TwinEthosRequest access

Law

EU GDPR (articles applied to AI data flows)

EU/EEA data protection supervisory authorities · European Union (EU) · 5 provisions encoded · verified against the official source as of 2026-09-30.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

AI-adjacent law General privacy or biometric law, included only where AI data flows trigger it; reported apart from AI-specific law.

Official text: publications.europa.eu.

Binding law — in force AI-adjacent law

AI prompts and outputs must not be captured, stored or exposed beyond need by default (GDPR Art. 25(2))

GDPR Article 25(2) · official text · In force: applies since 25 May 2018 · European Union (EU)

The controller must ensure that, by default, only the personal data necessary for each purpose is processed, covering the amount collected, the extent of processing, the storage period and accessibility. For AI features the defaults that decide this are code and configuration: whether GenAI tracing captures full prompt and completion content, whether responses are stored at the provider, and how long conversations are kept. Detect content capture turned on by default in GenAI telemetry and provider-side storage requested without need.

Who it applies to

  • Duty falls on: controller
  • Controllers running AI features that process personal data of people in the EU. Applies since 2018-05-25.

The guard to add

Turn off prompt and completion content capture in GenAI tracing, send store=False to the provider, and set a retention limit on stored conversations by default.

Set the defaults in the configuration that ships to production: OTEL_INSTRUMENTATION_GENAI_CAPTURE_MESSAGE_CONTENT false or unset, TRACELOOP_TRACE_CONTENT=false (Traceloop captures content when it is unset), and LANGSMITH_HIDE_INPUTS and LANGSMITH_HIDE_OUTPUTS true, or a masking function, whenever LangSmith tracing is on. Model calls pass store=False unless a documented feature needs provider-side storage (the OpenAI Responses API stores by default). Stored conversations carry a retention period enforced by a TTL or purge job, and any wider capture is an explicit opt-in scoped to a debugging environment or a sampled, masked subset.

Where it goes: 2 data models, 3 config and feature flags, 8 model configuration, 10 logs and telemetry.

Example (Production .env), before:

OTEL_INSTRUMENTATION_GENAI_CAPTURE_MESSAGE_CONTENT=true
LANGSMITH_TRACING=true

After:

OTEL_INSTRUMENTATION_GENAI_CAPTURE_MESSAGE_CONTENT=false
TRACELOOP_TRACE_CONTENT=false
LANGSMITH_TRACING=true
LANGSMITH_HIDE_INPUTS=true
LANGSMITH_HIDE_OUTPUTS=true

Control: AI inputs and outputs retained or exposed by default. The same guard addresses 1 item with binding law in 1 jurisdiction. Engineering guidance, not legal advice.

Rule id eu-gdpr-ai-data.ai-data-minimal-by-default · review status: primary source derived

Binding law — in force AI-adjacent law

Name AI providers as recipients, and any transfer outside the EU, when collecting personal data (GDPR Art. 13(1)(e)-(f))

GDPR Article 13(1)(e)-(f) · official text · In force: applies since 25 May 2018 · European Union (EU)

When personal data is collected from the data subject, the controller must, at that time, give the recipients or categories of recipients and, where applicable, the intended transfer to a third country with the adequacy decision or safeguards. When an app forwards what users type or upload to an AI provider, the provider is a recipient and often sits outside the EU. Detect an AI input surface (chat box, upload, voice capture) whose collection notice does not name AI providers as recipients or the transfer.

Who it applies to

  • Duty falls on: controller
  • Controllers collecting personal data from people in the EU through features that send it to an AI provider. Whether the provider is a processor named by category or must be named individually, and whether a transfer occurs, depend on contracts and hosting outside the code. Applies since 2018-05-25.
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Show a notice at each AI input (chat box, upload, voice capture) that names the AI providers receiving the data and any transfer abroad, linked to the full privacy notice.

Next to every control where users type, upload, or speak into an AI feature, render a short notice that their input is sent to the named AI provider (or the category 'AI model providers'), linked to the privacy-notice section that lists each provider as a recipient, where it processes data, and the transfer mechanism (adequacy decision or standard contractual clauses). Drive both from one provider registry that the code also uses to configure model clients, so adding or switching a provider updates the notice. The notice appears at the point of collection, not only on a policy page users may never reach.

Where it goes: 1 application source code, 3 config and feature flags, 12 repository artifacts, 14 user-facing text.

What this provision adds:

  • Give the recipient information at the time the data is collected, and where data leaves the EU, state the transfer and the adequacy decision or safeguards relied on.

Example (Next.js + Vercel AI SDK (useChat)), before:

<form onSubmit={handleSubmit}>
  <textarea value={input} onChange={handleInputChange} />
  <button type="submit">Send</button>
</form>

After:

<form onSubmit={handleSubmit}>
  <textarea value={input} onChange={handleInputChange} aria-describedby="ai-recipient-notice" />
  <p id="ai-recipient-notice">
    Your messages are sent to {AI_PROVIDERS.chat.name} ({AI_PROVIDERS.chat.region}) to generate replies.{' '}
    <a href="/privacy#ai-providers">Recipients and transfers</a>
  </p>
  <button type="submit">Send</button>
</form>

Control: AI providers not named as recipients when personal data is collected. The same guard addresses 1 item with binding law in 1 jurisdiction. Engineering guidance, not legal advice.

Rule id eu-gdpr-ai-data.ai-recipients-named-at-collection · review status: primary source derived

Binding law — in force AI-adjacent law

Erasure must also delete a person's embeddings, vector entries and AI chat history (GDPR Art. 17(1))

GDPR Article 17(1) · official text · In force: applies since 25 May 2018 · European Union (EU)

When a data subject is entitled to erasure (for example the data is no longer necessary, consent is withdrawn, or the processing was unlawful), the controller must erase their personal data without undue delay. In AI features that data also lives in embeddings and vector-store entries, conversation history, agent memory, and files or threads stored with the model provider. Detect account or data deletion handlers that delete primary records but never reach those AI stores.

Who it applies to

  • Duty falls on: controller
  • Controllers holding personal data of people in the EU in AI stores (vector databases, chat history, agent memory, provider-stored files). Art. 17(3) exceptions (legal obligation, legal claims, archiving and research) can justify keeping some data. Applies since 2018-05-25.

The guard to add

Make the account-deletion handler also delete the person's vector entries, embeddings, chat history, agent memory and provider-stored files or conversations.

Extend the erasure path (DELETE /account, delete_user, the data-subject-request worker) so that after the primary records it deletes everything keyed to the person in AI stores: vector-store entries by id, metadata filter or per-user namespace, conversation and chat-history tables, agent memory and checkpoints, and files, vector-store files, threads or conversations held with the model provider. This requires writing the user id as metadata on every vector and recording every provider object id at creation, so the deletion can find them. Where a legal hold or retention exception applies, skip only the covered items and record the reason; log which stores were erased.

Where it goes: 1 application source code, 2 data models, 6 API calls and integrations.

What this provision adds:

  • Run the erasure across the AI stores without undue delay once the person is entitled to it (for example the data is no longer necessary, consent is withdrawn, or the processing was unlawful).
  • Keep AI-store data only where an Art. 17(3) exception applies (legal obligation, legal claims, archiving and research), and record which exception on the retained items.

Example (FastAPI + Chroma + OpenAI SDK), before:

@app.delete('/account')
def delete_account(user=Depends(current_user)):
    db.users.delete(user.id)
    return {'status': 'deleted'}

After:

@app.delete('/account')
def delete_account(user=Depends(current_user)):
    db.users.delete(user.id)
    collection.delete(where={'user_id': user.id})          # Chroma embeddings
    db.chat_messages.delete_for_user(user.id)              # conversation history
    for f in db.provider_files.for_user(user.id):
        client.files.delete(f.file_id)                      # files stored with OpenAI
    for c in db.provider_conversations.for_user(user.id):
        client.conversations.delete(c.conversation_id)
    erasure_log.record(user.id, stores=['chroma', 'chat', 'openai_files', 'openai_conversations'])
    return {'status': 'deleted'}

Control: Data erasure does not reach embeddings, vector stores or AI chat history. The same guard addresses 1 item with binding law in 1 jurisdiction. Engineering guidance, not legal advice.

Rule id eu-gdpr-ai-data.erasure-reaches-ai-data-stores · review status: primary source derived

Binding law — in force AI-adjacent law

Send an AI model only the personal data the task needs (GDPR Arts. 5(1)(c) and 25(1))

GDPR Article 5(1)(c) · official text · In force: applies since 25 May 2018 · European Union (EU)

Personal data must be adequate, relevant and limited to what is necessary for the purpose (data minimisation), and the controller must build measures such as pseudonymisation into the processing to implement that principle. Prompts, retrieval context, embedding inputs and AI telemetry are processing of the personal data they carry. Detect prompts or embedding inputs built by serializing a whole user, customer, account or profile object, with no field selection, redaction or pseudonymisation before the model call.

Who it applies to

  • Duty falls on: controller
  • Controllers that send personal data of people in the EU to AI models (hosted or self-run), embedding services or AI telemetry. Applies since 2018-05-25.

The guard to add

Build prompts, retrieval context and embedding inputs from an explicit per-task field allowlist or pseudonymised data, never a serialized whole user record.

In each prompt builder, retrieval formatter and embedding job, select only the fields the task needs (an allowed_fields projection, pydantic model_dump(include=...), or a typed DTO), replace direct identifiers with a pseudonymous id where the task does not need them, and redact PII in free text such as tickets or notes (for example Presidio AnalyzerEngine and AnonymizerEngine). Never pass json.dumps(user), JSON.stringify(customer), vars(profile) or account.model_dump() into a model or embedding call. Apply the same selection to what AI telemetry and prompt logs capture.

Where it goes: 7 prompt construction, 1 application source code, 10 logs and telemetry.

Example (Python + OpenAI SDK), before:

user = db.get_user(uid)
prompt = 'Suggest a plan upgrade for this customer: ' + json.dumps(user)
resp = client.chat.completions.create(model=MODEL, messages=[{'role': 'user', 'content': prompt}])

After:

ALLOWED_FIELDS = ('plan', 'monthly_usage_gb', 'tenure_months')
user = db.get_user(uid)
facts = {k: user[k] for k in ALLOWED_FIELDS}        # no name, email, address
prompt = 'Suggest a plan upgrade for this customer: ' + json.dumps(facts)
resp = client.chat.completions.create(model=MODEL, messages=[{'role': 'user', 'content': prompt}])

Control: Whole personal-data records sent to an AI model. The same guard addresses 1 item with binding law in 1 jurisdiction. Engineering guidance, not legal advice.

Rule id eu-gdpr-ai-data.minimise-personal-data-sent-to-ai · review status: primary source derived