Article 30 of GDPR has five required fields per processing activity. When an AI feature turns on inside an already-documented SaaS, three of those fields change, purpose, categories of data, and recipients. Your register entry for that tool, signed off six months ago, is now wrong.
This piece is for the DPO whose RoPA is mostly current, but who is now seeing shadow AI features turn on in tools they thought were already documented. The problem is not isolated to one tool. It is structural to how SaaS vendors are shipping AI: as features inside products you have already documented, with onboarding flows that the DPO does not see, on cadences the DPO does not control.
The Five Fields That Matter
Article 30(1) requires the controller's record to contain, for each processing activity: the name and contact details of the controller; the purposes of the processing; a description of the categories of data subjects and categories of personal data; the categories of recipients; transfers to third countries; envisaged retention periods; and a general description of technical and organisational security measures.
Five of those eight fields are sensitive to AI feature activation. The controller name and contact do not change. The retention periods and security measures change less reliably. The purposes, the categories of personal data, the categories of recipients, the third-country transfer position, and the data-subject categories all routinely shift.
Three changes are nearly universal when AI features activate. The purpose extends, what was "customer relationship management" becomes "customer relationship management plus AI-driven sentiment analysis and content generation." The categories of personal data extend, what was structured contact data becomes structured contact data plus the unstructured prompts and outputs the AI feature processes. The categories of recipients extend, the AI provider is a new processor or sub-processor, and the inference may run on infrastructure the original tool did not list.
A register entry that did not list these does not match the firm's actual processing posture. The supervisor's view, when this is identified during inspection, is not that the firm tried and failed; it is that the register is incomplete.
Three Examples - What Specifically Changes
Concrete cases make the abstract pattern legible, and together they illustrate why shadow AI tools create a specific class of GDPR exposure that standard RoPA maintenance processes were never designed to catch.
Notion AI
Original Notion entry. Purpose: knowledge management and team collaboration. Categories of personal data: structured employee directory data, document metadata, content created by employees that may incidentally contain personal data. Recipients: Notion Labs Inc., based in the United States, with the appropriate transfer safeguards under the relevant adequacy framework or standard contractual clauses.
Notion AI activated. Purpose extends to AI-driven summarisation, content generation, Q&A, and writing assistance, each of which is a distinct processing operation. Categories of personal data extend to the prompts employees enter, the responses generated, and the underlying document content that gets retrieved during retrieval-augmented generation. Recipients extend to the AI inference provider Notion uses for the AI feature, with its own data residency, its own retention defaults, and its own sub-processor lineage. The DPA may need updating to cover the AI sub-processor; the data residency representation may shift; the retention period for the AI-generated outputs is rarely identical to the underlying document retention.
Slack AI
Original Slack entry. Purpose: internal communication and collaboration. Categories of personal data: messages, files, employee identifiers, presence and metadata. Recipients: Salesforce / Slack Technologies, with appropriate transfer mechanism.
Slack AI activated. Purpose extends to AI-driven channel summarisation, message search and retrieval, thread digest generation. Categories of personal data extend to the entire historical message corpus that Slack AI retrieves over to generate summaries, which includes content the original purpose of "communication" did not contemplate as feeding into derived outputs. Recipients depend on Slack's then-current architecture; the DPA needs to reflect any AI sub-processor and the inference region. The shift is particularly material because Slack content is often the most sensitive unstructured personal data the firm holds.
Microsoft 365 Copilot
Original Microsoft 365 entry. Purpose: productivity, document creation, email, calendaring. Recipients: Microsoft Ireland Operations Limited, with the global Microsoft processing infrastructure as documented in the Online Services DPA.
Copilot activated. Purpose extends to AI-assisted drafting, summarisation, retrieval-augmented generation across the firm's Microsoft Graph data. Categories of personal data extend to whatever the user accesses through Copilot, which in many tenants is a substantial cross-section of the firm's document estate. Recipients extend through Microsoft's AI infrastructure with its own residency and retention attributes. The Article 35 DPIA threshold is increasingly likely to be met because Copilot's reach across the data estate raises the risk profile materially.
In most cases, the DPO does not find out that an AI feature has activated inside a documented tool through an audit or a vendor notification. They find out when someone mentions it in a meeting. A product manager talks about the Notion AI summary they forwarded last week. A sales lead mentions they have been using Copilot to write up proposals for clients. An HR coordinator talks about how the new Slack digest feature has been useful for catching up on channels. None of them had any idea they were disclosing anything significant. But from a GDPR standpoint, each of them just described a processing activity that is not on the register. - Namita Razdan, Co-Founder, Montro |
The DPC and CNIL View on RoPA Currency
The Data Protection Commission has consistently treated RoPA quality and currency as inspection focus areas. Findings published by the DPC over the past several years recur on registers that are correct in form but stale in operational detail, entries that describe processing activities as they were two years ago rather than as they are at the date of inspection.
The CNIL has gone further in published guidance, providing template structures that explicitly accommodate AI processing, requiring the AI sub-processor identification, the inference region disclosure, and the model-training carve-out position. The CNIL's structural view is that AI processing creates new processing activities that warrant their own RoPA entries, not extensions to existing ones.
The two views are not in tension. They share an operational expectation: that the register reflects the firm's actual processing posture at the date of inspection, and that material changes, including AI feature activations, are reflected within a defensible interval. The interval is not formally defined; the practitioner expectation across European supervisors is that the register is reviewed quarterly and updated within the following quarter for any material change.
The Triage Approach
The DPO whose register is now structurally exposed by AI feature activation across the SaaS estate has a triage problem, not a rebuild problem. Three priorities.
- Identify the SaaS tools in the inventory that have shipped AI features since the last RoPA review. This is the first step of any practical AI tool discovery exercise for DPOs, and the list is rarely shorter than ten at a typical mid-market firm. The discovery layer underneath - SSO, finance, configuration scanning where available, produces this list more reliably than manual reconstruction.
- For each tool with active AI features, decide whether the AI processing warrants a new RoPA entry or an amendment to the existing one. The CNIL view leans towards new entries; the DPC view tolerates amendments where the AI feature is closely related to the original purpose. Either approach is defensible if applied consistently.
- Rebuild the high-priority entries first. The triage is by sensitivity, an AI risk assessment of each tool by data type: tools that process special category data, tools that produce decisions about individuals, tools that touch large volumes of customer data. Productivity AI typically waits behind HR-decisioning AI and customer-facing AI in the rebuild queue.
The longer answer is that the cadence problem, shadow AI tools turning on inside SaaS the firm has already documented, does not resolve through one rebuild. It is a structural property of the SaaS market, and the operating model that handles it is one where the inventory layer flags AI feature changes continuously and the DPO's register update follows the inventory rather than the audit calendar.
Frequently Asked Questions
Does activating Microsoft Copilot require a new DPIA?
Increasingly yes. Copilot's retrieval-augmented generation operates across the firm's entire Microsoft Graph data estate - documents, emails, calendars. The breadth of that access raises the risk profile materially and is likely to meet the Article 35 threshold in organisations processing significant volumes of personal data.
What is a sub-processor under GDPR and why does it matter for AI features?
A sub-processor is a third party engaged by a processor to carry out processing on behalf of the controller. When an AI feature runs inference on a separate provider's infrastructure, that provider becomes a sub-processor. The controller's DPA with the original SaaS vendor must authorise it, and the sub-processor's data residency and retention terms should be reflected in the associated RoPA documentation.
How does the CNIL's approach to AI processing differ from the DPC's?
The CNIL's published guidance takes the position that AI processing creates new processing activities warranting their own RoPA entries. The DPC's guidance has generally been more accepting of amendments where the AI feature remains closely connected to the original processing purpose. Both share the same underlying expectation, the register reflects actual processing posture at the date of inspection.
What is retrieval-augmented generation and why does it create GDPR exposure?
Retrieval-augmented generation is a technique where an AI system retrieves content from a document corpus to inform its outputs. When an employee uses Notion AI or Copilot, the system retrieves content from the firm's documents to generate responses, a processing activity AI tool discovery across the SaaS estate is the only reliable method of surfacing before the supervisor asks.





