Data Protection Impact Assessment (DPIA)

AiEGIS AI Agent Security Platform — GDPR Compliance Assessment

1. Data Processed

CategoryData ElementsSensitivity
Agent RegistrationAgent name, type, owner email, API key hash, creation dateLOW
Action LogsTimestamps, action type, target resource, outcomeLOW
Compliance ScansRisk level, EU AI Act article mapping, scan timestampLOW
Behavioural BaselinesAggregated metrics (request frequency, error rates)LOW

NOT processed: End-user PII, model training data, inference inputs/outputs (unless customer explicitly configures audit logging).

2. Data Storage

3. Retention Policy

4. GDPR Legal Basis

5. Data Minimisation

6. Risk Assessment

Risk FactorAssessmentMitigation
Data breachLOWSelf-hosted; no external data transmission
Unauthorised accessLOWJWT + API key + RBAC authentication
Data lossLOWCustomer-managed backups; immutable audit logs
Cross-border transferLOWNo data leaves customer infrastructure
Purpose limitationLOWData used solely for AI governance and compliance

7. DPIA Conclusion

Overall DPIA threshold: LOW RISK

AiEGIS processes only AI agent operational metadata on customer-controlled infrastructure. No special category data, no profiling of natural persons, no cross-border data transfers. The self-hosted deployment model ensures full data sovereignty and GDPR compliance by design.