P
⚖️LegalAdvanced4 steps

GDPR Compliance Verification Agent for Websites and Applications

This agent analyzes your personal data processing and verifies its compliance with the General Data Protection Regulation (GDPR). It identifies compliance gaps, assesses associated risks, and generates a prioritized remediation plan with concrete recommendations.

conformité RGPDaudit juridiqueprotection des donnéescomplianceDPO

For who

DPOs, compliance officers, corporate lawyers, GDPR consultants, and SMB executives looking to quickly audit their GDPR compliance.

Input

Type: text
Format: libre

Description de l'organisation, de ses activités, des traitements de données personnelles réalisés (formulaires, bases clients, RH, marketing, sous-traitants, outils utilisés), des mesures de sécurité en place et des documents de conformité existants (politique de confidentialité, registre des traitements, CGU/CGV, contrats sous-traitants).

steps (4)

1

Processing Activities Mapping

prompt

Analysis and structuring of all declared personal data processing activities

2

Article-by-Article Compliance Audit

prompt

Systematic verification of each processing activity's compliance with key GDPR requirements

3

Risk Assessment and Prioritization

prompt

Classification of gaps by risk level and remediation urgency

4

Detailed Remediation Plan

prompt

Generation of a concrete corrective action plan with owners and deadlines

Output

Type: text
Format: structuré

Rapport de conformité RGPD complet comprenant : registre des traitements cartographié, grille d'audit article par article avec statuts de conformité, matrice des risques priorisée, et plan de remédiation détaillé avec actions correctives, responsables, échéances et indicateurs de succès.

Example

Input

Our B2B SaaS company (50 employees, 5M EUR revenue) publishes HR management software. We collect data from our clients (companies) and their employees: name, first name, email, social security number, pay slips, sick leave. Hosted on AWS Ireland and AWS US-East. We use Google Analytics, HubSpot for marketing, and Slack internally. No appointed DPO. Privacy policy dating from 2019. Cookie consent via a simple banner 'By continuing, you agree'. No formalized processing register. Payroll subcontractor based in Tunisia without specific contractual clauses.

Output

**Overall compliance score: 35/100 — Critical level**

**Register**: 8 processing activities identified, including 3 at very high risk (employee health data, social security numbers, pay slips).

**Critical gaps P1**:
- No DPO despite being mandatory (large-scale sensitive data processing, Art. 37)
- Payroll data transfer to Tunisia without valid transfer mechanism (Art. 44-49)
- Health data processing without DPIA (Art. 35)
- Cookie banner non-compliant (no equivalent refusal option, consent not freely given)

**Important gaps P2**:
- Outdated and incomplete privacy policy
- No formalized processing register (Art. 30)
- Processor contracts without Art. 28 clauses

**Phase 1 (urgent)**: Appoint a DPO, suspend Tunisia transfer or implement SCCs, complete the DPIA, redo cookie banner with compliant CMP.
**Phase 2**: Update privacy policy, formalize the register, renegotiate processor contracts.
**Phase 3**: Train teams, implement rights exercise process, plan semi-annual audits.

Customization

ParameterDescriptionDefault
Secteur d'activitéSecteur de l'organisation pour adapter les exigences sectorielles spécifiques (santé, finance, e-commerce, RH, éducation)Généraliste
Niveau de détail du rapportGranularité souhaitée pour le rapport : synthétique (direction), standard (DPO), ou exhaustif (audit formel CNIL)Standard
Référentiel complémentaireRéférentiels additionnels à croiser avec le RGPD : recommandations CNIL, ISO 27701, ePrivacy, CCPA, guidelines EDPBRecommandations CNIL

Technical Notes

<p>This agent performs an analysis based on declarative information provided by the user. It does not replace a field audit or personalized legal advice. For organizations processing sensitive data at large scale (health, biometrics, judicial data), it is recommended to complement this analysis with a consultation with a certified DPO or specialized firm.</p><p>The prompts are calibrated on the GDPR (EU Regulation 2016/679) and EDPB (European Data Protection Board) guidelines. For multi-jurisdictional compliance, activate the appropriate complementary framework (CCPA for the United States, LGPD for Brazil, etc.).</p><p>For a more thorough audit, provide your existing documents as input: privacy policy, processing register, processor contracts, completed DPIAs. The agent can then perform a comparative analysis between your documents and regulatory requirements.</p>

Related Prompts

⚖️LegalAdvancedAll AIs

Draft GDPR-Compliant Terms of Use and Service

Generates complete, structured Terms of Use and/or Terms of Service that are GDPR-compliant, adapted to your online business.

0432
⚖️LegalIntermediateAll AIs

DALL-E Prompt for Drafting a Contract

DALL-E, the image generation tool developed by OpenAI, can play an unexpected but valuable role in drafting contracts. While it doesn't draft legal text directly, DALL-E enables you to create professional visuals that accompany and enrich your contractual documents: explanatory diagrams of clauses, responsibility flowcharts, business process illustrations, or visual layouts for technical appendices. In a context where visual clarity enhances the understanding of commitments between parties, integrating graphic elements generated by DALL-E into your contracts can reduce ambiguities and facilitate negotiation. Whether you are a legal professional, entrepreneur, or freelancer, this hybrid text-image approach modernizes your documents and makes them more accessible. Contractual visuals are particularly useful for service agreements involving creative deliverables, partnership agreements requiring governance schematics, or technical contracts with specifications to be illustrated. Discover how to formulate your DALL-E prompts to produce professional-quality contractual visual elements.

0166
⚖️LegalAdvancedAll AIs

Prompt to Analyze SaaS Contract Terms

This prompt provides a complete legal analysis of a SaaS contract, covering risks, GDPR compliance, SLAs, data ownership and negotiation recommendations.

0103
⚖️LegalIntermediateAll AIs

GitHub Copilot Prompt for Drafting Terms of Use

Drafting Terms of Use (CGU) is a crucial legal step for any website or application. This document governs the relationship between the editor and its users, defining rights, obligations, and responsibilities of each party. However, drafting complete CGU compliant with French and European legal frameworks is a complex exercise, often outsourced to specialized law firms. GitHub Copilot, integrated directly into your development environment, offers a complementary approach to generate a first structured version of your CGU. By leveraging its ability to produce contextualized legal text, you can quickly obtain a document covering essential clauses: purpose of service, intellectual property, personal data protection, liability limitations, and termination terms. This prompt is designed to guide Copilot in producing a professional document adapted to your platform type. It does not replace validation by a legal professional but provides a solid foundation to significantly accelerate your legal drafting process.

0204