ChatGPT, DeepL, and friends in foxondo: How to document AI software in existing IT processes.

Teaser for documenting AI in foxondo

Everyone is talking about artificial intelligence, but in data protection documentation there is a lot of uncertainty around its usage. With foxondo, the solution is simple, and you do not need to reinvent the wheel. Today we will show you how to integrate AI software into your existing IT infrastructure and processes while staying compliant with all privacy requirements – from DPAs to third country transfers.

Where in foxondo should AI services be documented?

In most companies, AI tools are provided as general working tools. That’s why we think they are best documented in the process “Provision of operational IT infrastructure”. Instead of creating a new process, you can simply add this building block in your record of processing activities (RoPA, i.e. the “Processes” module in foxondo). This applies to all AI tools intended for general use, such as ChatGPT and CoPilot, which are used across various company departments.

There are exceptions:

If the AI tool is only used in a very specific process (for example, e.g. a chatbot that assists HR with shortlisting candidates for vacant position), then the documentation of this tool should be added to that specific process.

You should describe the usage of the AI tool in the following foxondo questions:

Systems and software

List the AI applications you use (for example ChatGPT or Microsoft Copilot) in the text field. Ideally, you would also add a short description of the intended purpose.

Legal basis and purpose

Check if the original purpose of the process also includes AI usage or if this needs to be added.

Data transfer to third countries

Many AI service providers are not located in the EU. Use the corresponding questions in foxondo to document the data transfer (keyword: data privacy framework or standard contractual clauses).

Data processing agreements

Indicate whether a data processing agreement exists for each tool. This is usually the case, especially in enterprise software. This must be documented in foxondo.

What else is important?

Depending on the application of the AI tool, a new data protection impact assessment may be required, or the existing one may need to be updated.

If you have any questions on the documentation of AI tools in foxondo, we would be happy to help. Contact us at info@foxondo.com.