Reg. (EU) 2016/679Evidence pack
GDPR
AI systems process personal data pervasively — in prompts, outputs and logs. Nyx applies minimization at the point of use and keeps the evidence GDPR asks for.
| Reference | Requirement | Nyx capability |
|---|---|---|
| Art. 5(1)(c) | Data minimization | K-anonymity engine removes or generalizes PII in prompts and attachments before they reach the model |
| Art. 25 | Privacy by design & pseudonymization | Reversible tokenization on-device: PII is replaced before it reaches the model; re-identification is admin-only and every reveal is audited |
| Art. 30 | Records of processing | Tamper-evident audit trail of every AI interaction, exportable for the supervisory authority |
| Art. 35 | Data Protection Impact Assessment | Pre-filled DPIA generator, populated from your AI processing inventory and incident record |
| Art. 22 | Human review of automated decisions | Dispute workflow: a blocked user can request review; admins mark false / true positive, fully logged |
| Art. 33–34 | Breach notification | Pattern-based detection of data exfiltration via LLM with severity-classified incident records |
| Art. 44–46 | Transfers & data location | Residency control: every model's provider jurisdiction is evaluated against your allow/block policy and violations are flagged |
Every control here maps to a shipping capability. The report itself is auditor-facing evidence — control, requirement, metrics and reasoning — not a compliance verdict.
The information on this page is for informational purposes and does not constitute legal advice. For an assessment specific to your organization, consult a qualified professional. Nyx reports are evidence packs — control, requirement, metrics and reasoning — not a compliance verdict.