← All frameworks
Binding
GDPR
EU / national DPAs · Brussels, EU · effective 25 May 2018
The EU data-protection regime. For AI, Article 22 (automated decision-making), DPIAs for high-risk processing, and data-subject rights are the pressure points.
Your Council assistant — do it all here
You are interacting with an AI system.
Who must comply
- ▸Any org processing EU residents' personal data
- ▸AI systems making automated decisions about people
Penalties
Up to €20M or 4% of global annual turnover.
Key obligations
Lawful basis
Establish and document a lawful basis for processing.
Art. 22 safeguards
Human intervention & explanation for solely-automated decisions.
DPIA
Data Protection Impact Assessment for high-risk processing.
Data-subject rights
Access, rectification, erasure, portability, objection.
Sectors in scope
All sectors handling personal dataAdTechHRHealthcareFinance
Threats & cybersecurity it addresses
Unlawful profilingOpaque automated decisionsCross-border data misuse
Crosswalks — comply once, cover many
CSOAI Layer 0 mapping
Charter Art. 11, 12, 22, 33, 43, 47
Governed MCP tools — open source, pip/npx install