Known as DSGVO in Germany and Austria, RGPD in France and Spain, and GDPR in Ireland and the Netherlands.
Who it binds. Any organisation processing personal data of people in the EU, wherever that organisation is based.
What it requires
- A lawful basis for every processing activity.
- Data minimisation: collect and retain only what the purpose requires.
- A Data Protection Impact Assessment where processing is likely to be high risk.
- Restrictions on transfers outside the EU under Article 44 and the chapter that follows it.
- Breach notification to the supervisory authority within 72 hours.
Penalty. Up to 20 million euro or 4 percent of global annual turnover, whichever is higher.
Where Omit changes it. Redaction before disclosure is data minimisation applied at the point of sharing. Because Omit runs on the machine that already holds the file, there is no transfer to assess under Article 44, and no processor to contract with.
Who it binds. Providers and deployers of AI systems placed on the EU market or whose output is used in the EU.
What it requires
- Prohibited practices ceased from 2 February 2025.
- Transparency and documentation for general purpose AI models from 2 August 2025.
- Risk management, data governance, logging, human oversight and accuracy testing for high risk systems.
- A Fundamental Rights Impact Assessment for high risk deployments, which sits alongside the GDPR assessment rather than replacing it.
- Provenance labelling for generated content, expected from 2 December 2026.
Penalty. Up to 35 million euro or 7 percent of global annual turnover for prohibited practices.
Where Omit changes it. The Act does not stop teams pasting personal data into general purpose models, and neither does policy. Removing the identifiers before the paste is the control that survives an audit, because it happens on the endpoint and is logged there.
Who it binds. Essential and important entities across eighteen sectors, including health, public administration, energy, transport and digital infrastructure.
What it requires
- Risk management measures proportionate to exposure.
- Incident reporting, with an early warning inside 24 hours.
- Supply chain security, covering the tools staff use day to day.
- Management bodies can be held personally accountable for failures.
Penalty. Up to 10 million euro or 2 percent of global annual turnover for essential entities.
Where Omit changes it. A tool that never opens a network socket removes an entire class of supply chain exposure. There is no vendor endpoint to assess, no data processing agreement to negotiate, and no third party breach that can reach your documents.
Who it binds. Manufacturers of connected products, related service providers, and cloud providers serving EU customers.
What it requires
- Users can access and share the data their connected products generate.
- Cloud switching provisions, including the removal of egress charges.
- Safeguards against unlawful third country access to non personal data held in the EU.
Penalty. Set by member states. Enforcement sits with national authorities.
Where Omit changes it. Perpetual local licensing means there is no lock in to unwind. There is no stored corpus to export, because nothing was ever uploaded.