All frameworks
    Reg. (EU) 2016/679Evidence pack

    GDPR

    AI systems process personal data pervasively — in prompts, outputs and logs. Nyx applies minimization at the point of use and keeps the evidence GDPR asks for.

    ReferenceRequirementNyx capability
    Art. 5(1)(c)Data minimizationK-anonymity engine removes or generalizes PII in prompts and attachments before they reach the model
    Art. 25Privacy by design & pseudonymizationReversible tokenization on-device: PII is replaced before it reaches the model; re-identification is admin-only and every reveal is audited
    Art. 30Records of processingTamper-evident audit trail of every AI interaction, exportable for the supervisory authority
    Art. 35Data Protection Impact AssessmentPre-filled DPIA generator, populated from your AI processing inventory and incident record
    Art. 22Human review of automated decisionsDispute workflow: a blocked user can request review; admins mark false / true positive, fully logged
    Art. 33–34Breach notificationPattern-based detection of data exfiltration via LLM with severity-classified incident records
    Art. 44–46Transfers & data locationResidency control: every model's provider jurisdiction is evaluated against your allow/block policy and violations are flagged

    Every control here maps to a shipping capability. The report itself is auditor-facing evidence — control, requirement, metrics and reasoning — not a compliance verdict.

    Get a readiness demo

    The information on this page is for informational purposes and does not constitute legal advice. For an assessment specific to your organization, consult a qualified professional. Nyx reports are evidence packs — control, requirement, metrics and reasoning — not a compliance verdict.