All frameworks
    Reg. (EU) 2016/679Evidence pack

    GDPR

    AI systems process personal data pervasively, in prompts, outputs and logs. Nyx applies minimization at the point of use and keeps the evidence GDPR asks for.

    ReferenceRequirementNyx capability
    Art. 5(1)(c)Data minimizationK-anonymity engine removes or generalizes PII in prompts and attachments before they reach the model
    Art. 25Privacy by design & pseudonymizationReversible tokenization on-device: PII is replaced before it reaches the model; re-identification is admin-only and every reveal is audited
    Art. 30Records of processingTamper-evident audit trail of every AI interaction, exportable for the supervisory authority
    Art. 35Data Protection Impact AssessmentPre-filled DPIA generator, populated from your AI processing inventory and incident record
    Art. 22Human review of automated decisionsDispute workflow: a blocked user can request review; admins mark false / true positive, fully logged
    Art. 33-34Breach notificationPattern-based detection of data exfiltration via LLM with severity-classified incident records
    Art. 44-46Transfers & data locationResidency control: every model's provider jurisdiction is evaluated against your allow/block policy and violations are flagged

    Every control here maps to a shipping capability. The report itself is auditor-facing evidence (control, requirement, metrics and reasoning), not a compliance verdict.

    Get a readiness demo

    The information on this page is for informational purposes and does not constitute legal advice. For an assessment specific to your organization, consult a qualified professional. Nyx reports are evidence packs, control, requirement, metrics and reasoning, not a compliance verdict.