The EU's horizontal data-protection law — the legal floor for handling personal data in Europe.
The General Data Protection Regulation (Regulation (EU) 2016/679) is the EU's horizontal personal-data protection law, adopted in 2016 and applicable from 25 May 2018. It applies to any organisation processing personal data of individuals in the EU, irrespective of where the organisation itself is established.
Article 22 grants individuals the right not to be subject to a decision based solely on automated processing — including profiling — that produces legal or similarly significant effects. This is the article most directly relevant to financial-defence AI: consequential decisions about an individual must have a human in the loop.
Maximum administrative fines reach EUR 20 million or 4% of global annual turnover, whichever is higher. National data-protection authorities (e.g. CNIL in France, the Datenschutzbehörde in Austria) investigate and enforce, coordinated by the European Data Protection Board.
Silbad's federated architecture is designed around the GDPR: customer data does not leave the customer institution. See Public Engagement for the citizen-facing version of the same architecture.