The GDPR watch points for an AI system
Legal basis & purpose
Every processing operation must rest on a legal basis (a public interest task for a local authority) and on a specified purpose. The AI assistant must have a documented scope of use.
Impact assessment (DPIA)
An innovative technology processing sensitive data on a large scale triggers the DPIA obligation (art. 35). To be carried out before going live, together with the DPO.
Right to erasure inside a RAG
In a RAG system, a document is split into vectorised fragments. Deleting the file is not enough: you need a procedure that also purges the vectors and the histories. A technical point that we industrialise.
Minimisation & retention
Process only what is necessary, and define retention periods. Our GPU instances are stateless and wiped daily: structural minimisation.
Processors (art. 28)
A clear contractual chain between the data controller, the provider and the hosting companies. EU hosting means no transfer outside the Union to be framed.
Where your data lives inside a RAG
An indexed document is split and then vectorised into the database. Deleting the source file removes neither the vectors nor the histories: erasure (art. 17 GDPR) must purge the entire chain.
How a sovereign AI helps
- ✓ Data hosted in the EU, under European law alone
- ✓ Minimisation by design (ephemeral instances, daily wipe)
- ✓ Documentation ready for the DPO and the DPIA
- ✓ Data anonymisation when third-party APIs are used
Official sources
- Regulation (EU) 2016/679 (GDPR): full text on EUR-Lex
The official text of the general data protection regulation.
- CNIL: Artificial intelligence
Recommendations from the CNIL on AI and personal data (practical factsheets, generative AI).
- CNIL: The data protection impact assessment (DPIA)
When and how to carry out a DPIA (art. 35 GDPR).
An AI project that is compliant from day one
We supply the compliance documentation and support your DPO. See also the EU AI Act.
Discuss your compliance