What GDPR means in practice
The General Data Protection Regulation is the EU's omnibus data-protection law, in force since 2018. The implications for AI are pervasive: lawful basis for processing applies to model training data, the right to explanation pressures black-box models, cross-border transfer restrictions push inference toward in-region or on-prem deployment, and the data-minimisation principle pushes against indiscriminate prompt logging. The UK GDPR is the post-Brexit equivalent and largely substantively identical. In sovereign AI deployments GDPR compliance is a design constraint, not a post-hoc check — the architecture choice to keep data and model inside the customer's perimeter is what satisfies the cross-border-transfer and processing-control questions.
Related terms
DPDP Act (India) →
India's Digital Personal Data Protection Act 2023, the country's first comprehensive data-protection law, with explicit treatment of health and financial data as a special category.
EU AI Act →
The European Union's AI Act — risk-tiered regulation of AI systems, with high-risk-system requirements that effectively mandate auditability, human oversight and conformity assessment.
Sovereign AI →
An architecture where customer data never leaves the network perimeter, model weights run on customer-controlled hardware, inference logs stay in the customer's SIEM, and the entire stack can operate air-gapped.
More in this category
All 62 terms, in plain language
Sovereign AI, RAG, agentic AI, IDP, MLOps and the regulations that shape enterprise AI.