The problem
- Data crosses borders.AEPD fines up to 4% global revenue.
- OpenAI processes in the US.Article 46 transfer mechanisms don't apply.
- Consent is not enough.Your DPO is exposed.
The solution
EU data stays in the EU. By architecture.
Personal data processed within the EU region. No cross-border transfer. GDPR Art. 5, 25 and 32 covered by the infrastructure layer — your DPO gets a technical guarantee, not a vendor promise.
GDPR Art. 9(1)
"Processing of personal data revealing racial or ethnic origin, political opinions, religious beliefs, health data or data concerning a natural person's sex life or sexual orientation shall be prohibited."
No personal data crosses EU borders. GDPR Art. 44 satisfied by architecture.
Frequently asked questions
Is using the OpenAI API GDPR compliant?
By default, calling OpenAI sends personal data to the US, triggering Chapter V transfer rules (Art. 44–46). Privedge processes personal data within the EU and tokenizes it before any call, so identifiable data does not leave the EU.
Is tokenization the same as anonymization under GDPR?
No — and precision matters here. Reversible tokenization is pseudonymization (Art. 4(5), Recital 26), and pseudonymized data is still personal data. The benefit is that the provider never receives identifiable data — not that GDPR stops applying.
Do I still need a lawful basis and a DPA?
Yes. Privedge reduces transfer exposure and risk but does not replace your lawful basis (Art. 6) or your processor agreements. We provide a DPA for our processing role.
How does this help with the right to erasure (Art. 17)?
Because real identifiers never reach the provider, there is far less personal data spread across third parties to erase. The pseudonymization map stays under your control, so erasure is managed in one place.