Trust, privacy, and compliance
Configuring for GDPR, DORA, the EU AI Act, and sector rules
Unless is built for regulated European businesses, which means compliance is not a feature you switch on but a set of controls woven into the platform’s architecture. The platform is designed to be configurable for GDPR, DORA, the EU AI Act, and sector-specific rules such as those from BaFin and AFM, so your legal, DPO, and security teams can demonstrate control without bolting on a second tool. This article explains how those frameworks map to the platform, what you configure, and where the documentation lives.
Your role and Unless’s role
Under the EU AI Act, Unless acts as the provider of the AI system. We build, configure, and operate the platform, including the RAG layer, the Privacy Vault, the agentic framework, and the integrations with foundation models. The foundation models themselves come from upstream providers like AWS Bedrock and Azure OpenAI, hosted in EU regions.
Your organization acts as the deployer within your own context. That means you are responsible for the deployer obligations in Article 26 of the EU AI Act, which include using the Services according to their instructions, assigning human oversight to competent staff, ensuring input data is relevant, monitoring operations, retaining logs, and carrying out a Fundamental Rights Impact Assessment where applicable. Unless supports you by making available the technical documentation and instructions for use you need to meet those obligations.
Configuring the platform for each framework
The Compliance tab in the Unless dashboard is the workspace where your legal, DPO, and security teams work. Audit logs, risk classifications, retention rules, sub-processor inventory, and transparency reports are all there, editable and exportable.
GDPR
Personal data is filtered at ingestion and at runtime, so identifiers are removed or masked before they enter the model. Where personal context is required, it is tokenized through the Privacy Vault, and the model only sees tokens, not the underlying identifiers. De-tokenization happens inside our controlled environment, so raw personal data never reaches the foundation model provider. You decide which fields the agent can see at each moment, and you can change that decision at any time.
DORA
DORA is the EU operational-resilience rule set for financial services. Unless is configurable for DORA requirements, and the platform’s audit trails and incident response plan support your obligations. Critical incidents are disclosed to customers within the timeline in your DPA, and status updates are posted at status.unless.com.
EU AI Act
Every AI interaction carries a per-decision risk classification you can read. The platform maintains a per-interaction audit trail with timestamp, decision path, model used, and source citation, all stored and exportable. Real-time guardrails stop the agent at the boundary you set. Transparency reports are produced in a format and language your regulator can read.
Sector rules
Unless is configurable for entities supervised by BaFin and AFM. Sector-specific guardrails for finance, HR, payroll, and healthcare are configured, not custom-built per customer. Independent content silos ensure one customer’s data does not train another customer’s agent.
Proving compliance for a specific moment
To prove EU AI Act compliance for a specific interaction, combine three things. First, the per-decision audit trail from Conversations. Second, the configuration status in Accountability showing which AI Act controls are active. Third, the Provider documentation in the Compliance Center, including risk classification and Provider obligations. Together those cover what an auditor will ask for.
Documentation and support
The Compliance Center holds the formal documentation behind each framework, including the DPA, sub-processor list, security addendum, and code of conduct. For a DPIA, Unless provides a dedicated document that maps the nine GDPR criteria to the platform’s processing operations, and it commits to reasonable assistance with DPIAs, data subject rights requests, and prior consultations with supervisory authorities.
Conclusion
Compliance at Unless is a matter of configuration, not custom engineering. The platform gives you the controls to meet GDPR, DORA, the EU AI Act, and sector rules, and the documentation to prove it. Start in the Compliance tab, pull the audit trails you need, and use the Compliance Center for the formal paperwork your auditors will ask for.