rest and in-transit? TLS 1.3, AES-256. Standard, but demand it explicitly.

Bonus Questions for the Vendor

These 5 questions separate serious vendors from hobby projects:

  1. “Where is your ISO 27001 certificate?” — Vendors with a certified ISMS are 3-5x safer.
  2. “Do you have a CISO / DPO by name?” — If no, no go.
  3. “Can you show me your last 3 pentest reports (under NDA)?” — Vendors without pentests = red flag.
  4. “What does your incident response plan look like?” — Who informs me in case of a breach? In what timeframe?
  5. “Can you guarantee an isolated EU instance?” — Some vendors can, some can’t. If yes, that’s the strongest compliance guarantee.

Quick Verdict in 60 Seconds

If the vendor has no clear answer on 3 or more of these 12 points, look elsewhere. If 6 or more are unclear, the tool is not suitable for GDPR-compliant use.

How EmpireHazeClaw Does It

We host in Frankfurt, operate Draft-Only mode by default, provide complete audit trails with export, and have a clear DPA process (24h SLA, no data export to third countries). On empirehazeclaw.com you can see the English product page; the technical architecture is documented at empirehazeclaw.info/impressum.html. If you want to buy an AI tool, it takes 5 minutes: empirehazeclaw.store — GDPR-compliant, monthly cancellation, €299.

Conclusion

A GDPR audit doesn’t have to take weeks. With this 12-point list, you have a defensible first assessment in 15 minutes. At 6+ unclear points: keep looking. At EmpireHazeClaw, you can answer all 12 points with “Yes” immediately — that’s part of our promise.