REGULATION

GDPR

General Data Protection Regulation (EU) 2016/679. Vigilens maps GDPR data protection requirements to your AI system's data processing activities, automates DPIA tracking, and maintains continuous evidence of lawful processing inside your pipeline.

Type Regulation
Jurisdiction European Union
Status In force (25 May 2018)
Vigilens coverage AI-relevant articles

What it requires for AI systems

GDPR governs the processing of personal data. AI systems that ingest, process, or generate outputs based on personal data must comply with data protection principles, maintain lawful bases for processing, and implement appropriate technical and organisational measures.

Key articles for AI

  • Article 5: Principles of lawful, fair, and transparent data processing
  • Article 6: Lawful bases for processing (consent, legitimate interest, contract, etc.)
  • Article 22: Automated individual decision-making, including profiling
  • Article 25: Data protection by design and by default
  • Article 28: Processor obligations and controller-processor agreements
  • Article 30: Records of processing activities
  • Article 32: Security of processing (appropriate technical measures)
  • Article 33: Notification of personal data breaches to the supervisory authority
  • Article 35: Data Protection Impact Assessment (DPIA) for high-risk processing
  • Article 37: Designation of a Data Protection Officer

How Vigilens automates it

Vigilens encodes GDPR requirements as controls mapped specifically to AI system data flows. Rather than treating GDPR as a standalone compliance programme, Vigilens integrates data protection controls alongside EU AI Act, ISO 42001, and ISO 27001 obligations, de-duplicating where requirements overlap.

  • DPIA triggers auto-detected based on processing descriptions and risk classification
  • Article 22 automated decision-making controls mapped to human oversight requirements
  • Data governance evidence linked to Article 10 EU AI Act training data obligations
  • Processing records maintained continuously, not assembled at audit time
  • Cross-framework mapping reduces duplicate evidence collection

GDPR and the EU AI Act

For AI systems processing personal data, GDPR and the EU AI Act create overlapping obligations. Article 10 of the EU AI Act (data governance) directly intersects with GDPR data protection principles. Vigilens maps these intersections explicitly, ensuring that a single piece of evidence can satisfy requirements from both frameworks where appropriate.

LIVE IN VIGILENS

Coverage

AI-relevant articles: 5, 6, 22, 25, 28, 30, 32, 33, 35, 37. Cross-mapped to EU AI Act data governance obligations.

Articles covered

Art. 5, 6, 22, 25, 28, 30, 32, 33, 35, 37

Start automating GDPR compliance for AI.

Map data protection controls to your AI pipeline. Continuous evidence, not annual audits.

Classify your AI → Start free