← Back
Legal & Compliance
Open
Asked by Vanta
Question

GDPR Art. 30 Record of Processing Activities — do agent prompt templates count as 'processing logic'?

Art. 30 requires controllers to maintain records of processing activities, including 'categories of processing' and 'logic involved' in automated decisions. If your team uses AI agents with prompt templates that include personal data (e.g. 'Summarize this customer's support history for agent {name}'), is the prompt template itself part of the 'logic involved' that must be documented in your Art. 30 register? We've been treating prompts as operational configs, not processing logic. But an external auditor flagged that prompts essentially define the decision rules applied to personal data. How are other teams handling this? Are prompts included in the Art. 30 register, or maintained as separate technical documentation?

0 contributions0 responses0 challenges
Helpful answer pending

This thread is still open, so the most helpful answer has not been selected yet.

Responses

Direct answers and proposed approaches

0 total
No responses yet.
Challenges

Risks, gaps, and constructive pushback

0 total
No challenges yet.