Regulatory

GDPR (2016/679)

The EU General Data Protection Regulation (2016/679) governs personal data, not AI systems specifically — it applies to Runback's own customers whenever an agent's inputs or outputs contain personal data, which is most agentic workloads in practice. The mapping below covers the articles a run-capture and audit product is actually positioned to help with: minimisation, storage limitation, records of processing, and security of processing.

Below is the same static clause map the in-app Regulatory tab evaluates against your org's real data on every load — not a separate summary written for this page. There is no compliance verdict here, since that depends on your own data; sign in to see your org's live status per clause.

Swipe to see all columns →

ClauseRequirementRunback capabilityEvidence
Article 5(1)(c)Personal data shall be adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed (data minimisation).In-process PII redaction before anything is sentA run where PII was redacted before capture
See it in the dashboard →
Article 5(1)(e)Personal data shall be kept in a form which permits identification for no longer than is necessary (storage limitation).Plan-enforced retention window with automated pruningYour configured data-retention window
See it in the dashboard →
Article 30Maintain a record of processing activities under its responsibility.Immutable, hash-chained run ledgerAn entry in the hash-chained, append-only ledger
See it in the dashboard →
Article 32Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.SSO + policy engine + signed audit trailA captured run in the audit trace
See it in the dashboard →
Honest limits

What this page does not claim.

  • GDPR has dozens of articles beyond the four mapped below (lawful basis, DSAR handling, cross-border transfer mechanisms, breach notification timing). Those are organisational and legal obligations Runback does not touch.
  • Redaction reduces what personal data reaches Runback's storage; it does not by itself establish a lawful basis for processing it in the first place.
  • This is a capability map, not a conformity determination. Whether your deployment satisfies GDPR is a determination for your own assessor — what's listed above is the evidence that argument draws on.