Regulation

GDPR: minimisation that runs, accountability that holds up

Most GDPR work happens in documents. The part that runs in production is minimisation, access control, oversight and evidence. AI-FW is where those four become configuration rather than intent.

The instrument
Regulation (EU) 2016/679
Status
In force
Who it applies to
Controllers and processors whose AI use cases touch personal data, including special-category data.

Where AI-FW fits

GDPR is a set of controller and processor obligations. AI-FW is a technical and organisational measure under Article 32 and an instrument for the principles in Article 5. It cannot establish a lawful basis, sign a data processing agreement, or decide your retention periods. What it can do is enforce and evidence the decisions you have made.

What stays with you

Read this list first. It is the boundary of what a product can do for you, and it is where the remaining work sits.

  • Choosing a lawful basis, or completing the data protection impact assessment
  • Signing data processing agreements, or approving transfer mechanisms and assessments
  • Deciding retention periods, which stay a policy decision you make and the product then enforces
  • Executing erasure in your source systems, though the logs let you locate the records
  • Deciding whether a breach is notifiable within 72 hours: AI-FW supplies the timeline, not the judgement

What the framework asks, and what the product does

The obligations that touch the AI path, paired with the capability that answers each one. Everything else in this framework is organisational work, listed above.

Minimisation and storage limitation
What it asks

Personal data must be adequate, relevant and kept no longer than necessary

What AI-FW does

Detection and masking of personal-data classes on the way in, retention settings you set, and purge behaviour that is recorded rather than assumed

Integrity and confidentiality
What it asks

Appropriate security of processing

What AI-FW does

Role-based access, identity-bound API keys, mutual TLS for agents and TLS in transit, with a non-root container as the default posture

Accountability
What it asks

You must be able to demonstrate what you did

What AI-FW does

Every enforcement change is audited: who enabled, disabled or edited a rule, what changed, and when

Lawful basis and special categories
What it asks

Special-category data needs a stricter basis and stronger safeguards

What AI-FW does

A special-category rule pack covering health, biometric, political, religious and sexual-orientation signals, set to block or mask per your policy

Transparency
What it asks

Notices must describe the processing that actually happens

What AI-FW does

An inventory of models, agents and data categories crossing the gateway, so the notice reflects reality instead of the design document

Subject access and erasure
What it asks

You must be able to find and remove personal data on request

What AI-FW does

Searchable activity and audit records by subject identifier, so you can locate where data travelled before you act on it

Automated decisions
What it asks

Significant automated decisions need safeguards and, often, human involvement

What AI-FW does

Approval gates that route sensitive actions to a person, with the decision recorded against an identity

Processors and transfers
What it asks

You must know which processors touch personal data, and where it goes

What AI-FW does

A model inventory that enumerates every provider and endpoint, and records which data categories each one received

A rule pack to start from

The enforcement that makes the controls real. Severity runs 1 to 5, and a rule that is switched off reports as a gap, so these are meant to be live from day one.

Email, phone, national identifier and bank-account patternsInboundMaskSeverity 4

Minimisation: what never crosses cannot be misused downstream

Special-category terms (health, biometrics, political, religious, sexual orientation)InboundBlockSeverity 5

Article 9 data, set to block or mask according to your policy

Bulk identifiers or key material leaving toward a providerOutboundBlockSeverity 5

Exfiltration looks like a normal request until it does not

Prompt injection and data-exfiltration attemptsInboundBlockSeverity 4

Confidentiality of the data you do allow through

Unapproved model or endpointInboundBlockSeverity 3

Keeps the processor inventory and the DPA register honest

What the evidence pack contains

Per period, and without prompt or response content, which is what makes it safe to hand over.

  • Masking rule statePresent, enabled, and with the expected action
  • Retention valuesMatching your documented schedule
  • Approval countsOversight of decisions with legal or significant effect
  • Model and category inventoryThe processing your notice has to describe
  • Manifest hashProves which control set produced the pack

Customer responsibilities and sources

Yours to run
  • Establish the lawful basis for each processing purpose and complete a data protection impact assessment where the processing is high risk.
  • Keep your record of processing activities current, with data processing agreements for every processor in the model inventory.
  • Operate the data-subject request process, including erasure in source systems according to your retention rules.
  • Decide whether an incident is notifiable, and make the 72-hour call: AI-FW supplies the timeline, not the decision.
  • Appoint a data protection officer where required, train staff, and review the model inventory against the processor register.

Common questions

It is a technical and organisational measure that you run, so what matters is your deployment model and your own role assessment. What we can say plainly: the product does not establish a lawful basis, cannot sign a data processing agreement on your behalf, and does not decide retention. Those stay with you, and your counsel decides how to characterise the arrangement.

It gives you a searchable record of which identity sent which category of data to which model, and when. That is what you need to locate records and to answer where data went. Erasure itself happens in your source systems and in the logs according to your retention rules.

Metadata is the default: identity, model, decision, rule, latency and outcome. Content capture is a policy choice, and when it is on, masking applies and the retention clock is yours. Evidence packs never include payloads, which is the point of them.

Validate it yourself with our Technical Plan

Ask us to run this framework against your own environment: the rules that would be created, what the assessment reports, and what the evidence pack contains for a real period.

This page maps product capabilities to published expectations. It is not legal, audit or certification advice, and it creates no compliance representation. Applicability and sufficiency are judgements for your counsel and, where relevant, your auditor, assessor or certification body. Framework details are current as reviewed; check the primary sources above, and the page itself, before relying on a date or a threshold.