AIXYRA
All Frameworks
PrivacyIn force since May 2018. Fines up to EUR 20 million or 4% of global turnover.

GDPR

EU General Data Protection Regulation (Regulation (EU) 2016/679)

The EU's data protection law — and a de facto AI regulation wherever models train on or process personal data, or make automated decisions about people.

99 individual requirements seeded and assessable in AIXYRA.

GDPR predates the current AI wave, but it governs much of it: lawful basis for processing training and inference data, purpose limitation, data minimization, transparency about automated decision-making (Article 22), and data protection impact assessments (Article 35) for high-risk processing. AI systems that touch personal data inherit all of it.

For AI governance teams, the GDPR question is traceability: which systems process personal data, on what basis, flowing from which data sources, with what safeguards. Answering it requires knowing your AI estate and its data dependencies — not just having a privacy policy.

Who it applies to

Any organization processing personal data of people in the EU — controllers and processors alike, wherever the organization is based.

Key requirement themes

Lawful basis & purpose limitation

Every AI use of personal data needs a lawful basis, and data collected for one purpose cannot silently feed another model.

Automated decision-making (Article 22)

Decisions with legal or similarly significant effects require safeguards, transparency, and routes to human review.

Impact assessments (Article 35)

High-risk processing — common in AI — triggers documented data protection impact assessments.

Data subject rights & consent

Access, erasure, and consent management must reach into AI pipelines, including the data sources feeding them.

Orientation for evaluators — not legal advice. Consult counsel for obligations specific to your organization.

How AIXYRA helps

  • Data source registry and architecture graphs show which AI systems consume which data — the traceability GDPR analysis needs
  • Assessments map AI systems to seeded GDPR articles with evidence, alongside EU AI Act mappings in the same pass
  • Optional data-scanning features are consent-gated and revocable, applying GDPR discipline to the platform itself
  • Risk scoring weighs data sensitivity as a first-class dimension, so personal-data systems surface for review

GDPR FAQ

How does GDPR apply to AI systems?

Wherever an AI system trains on or processes personal data, GDPR applies in full: lawful basis, purpose limitation, transparency, impact assessments for high-risk processing, and Article 22 safeguards for significant automated decisions. It operates alongside the EU AI Act, not instead of it.

Can one assessment cover GDPR and the EU AI Act together?

In AIXYRA, yes — an entity's compliance assessment maps to articles from every enabled framework simultaneously, so evidence gathered once serves GDPR, the EU AI Act, and the other built-in frameworks without parallel programs.

Assess your AI systems against GDPR

GDPR ships built into AIXYRA — and the same assessment maps to every other enabled framework at once.