Compliance
GDPR
Lawful processing and data minimization for AI. Evidence of what was collected, kept, and deleted.
At a glance
Who this covers, and who enforces it
Any organization processing the personal data of people in the EU through an AI system, including automated decision-making under Article 22.
- Instrument
- Regulation (EU) 2016/679 — binding law
- Enforced by
- National DPAs, coordinated by the EDPB
- In force
- 25 May 2018
- Max penalty
- €20M or 4% of global turnover
- AI hook
- Article 22 — automated decision-making
Requirements
What it asks for
- 1Lawful basis and data minimization
- 2Explanation for automated decisions
- 3Defined data retention limits
- 4Data subject access and deletion requests
Evidence mapping
What PRISM records against each requirement
Every plan records this evidence as your AI runs. Compliance Reports, which turn it into a reviewed, framework-mapped report, are delivered as a service, on request.
- Lawful basis & minimization
- Knowledge Base and Model Inventory show what data feeds each system.
- Automated-decision explanation
- Traces reconstruct exactly what a system saw and produced for any one decision.
- Retention limits
- Credits and Export & Audit show what is kept, for how long, and let it be exported or deleted.
- Data subject access
- Sessions let a team pull every trace tied to one user on request.
Primary source
Read the actual text
Everything on this page is drawn from Regulation (EU) 2016/679 (GDPR). The capture is live, not a paraphrase — go straight to the source and check us.

Evidence, not certification
This page describes GDPR’s publicly available requirements and how PRISM’s evidence layer supports them. It is not legal advice, and it does not constitute certification, regulatory approval, or a guarantee of compliance. GDPR compliance remains your organization’s responsibility, in consultation with qualified counsel.
Keep reading
Ask us about your framework
Tell us how GDPR applies to your systems and we'll show you the evidence path.