GDPR
The GDPR sets rules for processing the personal data of people in the EU and EEA: a lawful basis is required before processing can begin, individuals have rights to access, correct, delete and receive a copy of their data, and a breach that risks people's rights must generally be reported to the relevant supervisory authority within 72 hours of discovery. It applies regardless of where the organization doing the processing is based, so a vendor outside the EU handling an EU resident's data is still in scope.
The regulation was adopted in 2016 and has applied since May 25, 2018. Fines can reach 20 million euros or 4 percent of an organization's global annual turnover, whichever is higher.
For an enterprise buying an AI system, GDPR turns into a specific, checkable requirement: any vendor processing personal data on the company's behalf needs a signed Data Processing Agreement setting out what it does with that data and under what safeguards.
A support agent that retrieves a customer's account details needs a documented lawful basis for that processing and a Data Processing Agreement covering the vendor whose system performs the retrieval.
In Dynamiq, a Data Processing Agreement is available, and self-hosted deployment lets an organization keep data processing inside the region its own GDPR analysis requires.

See an agent on your own workflow.
Bring a process and its documents. Our engineers will show you how Dynamiq runs it, in your environment or ours.