Also called GDPR.
If you use personal data of people in Europe, GDPR applies even when the AI vendor sits somewhere else. You need a lawful reason to use the data, a way for people to access or delete it, and a contract with anyone who processes it for you. Automated decisions that significantly affect a person can require a human review.
This is not only a form for the legal team. A chatbot trained on EU customer email, or a scoring model that declines an application, is in scope. Map where personal data enters the AI system, which vendor receives it, and how you would delete it if someone asked. If you cannot do that map, you are not ready to launch that feature.
Think of it this way: GDPR follows the person, not the office. If a customer lives in the EU, the rules travel with their data, even if your company is based somewhere else.
A US SaaS company discovers its EU user base subjects it to GDPR. Their AI feature auto-processes profile data. Legal requires a data processing agreement with the AI provider, a documented lawful basis, and deletion procedures.
A US company launches a support bot for its EU customers and stores transcripts with a US vendor that trains on them by default. A deletion request arrives. They cannot remove one person's chats from the vendor's training. They switch the vendor setting, sign the right contract, and stop sending EU transcripts until the deletion path works.
Check GDPR applicability before any AI feature that processes personal data. It is not a post-launch consideration. Baking in compliance from the start is far cheaper than retrofitting it. There is no use case where GDPR compliance can be skipped if you process the data of EU residents. The size of the project is not a factor in whether the regulation applies.
RaftLabs writes the control into the system: which data can enter, who approves the result, and how you explain it later. The rule and the product stay the same story. The related work on our side is AI governance.
This sits with the other governance & compliance terms on the glossary. The rules that keep AI legal, and keep customer data out of the wrong tool. Worth reading next: Data Privacy / PII, Model Governance, and Shadow AI.