Glossary

DEFINITION

GDPR

The EU General Data Protection Regulation — the world's most comprehensive data-protection law, governing how organisations handle personal data of EU residents.

In depth

The General Data Protection Regulation (GDPR, EU 2016/679) regulates the processing of personal data of people in the EU and EEA. It applies to any organisation that targets or monitors EU residents, regardless of where the organisation is based. GDPR introduces concepts now common across global privacy law: lawful bases for processing, data subject rights (access, deletion, portability, objection), data protection by design, and substantial fines (up to 4% of global revenue). Sending EU personal data to a U.S.-based AI service raises a stack of GDPR concerns: lawful basis, processor agreements, cross-border transfer mechanisms, and data subject rights.

Examples

  • A Berlin-based consultancy pasting client emails into ChatGPT — a processing event under GDPR with the AI provider as processor (or sub-processor).
  • A French recruiter routing CVs through a U.S. AI tool, triggering cross-border transfer rules.
  • A Dutch healthcare administrator using a free AI summarisation tool on patient correspondence.

How Locke handles gdpr

Locke detects patterns consistent with personal data and can mask, tokenize, or block before transmission. Because all detection is local, Sonomos itself is not a processor of EU personal data — there is no cross-border transfer to mediate, no DPA to negotiate, no new sub-processor to add to the chain.

See the product