EU regulation

General Data Protection Regulation (GDPR)

The EU's horizontal data-protection law — the legal floor for handling personal data in Europe.

What it is

The General Data Protection Regulation (Regulation (EU) 2016/679) is the EU's horizontal personal-data protection law, adopted in 2016 and applicable from 25 May 2018. It applies to any organisation processing personal data of individuals in the EU, irrespective of where the organisation itself is established.

Key principles

Article 22 — automated decision-making

Article 22 grants individuals the right not to be subject to a decision based solely on automated processing — including profiling — that produces legal or similarly significant effects. This is the article most directly relevant to financial-defence AI: consequential decisions about an individual must have a human in the loop.

Enforcement

Maximum administrative fines reach EUR 20 million or 4% of global annual turnover, whichever is higher. National data-protection authorities (e.g. CNIL in France, the Datenschutzbehörde in Austria) investigate and enforce, coordinated by the European Data Protection Board.

How this matters in our work

Silbad's federated architecture is designed around the GDPR: customer data does not leave the customer institution. See Public Engagement for the citizen-facing version of the same architecture.