Skip to main content

GDPR for AI and software companies

The EU's General Data Protection Regulation governs how personal data is collected, processed, transferred, and deleted. European buyers ask about it in the first call.

Which edition this covers

Regulation (EU) 2016/679, as in force

Checked against the source on 2026-09-13 · read the source

Not covered

  • The UK GDPR and the Data Protection Act 2018, which are separate law after withdrawal.
  • National derogations, which each Member State sets and which change the answer in that state.
  • The ePrivacy Directive and its national implementations, which govern cookies and electronic communications separately.

What Trooth witnesses

Read on a schedule, republished with the date

  • Your published Data Processing Agreement position and privacy commitments
  • Sub-processors and where they operate, from your own disclosure
  • Stated retention and deletion practices, republished with the date they changed
  • Encryption in transit and at rest on the endpoints you expose

What Trooth does not do

Said plainly, so nobody guesses

  • Issue a certification, attestation, or audit opinion. Only a licensed auditor can do that.
  • Act as your Data Protection Officer or assess your lawful basis for processing.
  • Confirm your international transfer mechanism is valid.
  • Give legal advice or tell you whether you are compliant. That call is yours and your counsel's.

Why this is worth anything to a buyer

A questionnaire answer is a claim typed once and never checked again. GDPR here is the rulebook, not the product: what Trooth publishes for it is read from your live systems on a schedule and republished with the date it was last seen, so a buyer checking your company can tell the difference between what was true a year ago and what is true this morning. That is a smaller promise than an audit, and it is one we can actually keep. The full method is on the methodology page.