Home · Glossary · GDPR
Enterprise AI glossary · Compliance & Regulation

GDPR

The EU's General Data Protection Regulation — sets the rules for processing personal data of EU residents, with significant implications for AI systems that touch that data.

Definition

What GDPR means in practice

The General Data Protection Regulation is the EU's omnibus data-protection law, in force since 2018. The implications for AI are pervasive: lawful basis for processing applies to model training data, the right to explanation pressures black-box models, cross-border transfer restrictions push inference toward in-region or on-prem deployment, and the data-minimisation principle pushes against indiscriminate prompt logging. The UK GDPR is the post-Brexit equivalent and largely substantively identical. In sovereign AI deployments GDPR compliance is a design constraint, not a post-hoc check — the architecture choice to keep data and model inside the customer's perimeter is what satisfies the cross-border-transfer and processing-control questions.

Go deeper
EU AI Act compliance architecture →

All 62 terms, in plain language

Sovereign AI, RAG, agentic AI, IDP, MLOps and the regulations that shape enterprise AI.

Browse the glossary →Talk to an engineer →