Skip to content

Compliance

GDPR

Lawful processing and data minimization for AI. Evidence of what was collected, kept, and deleted.

At a glance

Who this covers, and who enforces it

Any organization processing the personal data of people in the EU through an AI system, including automated decision-making under Article 22.

GDPRFramework
Instrument
Regulation (EU) 2016/679 — binding law
Enforced by
National DPAs, coordinated by the EDPB
In force
25 May 2018
Max penalty
€20M or 4% of global turnover
AI hook
Article 22 — automated decision-making

Requirements

What it asks for

  • 1Lawful basis and data minimization
  • 2Explanation for automated decisions
  • 3Defined data retention limits
  • 4Data subject access and deletion requests

Evidence mapping

What PRISM records against each requirement

Every plan records this evidence as your AI runs. Compliance Reports, which turn it into a reviewed, framework-mapped report, are delivered as a service, on request.

GDPR
Lawful basis & minimization
Knowledge Base and Model Inventory show what data feeds each system.
Automated-decision explanation
Traces reconstruct exactly what a system saw and produced for any one decision.
Retention limits
Credits and Export & Audit show what is kept, for how long, and let it be exported or deleted.
Data subject access
Sessions let a team pull every trace tied to one user on request.

Primary source

Read the actual text

Everything on this page is drawn from Regulation (EU) 2016/679 (GDPR). The capture is live, not a paraphrase — go straight to the source and check us.

gdpr-info.eu
Capture of Regulation (EU) 2016/679 (GDPR)
Live capture, 24 Aug 2026Open the source ↗

Evidence, not certification

This page describes GDPR’s publicly available requirements and how PRISM’s evidence layer supports them. It is not legal advice, and it does not constitute certification, regulatory approval, or a guarantee of compliance. GDPR compliance remains your organization’s responsibility, in consultation with qualified counsel.

Ask us about your framework

Tell us how GDPR applies to your systems and we'll show you the evidence path.