GDPR
GDPR (General Data Protection Regulation) is the European Union law governing how organizations collect, process, and store the personal data of EU residents. It applies regardless of where the company is based, requires a lawful basis for processing, and gives individuals rights to access, correct, and delete their data.
GDPR reshaped how every company handling EU customer data operates, whether or not the company has a single employee in Europe. For any business running an AI agent on customer conversations, it sets the baseline for what's legally required.
What is GDPR?
The General Data Protection Regulation is a European Union law, in effect since 2018, that governs the processing of personal data belonging to people located in the EU. Its reach is extraterritorial: a company based in the US or anywhere else is still subject to GDPR if it processes the personal data of EU residents.
GDPR distinguishes between a controller (the entity that decides why and how personal data is processed) and a processor (an entity that processes data on the controller's behalf, such as a vendor providing a support platform). Each role carries distinct legal obligations, spelled out through a Data Processing Agreement (DPA) between the two parties.
Why GDPR Matters
GDPR carries some of the steepest penalties of any privacy law: fines up to 4% of global annual revenue or €20 million, whichever is greater. Beyond the legal exposure, it shapes how vendor contracts, data flows, and even AI training practices get structured.
- Individual rights: access, rectification, erasure, portability, and the right to object to processing
- Cross-border transfer rules: personal data leaving the EU generally requires a valid transfer mechanism, such as Standard Contractual Clauses or an adequacy decision
- Breach notification: organizations must notify the relevant supervisory authority within 72 hours of becoming aware of a qualifying breach
How GDPR Compliance Works
- Identify the lawful basis for each type of processing (consent, contract, legitimate interest, and so on)
- Execute a DPA with any vendor acting as a processor of personal data
- Put a valid mechanism in place for any international data transfer
- Build a process to respond to data subject requests (access, deletion, portability) within statutory timelines
- Maintain breach detection and notification procedures
For AI agents specifically, GDPR also touches how customer data can be used to improve the underlying models. Fin, for example, only uses anonymized customer data for model fine-tuning, with an opt-out available at any time. For a deeper look at how AI agents handle GDPR and HIPAA obligations together, see this guide on GDPR-compliant AI agents.
GDPR vs CCPA
GDPR and CCPA both regulate personal data, but they come from different legal traditions. GDPR generally requires an affirmative lawful basis before processing can begin; CCPA takes an opt-out approach, letting consumers stop the sale or sharing of their data after the fact. GDPR also applies EU-wide, while CCPA is scoped to California residents and businesses meeting specific thresholds.
Frequently Asked Questions
Does GDPR apply to companies outside the EU?
Yes. Any organization processing the personal data of people located in the EU is subject to GDPR, regardless of where the organization itself is headquartered.
Is signing a Data Processing Agreement enough for GDPR compliance?
No. A DPA is a necessary piece, but full compliance also requires a valid lawful basis for processing, appropriate security measures, a transfer mechanism for any data leaving the EU, and a process for handling data subject rights requests.