DEFINITION
GDPR
The EU General Data Protection Regulation — the world's most comprehensive data-protection law, governing how organisations handle personal data of EU residents.
In depth
The General Data Protection Regulation (GDPR, EU 2016/679) regulates the processing of personal data of people in the EU and EEA. It applies to any organisation that targets or monitors EU residents, regardless of where the organisation is based. GDPR introduces concepts now common across global privacy law: lawful bases for processing, data subject rights (access, deletion, portability, objection), data protection by design, and substantial fines (up to 4% of global revenue). Sending EU personal data to a U.S.-based AI service raises a stack of GDPR concerns: lawful basis, processor agreements, cross-border transfer mechanisms, and data subject rights.
Examples
- A Berlin-based consultancy pasting client emails into ChatGPT — a processing event under GDPR with the AI provider as processor (or sub-processor).
- A French recruiter routing CVs through a U.S. AI tool, triggering cross-border transfer rules.
- A Dutch healthcare administrator using a free AI summarisation tool on patient correspondence.
How Locke handles gdpr
Locke detects patterns consistent with personal data and can mask, tokenize, or block before transmission. Because all detection is local, Sonomos itself is not a processor of EU personal data — there is no cross-border transfer to mediate, no DPA to negotiate, no new sub-processor to add to the chain.
See the productRelated terms
- Personally Identifiable Information (PII)
Any information that can identify a specific person, either directly (name, SSN) or in combination with other data (zip code + birthdate).
- CCPA
The California Consumer Privacy Act and its 2023 successor, the CPRA — the United States' most influential state-level privacy law.
- Pseudonymization
Replacing direct identifiers with stable pseudonyms so the data can no longer identify a person without additional information held separately.