The General Data Protection Regulation (Regulation (EU) 2016/679) is the EU’s primary data protection law governing processing of personal data relating to individuals in the EU/EEA, with extraterritorial reach in defined cases.
AI Compliance Intelligence
GDPR
European Union · privacy-law
All AI Compliance frameworks → · Official source →
Brel does not assert that any vendor holds this certification unless a company profile cites a verified trust-center or official disclosure.
Editorial overview
Scope
- Lawful bases for processing, purpose limitation, data minimization
- Data subject rights (access, erasure, portability, and others)
- Controller/processor obligations, DPIAs, international transfers, and breach notification
Relevance to AI products
AI systems that train on, infer from, or store personal data must account for GDPR principles, including transparency, purpose limitation, and special-category data rules. Model training and logging practices are frequent GDPR diligence topics for EU customers.
Limitations & caveats
- Compliance is fact-specific; certifications under Article 42 exist but are not a substitute for legal analysis
- Interacts with the EU AI Act for AI systems processing personal data
Related frameworks
Related technologies
Related glossary terms
Why it matters
GDPR is tracked so buyers and builders can understand official scope, issuing bodies, and AI-relevant obligations — without confusing marketing claims with verified attestation or legal status.
Last reviewed
Sources
Correction request
If a technology assignment or hub description is inaccurate, submit a correction via the Corrections Policy.
All technologies → · AI Models → · APIs & SDKs → · Integrations → · Compliance → · Browse all companies → · Explore industries → · Compare →