OpenAI 2026 hackathon

Article30

Scans your codebase, finds every field of personal data, traces where it flows and drafts the GDPR Article 30 register your company is legally required to have and probably doesn't.

Solo project by Sandeep Makhija · 1 likes · 0 comments

Archive position — measured, not model output

1 like on Devpost

506 of the 7,856 archived projects have more likes, and 1,758 share exactly 1 — so this project's #628 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

What the company appears to be: Article30 is a self-reported tool that scans codebases for personal data fields, traces their flow, and drafts GDPR Article 30 register reports. It claims to automate a compliance task that is currently done manually by stale spreadsheets.

What changed: The author states they built this in a single Codex session using GPT-5.6 Terra, with an architecture defined via one detailed prompt. They claim the tool uses GPT-5.6 for both building and classifying data fields.

Single most important open question: Is there any evidence of actual usage or adoption beyond the author's own development environment?

Back to contents

What The Product Actually Is

The description states that Article30 is a tool that:

  • Scans code repositories
  • Identifies personal data fields in database schemas and models
  • Uses GPT-5.6 to semantically classify these fields into categories (identity, contact, financial, special category)
  • Traces where the data flows to third parties or across borders
  • Detects leaks (e.g., personal data in logs)
  • Generates a draft Article 30 register as HTML and JSON

It is described as a draft generator, not legal advice.

Evidence: The author's own write-up. No external verification.

Inference: The tool appears to be built using AI-assisted development with Codex and GPT-5.6 for both code generation and classification logic.

Back to contents

Positioning & Claim Evolution

The description states that Article30 addresses a compliance problem:

  • GDPR Article 30 requires organisations processing personal data in the EU to maintain a Record of Processing Activities.
  • This register is typically maintained as a stale spreadsheet, not updated with code changes.
  • The tool reads existing code and automates what would otherwise be a manual process.

It positions itself as solving an unenjoyable but necessary task — one that no one wants to own.

Evidence: Self-reported by the author. No third-party validation or market positioning data provided.

Inference: The product is positioned as a compliance automation tool for developers and DPOs, aiming to reduce manual effort in maintaining GDPR records.

Back to contents

Target Customer & ICP

The description implies that Article30 targets:

  • Organisations processing personal data in the EU
  • Compliance officers (DPOs)
  • Developers who manage codebases with personal data

It is not clear if it targets specific industries or company sizes, nor whether there are distinct buyer personas.

Evidence: The author's own write-up. No explicit segmentation or customer profile provided.

Inference: Likely aimed at mid-to-large tech companies or startups that must comply with GDPR and have codebases containing personal data.

Back to contents

Business Model & Pricing Evidence

The description does not state anything about pricing, monetisation, or business model.

It is unclear if the tool will be offered as a SaaS product, open-source, or otherwise.

Evidence: Not evidenced.

Inference: No evidence of any commercial structure beyond the author's own development effort.

Back to contents

Technical & Delivery Signals

The description states:

  • Built using Codex with GPT-5.6 Terra
  • Uses FastAPI for a web UI
  • Implements a four-stage engine: scanner → classifier → flow tracer → report generator
  • Uses regex and GPT-5.6 for classification
  • Includes response caching to ensure determinism in classifications
  • Has verification mechanisms built into the build process (e.g., planted leaks, ambiguous fields)
  • The author claims Codex delivered a runnable skeleton with passing tests in under an hour

Evidence: Self-reported by the author.

Inference: The tool is AI-assisted in both development and execution. It uses structured output from GPT-5.6 for classification and has some built-in verification logic to ensure correctness.

Back to contents

Traction & Maturity Signals

There is no evidence of any traction, revenue, customers, or adoption beyond the author’s own development.

The project was submitted to a hackathon (OpenAI 2026), suggesting it is early-stage.

Evidence: Not evidenced.

Inference: The tool appears to be in an experimental or prototype phase, with no known users or market validation.

Back to contents

Competitive Context

The description does not mention any competitors or existing solutions in the GDPR compliance space.

It also doesn’t describe how Article30 compares technically or functionally to other tools.

Evidence: Not evidenced.

Inference: No competitive landscape is described. The author does not reference similar tools or platforms.

Back to contents

Key Risks & Red Flags

  • Unverified claims: All evidence is self-reported and unverified.
  • No traction or adoption: No customers, revenue, or usage data.
  • AI dependency: Heavy reliance on GPT-5.6 for both building and running the tool raises questions about scalability, cost, and availability.
  • Limited scope: The tool only generates drafts; it is not legal advice or a full compliance system.
  • Hackathon origin: Submitted to a hackathon suggests early-stage development with no commercial traction.

Evidence: Not evidenced.

Inference: Risks include lack of real-world testing, overreliance on AI models, and absence of any business model or product-market fit evidence.

Back to contents

Diligence Questions To Ask The Founders

  1. What is the actual accuracy rate of GPT-5.6 in classifying personal data fields?
  2. How does the tool handle false positives or ambiguous classifications?
  3. Has the tool been tested on real-world codebases beyond the sample fixture?
  4. Are there any plans for CI/CD integration or enterprise deployment?
  5. What is the long-term vision for monetisation or product evolution?
  6. Is there a plan to support other EU regulations beyond GDPR?

Back to contents

Investment/Partnership Verdict

Not evidenced.

The description provides no information on:

  • Revenue
  • Customers
  • Traction
  • Market size
  • Financials
  • Team structure beyond one person
  • Product-market fit or competitive positioning

This is a self-reported, unverified project submitted to a hackathon. There is no evidence of any commercial activity or product traction.

Confidence level: Low. The entire analysis is based on the author’s own description, which is not independently verified.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.