azyware
Private AI & complianceStandard / regulation

GDPR

Also: General Data Protection Regulation, EU data protection

In one sentence

What is GDPR?

GDPR is the European Union's data-protection regulation, governing how personal data of people in the EU is collected, processed and transferred, with direct consequences for how AI systems handle that data.

What GDPR means

The General Data Protection Regulation applies to any organisation processing personal data of individuals in the EU, regardless of where the organisation sits. It defines controllers (who decide the purpose) and processors (who act on their behalf), requires a lawful basis for each processing activity, and grants individuals rights including access, rectification, erasure, portability and objection to automated decision-making.

For AI systems, several provisions bite directly. Data minimisation limits what goes into prompts and training sets. The right to erasure must extend to derived data such as embeddings and logs. Automated decisions with legal or similarly significant effects require human involvement and explanation. Transfers outside the EU need an approved mechanism, which affects where models and vector stores are hosted.

GDPR is often confused with a cookie-consent requirement; it is much broader. It is also distinct from the EU AI Act, which regulates AI systems by risk category. GDPR governs the personal data an AI system touches; the AI Act governs the system itself. An Indian company serving UK or EU customers is in scope, and UK GDPR applies separately post-Brexit with largely parallel rules.

Who it really matters to

  • Compliance officer: defines lawful basis, records of processing and data-protection impact assessments that any AI feature touching EU users must have.
  • CTO / Head of Engineering: dictates hosting region, transfer mechanisms and the technical ability to erase a person's data from every store.
  • Product manager: automated decisions affecting users need explanation and a human review route, which shapes the product design.
  • Founder / CEO: EU and UK enterprise buyers will not sign without evidence of GDPR-aligned processing, making it a sales prerequisite.

Why it exists

GDPR exists to give individuals control over their personal data and to make organisations accountable for how they use it, with penalties large enough to change behaviour. For AI builders it solves a real problem: it forces a clear answer to what data is used, why, and how it can be removed, which is exactly what buyers and auditors ask. The trade-off is that features which are trivial in an unregulated setting, such as storing full conversation histories or training on user content, need a documented basis, retention limits and deletion plumbing. Designing for GDPR from the start is cheaper than remediating a live system.

Where it is applied

  • A SaaS company serving EU tenants hosting its AI copilot backend in an EU region and documenting the transfer basis for any hosted model calls.
  • A retailer running personalisation on EU customers with a documented legitimate-interest assessment and an easy opt-out.
  • A fintech providing human review and explanation for AI-assisted credit decisions affecting EU applicants.
  • A healthcare platform treating patient data as a special category and applying stricter consent before any AI processing.
  • An Indian services firm acting as a processor for UK clients, with data-processing agreements and sub-processor lists covering every AI vendor used.

Is GDPR a skill?

Standard / regulationA regulation to comply with, not a capability you build once. Eazyware builds erasure paths, region pinning and human-review routes into AI systems for EU and UK clients, primarily through Private Agentic AI, and documents the evidence buyers ask for.

Eazyware service that covers it: Agentic AI Solutions (self-hosted). Starting prices are on the pricing page.

Frequently asked questions

Does GDPR apply to an Indian company building AI for EU clients?

Yes. GDPR applies based on whose data is processed, not where the processor sits. An Indian company handling EU personal data is typically a processor and must sign a data-processing agreement, support the client's obligations and respect transfer rules.

Can we train models on EU user data under GDPR?

Only with a lawful basis, typically consent or a documented legitimate-interest assessment, and with minimisation and erasure handled. Training on data collected for another purpose without a compatible basis is a common failure. Anonymised data is outside scope if anonymisation is real.

Related reading

Need GDPR built, not just explained?

PRJECT IN MIND?