CattleGrid

DPO / Compliance Officer

DPO / Compliance Officer

The stake

A processor relationship does not require a signed contract to exist. It requires personal data to be sent to a third party for processing. Every time a member of staff pastes a client name, a case reference, or an employee record into a public AI tool, that data has left your organisation and reached a processor you almost certainly have not documented, assessed, or put a DPA in front of.

This is not a hypothetical gap. 71% of UK employees are using AI tools their employer has not sanctioned, and 51% do so at least weekly (Microsoft/Censuswide UK Shadow AI Survey, October 2025, n=2,003). 83% of UK organisations have no controls over what data leaves through those tools (BlackFog/Sapio Research, November 2025, n=1,000 UK organisations). The IBM Cost of Data Breach Report 2025 puts the additional cost of a breach where shadow AI was involved at £498,000 over the baseline, against an average UK breach cost of £3.29 million. None of that is a technology problem you can solve with a memo. It is a visibility problem, and visibility is what an audit trail is for.

What CattleGrid actually does

It enforces the policy you already wrote, on every request, not just the ones people remember. CattleGrid sits inline between your applications and the AI providers they call, inspecting the content of every outbound prompt against your configured rules before it leaves. Twenty-eight pre-built templates cover UK-specific personal data — National Insurance numbers, NHS numbers, postcodes, passport numbers, phone numbers, dates of birth — alongside financial data and credentials, with block, redact, warn, or log actions assignable per rule.

The audit trail is cryptographically verifiable — tamper-evident by design. Every inspection decision is written to an immutable record, chained using SHA-256 hashing and signed with HMAC-SHA256 keys held separately in encrypted storage. Two automated jobs run continuously: one verifies the hash chain every fifteen minutes, the other samples and re-verifies signatures hourly. A record cannot be altered after the fact without that tampering being detected automatically — this is what "audit trail" means as an evidentiary standard, not as a phrase.

Right to erasure comes with proof, not just an action. When an account is deleted under UK GDPR Article 17, CattleGrid generates a deletion certificate: a timestamped, itemised record of exactly what was erased, table by table, retained permanently as evidence. The certificate itself contains no personal data — only counts and identifiers — so it can be produced for a data subject or the ICO without creating a fresh disclosure risk.

Document uploads get the same governance as prompts. File uploads to AI tools are extracted, inspected against the same policy engine, and discarded — never stored. Coverage runs across PDF, Word (.doc/.docx), Excel spreadsheets, OpenDocument Text, and RTF. This closes a gap most DPOs haven't yet had to think about: a contract or a spreadsheet uploaded to summarise is exactly as exposed as a pasted paragraph, and now gets inspected the same way.

Reversible tokenisation, precisely scoped. Where a workflow genuinely needs the AI's output to reference a real client name or account number, CattleGrid can swap identifiers for tokens on the way out and restore the real values on the way back — the AI provider never sees the underlying value. There is no persistent key: the token map exists only in memory for that single request and is destroyed on every exit path. This is pseudonymisation under UK GDPR Article 4(5), not anonymisation — the data remains personal data throughout, and your organisation remains the controller of it. That distinction matters for your RoPA, and CattleGrid's own documentation states it plainly rather than blurring it.

Everything exports to where your governance work already happens. Compliance events stream to SIEM platforms (Splunk, Wazuh, Elastic) and GRC platforms (ServiceNow, Archer, MetricStream, and others), in CEF, Syslog, NDJSON, or webhook format, so the evidence CattleGrid generates lands inside the systems your team already uses to manage it.

What this looks like once it's running

You can answer "does our AI usage create an undocumented processor relationship" with a governance record, not a guess — what left, what was blocked, what was redacted, and when, for every AI interaction across the organisation. When a client's due-diligence questionnaire or an ICO enquiry asks you to demonstrate technical measures under Article 32, you have a timestamped answer rather than a policy document nobody can prove was followed.

What CattleGrid does not do

CattleGrid does not conduct or produce Data Protection Impact Assessments, maintain your Record of Processing Activities, or draft privacy notices — those remain judgement calls only you can make, informed by evidence CattleGrid provides. It does not advise on lawful basis, determine whether an incident meets the ICO notification threshold, or negotiate DPAs with AI providers on your behalf. It does not designate or substitute for a DPO function. And reversible tokenisation does not achieve anonymisation under Article 4(9): CattleGrid does not retain a re-identification key at any point — the token map is ephemeral and self-erasing, so there is nothing to escrow or rotate — but the data your organisation controls remains personal data throughout, and that responsibility stays yours.

Pricing →