Skip to main content
The GDPR policy pack covers Articles 5, 17, 25, 30, and 32.
RequirementAGCMS featureArticle
Records of processingAudit log + Article 30 report endpointArt. 30
Right to erasureTwo-admin-approval purge → tombstoned audit rowsArt. 17
Data minimisationPII redaction at gateway before forwarding to LLMArt. 5(1)(c)
Security of processingTLS 1.3, encryption at rest, signed audit chainArt. 32
Privacy by designDefault-deny policy posture + tenant-isolated RLSArt. 25
The pack ships an Article 30 report builder that produces a CSV / JSON of all processing activities for a date range, downloadable from Reports → GDPR Art. 30.