🇪🇺 GDPR · Reg (EU) 2016/679
GDPR compliance scoping for AI products Free. 2 minutes. Engineer-led.
GDPR is the baseline for any AI system processing data of EU residents — regardless of where you incorporate. Get a clean list of articles, DPIA triggers, transfer mechanisms and breach SLAs that apply to your specific setup.
In scope
What this covers
- 01 Lawful basis (Art. 6 + Art. 9 for special-category data — health, biometric, political)
- 02 Data Protection Impact Assessment (Art. 35) — when triggered + the seven mandatory sections
- 03 Data-subject rights workflows on 1-month SLA (access, erasure, portability, rectification…)
- 04 Cross-border transfers — SCCs + Transfer Impact Assessment, or EU–US Data Privacy Framework path
- 05 Breach notification — 72-hour to supervisory authority, individual notice if high-risk
- 06 EU representative (Art. 27) for non-EU controllers + processor agreements (Art. 28)
- 07 Records of processing (Art. 30) and accountability documentation
For · CTO / Tech Lead / DPO at SaaS, medtech, fintech or HR-tech with EU users