TwinEthosRequest access

Catalog

EU GDPR (articles applied to AI data flows)

EU/EEA data protection supervisory authorities · pack 0.2.1 · verified against the official source as of 2026-09-30. AI-adjacent group: general privacy or biometric law, included only where AI data flows trigger it.

Binding law — in force

AI prompts and outputs must not be captured, stored or exposed beyond need by default (GDPR Art. 25(2))

The controller must ensure that, by default, only the personal data necessary for each purpose is processed, covering the amount collected, the extent of processing, the storage period and accessibility. For AI features the defaults that decide this are code and configuration: whether GenAI tracing captures full prompt and completion content, whether responses are stored at the provider, and how long conversations are kept. Detect content capture turned on by default in GenAI telemetry and provider-side storage requested without need.

eu-gdpr-ai-data.ai-data-minimal-by-default · GDPR Article 25(2) · official source · jurisdictions: EU

Binding law — in force

Name AI providers as recipients, and any transfer outside the EU, when collecting personal data (GDPR Art. 13(1)(e)-(f))

When personal data is collected from the data subject, the controller must, at that time, give the recipients or categories of recipients and, where applicable, the intended transfer to a third country with the adequacy decision or safeguards. When an app forwards what users type or upload to an AI provider, the provider is a recipient and often sits outside the EU. Detect an AI input surface (chat box, upload, voice capture) whose collection notice does not name AI providers as recipients or the transfer.

eu-gdpr-ai-data.ai-recipients-named-at-collection · GDPR Article 13(1)(e)-(f) · official source · jurisdictions: EU

Binding law — in force

Erasure must also delete a person's embeddings, vector entries and AI chat history (GDPR Art. 17(1))

When a data subject is entitled to erasure (for example the data is no longer necessary, consent is withdrawn, or the processing was unlawful), the controller must erase their personal data without undue delay. In AI features that data also lives in embeddings and vector-store entries, conversation history, agent memory, and files or threads stored with the model provider. Detect account or data deletion handlers that delete primary records but never reach those AI stores.

eu-gdpr-ai-data.erasure-reaches-ai-data-stores · GDPR Article 17(1) · official source · jurisdictions: EU

Binding law — in force

Send an AI model only the personal data the task needs (GDPR Arts. 5(1)(c) and 25(1))

Personal data must be adequate, relevant and limited to what is necessary for the purpose (data minimisation), and the controller must build measures such as pseudonymisation into the processing to implement that principle. Prompts, retrieval context, embedding inputs and AI telemetry are processing of the personal data they carry. Detect prompts or embedding inputs built by serializing a whole user, customer, account or profile object, with no field selection, redaction or pseudonymisation before the model call.

eu-gdpr-ai-data.minimise-personal-data-sent-to-ai · GDPR Article 5(1)(c) · official source · jurisdictions: EU