← All frameworks
Binding

GDPR

EU / national DPAs · Brussels, EU · effective 25 May 2018

The EU data-protection regime. For AI, Article 22 (automated decision-making), DPIAs for high-risk processing, and data-subject rights are the pressure points.

Who must comply
  • Any org processing EU residents' personal data
  • AI systems making automated decisions about people
Penalties

Up to €20M or 4% of global annual turnover.

Key obligations
Lawful basis
Establish and document a lawful basis for processing.
Art. 22 safeguards
Human intervention & explanation for solely-automated decisions.
DPIA
Data Protection Impact Assessment for high-risk processing.
Data-subject rights
Access, rectification, erasure, portability, objection.
Sectors in scope
All sectors handling personal dataAdTechHRHealthcareFinance
Threats & cybersecurity it addresses
Unlawful profilingOpaque automated decisionsCross-border data misuse
Crosswalks — comply once, cover many
CSOAI Layer 0 mapping

Charter Art. 11, 12, 22, 33, 43, 47

Governed MCP tools — open source, pip/npx install