AI Compliance Intelligence

GDPR

European Union · privacy-law

IssuerEuropean Union
Categoryprivacy-law
Reviewed

All AI Compliance frameworks → · Official source →

Brel does not assert that any vendor holds this certification unless a company profile cites a verified trust-center or official disclosure.

Editorial overview

The General Data Protection Regulation (Regulation (EU) 2016/679) is the EU’s primary data protection law governing processing of personal data relating to individuals in the EU/EEA, with extraterritorial reach in defined cases.

Scope

  • Lawful bases for processing, purpose limitation, data minimization
  • Data subject rights (access, erasure, portability, and others)
  • Controller/processor obligations, DPIAs, international transfers, and breach notification

Relevance to AI products

AI systems that train on, infer from, or store personal data must account for GDPR principles, including transparency, purpose limitation, and special-category data rules. Model training and logging practices are frequent GDPR diligence topics for EU customers.

Limitations & caveats

  • Compliance is fact-specific; certifications under Article 42 exist but are not a substitute for legal analysis
  • Interacts with the EU AI Act for AI systems processing personal data

Related frameworks

Related technologies

Related glossary terms

Why it matters

GDPR is tracked so buyers and builders can understand official scope, issuing bodies, and AI-relevant obligations — without confusing marketing claims with verified attestation or legal status.

Last reviewed

Sources

Correction request

If a technology assignment or hub description is inaccurate, submit a correction via the Corrections Policy.

All technologies → · AI Models → · APIs & SDKs → · Integrations → · Compliance → · Browse all companies → · Explore industries → · Compare →