FastGrowth Fashion Ltd
Fast Fashion E-CommerceAI Systems Audited
Key Challenges Identified
Data leakage via ChatGPT: Staff using free tier ChatGPT were inputting customer names, order details, and complaint information — data that OpenAI could use for training.
No AI usage policy: No documented guidelines on which AI tools were approved or how they should be used with customer data.
Klaviyo segmentation concerns: AI-driven customer segmentation potentially using sensitive inference without proper legal basis.
No DPIAs conducted: Despite processing EU customer data through AI systems, no Data Protection Impact Assessments had been completed.
Audit Findings
Recommendations Delivered
- Immediate: Migrate from ChatGPT free tier to ChatGPT Team/Enterprise with data protection agreements
- 30 days: Implement AI Usage Policy covering all approved tools and data handling requirements
- 60 days: Complete DPIAs for Klaviyo and Gorgias AI processing EU customer data
- 90 days: Update privacy policy with AI disclosure and establish vendor assessment process