GDPR AI ComplianceTDX Attestation Live
French controller · VOLTAGE EI · SIREN 943 808 824

GDPR-compliant AI agents, Article 28 native DPA.

Hardware-sealed inference inside Intel TDX. Provider-blind processing. EU company, EU-hosted customer database. One Article 28 DPA, a named sub-processor list, and SCCs already in place.

GDPR + EU AI Act overlap

Two regulations, one stack.

GDPR governs personal data. The EU AI Act governs AI systems. Where AI processes personal data, almost every regulated workflow, both apply at once. The 2026 EU AI Office and EDPB joint guidance makes the overlap explicit: Article 32 GDPR confidentiality and Article 15 AI Act cybersecurity must be satisfied with the same technical measures. Hardware sealing covers both with one piece of evidence.

Art. 28 GDPR

Controller/processor agreement

Native DPA, no negotiation

Art. 32 GDPR

Confidentiality of processing

Intel TDX, AES-256 CPU-fused

Art. 35 GDPR

DPIA for high-risk processing

DPIA template + attestation evidence

Art. 44+ GDPR

Transfers documented and mitigated

SCCs + TIA; EU-hosted database, compute host outside the trust domain

Art. 12 AI Act

Automatic event logging

Per-request ECDSA quote

Art. 26 AI Act

Deployer documentation

Model cards + attestation logs

Article 28, native DPA

One DPA. No negotiation. SCCs already signed.

VOLTAGE EI is an EU controller subject to French data protection authority (CNIL) supervision. Our Article 28 DPA covers sub-processors, security measures, breach notification timelines (72 hours), audit rights and instructions on processing, aligned with the strictest reading of GDPR. Available on request, signed before production access.

What the DPA covers

  • Processor obligations (Art. 28(3) sub-clauses)
  • Sub-processor list with prior authorisation
  • Technical and organisational measures (Art. 32)
  • Breach notification within 72 hours
  • Data subject rights assistance
  • Audit rights and inspection cooperation
  • Return or deletion at end of processing
  • No international transfer outside EEA in inference path

Article 32, confidentiality by hardware

Provider-blind by design.

Article 32(1)(b) requires confidentiality of processing as a technical measure appropriate to the risk. Hardware-sealed inference inside Intel TDX is the strictest available implementation: AES-256 memory encryption with keys fused into the CPU at boot, the GPU attached inside the trust domain, an Intel TD Quote on request. VoltageGPU operators are technically incapable of reading user prompts. A French court order to dump RAM would return ciphertext.

AES-256 memory encryption

Keys fused inside the CPU at boot. RAM is opaque to operators and to the hypervisor.

Attestation on request

ECDSA quote bound to the enclave measurement. Independently verifiable on /trust.

EU jurisdiction

VOLTAGE EI, France. Subject to CNIL. No FISA 702 exposure.

Native DPA

Article 28 DPA on file before production access. SCCs and the transfer impact assessment come with it.

Sub-processor list

Two sub-processors. Both EU-aligned. Both in the DPA.

Sub-processorRoleData processedRegion
Targon (Manifold Labs)Confidential GPU computeEncrypted inference inputs and outputsUS-operated, locations vary by capacity
ChutesTEE inference endpointsModel weights serving (Qwen3-TEE, DeepSeek-V3.2-TEE)Locations vary by capacity

The application layer (auth, billing) and the customer database are EU-hosted (Frankfurt). Changes to the sub-processor list are notified in advance with right of objection.

FAQ

GDPR + AI questions buyers ask.

Do you sign a GDPR Article 28 DPA?

Yes. We provide a native Article 28 Data Processing Agreement that does not require negotiation. VOLTAGE EI is an EU controller (France, SIREN 943 808 824) subject to CNIL. The DPA covers sub-processors, security measures, breach notification timelines and audit rights aligned with the strictest interpretation of GDPR.

Who are the sub-processors?

Targon / Manifold Labs (Intel TDX confidential GPU compute, US-operated, locations vary by capacity) for compute and Chutes (TEE inference endpoints) for model serving. Both are listed in the DPA. Neither can read enclave memory: keys are CPU-fused and the host sits outside the trust domain. The application layer and customer database are EU-hosted (Frankfurt).

How is Article 32 confidentiality satisfied?

Hardware-sealed processing inside Intel TDX. AES-256 memory encryption with keys fused into the CPU, the GPU attached inside the trust domain, per-request ECDSA attestation. VoltageGPU operators are technically incapable of reading user prompts, this is the strictest defensible reading of Article 32(1)(b).

Is Schrems II a problem here?

The application layer and customer database are EU-hosted (Frankfurt). Confidential compute runs on a US-operated GPU provider listed in the DPA, so SCCs and a transfer impact assessment apply, and both are provided. The mitigating control is hardware: memory is encrypted with CPU-fused keys and the host operator sits outside the trust domain, so the transfer is of ciphertext the provider cannot read. EU-only compute residency is available on written confirmation.

Can I use this for special category data (Article 9)?

Yes, subject to a lawful basis under Article 9(2). Hardware sealing reinforces appropriate technical measures for health, biometric or judicial data. We provide a DPIA template aligned with Article 35 to support your assessment.

Related compliance pages

EU AI Act compliance pillar

Article 12, 14, 15 and 32 obligations enforceable from 2 August 2026.

DORA AI compliance

ICT third-party risk and operational resilience for financial entities.

NIS2 AI compliance

Essential and important entities, supply chain security, incident reporting.

Article 12 AI Act logging

Sample attestation log JSON, retention and API access.

Sovereign agentic AI

Vertical agents for legal, finance, regulated professionals, sealed in TDX.

Live attestation evidence

Verify any request against the public attestation root.

Confidential compute platform

Intel TDX trust domains with the GPU attached inside, as raw compute.

VoltageGPU for law firms

RGPD-aligned legal AI agents and procurement materials.

RGPD AI compliance guide

In-depth marketing-site guide on aligning AI with French and EU data law.

Get the DPA. Run the workflow. Walk away with attested evidence.

Article 28 DPA on signing. Article 32 confidentiality by hardware. EU company, EU-hosted customer database.

Try a confidential agentSee plans