Blog · Regulation

DPAs, SOC 2, GDPR, and the rest.

Regulatory guidance for document AI operators: GDPR Article 28, SOC 2 Type II, sub-processors, retention, and the compliance posture buyers ask for in 2026.

Regulation

GDPR for document AI: a practical guide for operators

Article 28 obligations, lawful basis, sub-processor governance, data subject rights, and what your DPA actually needs to say.

9 min
Regulation

Sub-processors in AI: what your DPA needs in 2026

AI products invoke 4–7 sub-processors per request. What your DPA needs to say about LLM providers, observability vendors, and zero-retention APIs in 2026.

9 min
Regulation

What modern data-protection laws say about document retention in AI

A practical guide for operators processing PII through language models.

10 min