compliance · GDPR
Wytness and GDPR
Articles 5, 25, 30, and 32 — evidenced with pseudonymisation at the core.
Wytness is built so the personal data your agents touch can reach us sealed: secret-named fields are scrubbed on every event, your customer-held keys pseudonymise structured identifiers and the fields you declare, and the audit trail can live in your own jurisdiction. Below is the article-by-article mapping; the processor/controller boundary is stated plainly at the end.
the artefact
What your DPO can hand over
GDPR is evidenced by the same machinery as the frameworks that do have packs, not by a pack of its own: the subject export for Article 15, the agent and tool inventories behind Article 30, and — for Articles 5, 25 and 32 — the key flow itself, which is the part a supervisory authority tends to ask about.
the mapping
What we map to what
| Article | Requirement | What Wytness provides |
|---|---|---|
| Article 5 | Lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, integrity, confidentiality. | PII pseudonymisation at egress means Wytness receives the minimum identifiable data necessary for audit. Customer-held keys give you full control over re-identification. |
| Article 15 | Right of access by the data subject. | Full-history subject export runs asynchronously and downloads as a single artefact covering every record held for that subject, with any section that failed to read reported rather than silently omitted. |
| Article 22 | Automated individual decision-making, including profiling. | Wytness does not make automated decisions about individuals — it records the decisions your agents make. The per-event trail (inputs, tool calls, outcomes, human approvals) is the evidence base for the Article 22(3) safeguards you owe your data subjects: human intervention, contestability, and review of what the agent actually did. |
| Article 25 | Data protection by design and by default. | Secret-named fields are scrubbed on every event; generating your PII keys enables pseudonymisation of structured identifiers and any field you declare — you hold the keys, Wytness never can. Bring Your Own Storage means the audit trail stays in your jurisdiction. Encryption at rest and in transit are turnkey. |
| Article 30 | Records of processing activities (ROPA). | Per-agent inventories with capability descriptions, data categories processed, and recipients of personal data — queryable in the dashboard and exportable. Wytness does not assemble the ROPA document itself; it holds the underlying records your DPO compiles it from. |
| Article 32 | Security of processing. | Ed25519 signing, hash-chained events, long-term retention with a soft-delete recovery window, anomaly detection, and access role-gating. Vendor-side attestation status, including the first third-party penetration test, is listed on /trust. |
| Article 33 | Notification of personal data breach. | A mis-signed envelope is rejected at ingest and recorded; the anomaly engine surfaces chain breaks, restricted-data access, and off-hours activity in seconds, raising in-app notifications and email alerts. Push into your own SIEM or incident workflow arrives with the connectors (coming soon). |
the boundary
What Wytness does not cover
- —There is no GDPR Evidence Pack. Packs are generated for SOC 2, the EU AI Act, and ISO 27001; each carries the signed event samples and integrity attestations that also evidence Article 32, and the subject export covers Article 15 directly.
- —Wytness is a processor (or sub-processor) for the audit data your AI agents generate. We are not a controller. You determine the purposes and means of processing.
- —Data subject rights (access, erasure, portability requests) are operator obligations. Wytness gives you the tools to re-identify and respond; we do not respond on your behalf.
- —Assembling the Article 30 ROPA document is the operator's job. Wytness holds and exports the agent and tool inventory data it draws on.
- —Cross-border transfer impact assessments and Standard Contractual Clauses are operator obligations. Our DPA, sub-processor list, and SCC suite are at /trust.