Trust, privacy, and compliance
Configuring for GDPR, DORA, the EU AI Act, and sector rules
Configuring your Unless platform to comply with GDPR, DORA, the EU AI Act, and sector-specific rules is a foundational aspect of its design, ensuring that your AI-powered customer agent operates within the strict regulatory frameworks applicable in the EU. This article explains how Unless integrates these requirements into its architecture and what controls you can manage to maintain compliance.
built-in compliance for GDPR, DORA, and the EU AI Act
Unless is designed with compliance embedded from the ground up rather than added as an afterthought. This means that the platform’s architecture inherently supports the key requirements of major EU regulations:
GDPR (General Data Protection Regulation): Unless ensures EU data residency by default, meaning all personal data stays within EU cloud regions you specify. It filters and tokenizes personally identifiable information (PII) at the gateway before any data leaves your perimeter, protecting sensitive identifiers. Data subject rights such as access, rectification, and erasure are handled through your dashboard with human confirmation for changes.
DORA (Digital Operational Resilience Act): For financial institutions, Unless supports ICT risk management aligned with ISO 27001 and ENISA guidance. The platform undergoes annual penetration testing, maintains incident reporting commitments, and provides transparency on subcontractors, helping you meet operational resilience requirements.
EU AI Act: Unless classifies AI interactions by risk on a per-decision basis and maintains a detailed audit trail for every AI output, including timestamps, decision paths, models used, and source citations. Real-time guardrails prevent the agent from exceeding boundaries you set, and transparency reports are generated in formats suitable for regulators.
sector-specific configurations and guardrails
Unless is also configurable to meet sector-specific regulations and supervisory requirements, particularly for entities overseen by BaFin (Germany) and AFM (Netherlands). This includes:
Pre-configured guardrails for sensitive sectors such as finance, human resources, payroll, and healthcare, which are built into the platform rather than custom-built for each customer. This approach ensures consistent compliance and reduces implementation complexity.
Independent content silos that prevent one customer’s data from training or influencing another customer’s agent, preserving data confidentiality and compliance with data segregation requirements.
managing compliance controls within the platform
The Unless dashboard includes a dedicated Compliance tab that serves as a workspace for your legal, data protection officer (DPO), and security teams. Here you can:
Access and export audit logs that record every AI decision and configuration change, supporting accountability and regulatory inquiries.
Configure retention rules for data and logs without needing engineering support.
Review and adjust PII filtering settings, including options to obfuscate PII during inference, remove PII from user input, and filter PII from training data by default. You can also manage a whitelist of terms exempt from filtering.
Generate transparency reports and access documentation such as the Data Processing Agreement (DPA), sub-processor inventories, and security questionnaires to support procurement and compliance reviews.
how compliance is maintained during operation
Unless enforces compliance continuously through its Privacy Vault and AI automation layers. The Privacy Vault applies multiple measures such as zero cookies, user authentication, PII filtering, tokenization, and real-time data management to protect personal data. The AI automation layer ensures that every AI interaction is classified, logged, and constrained by guardrails you define.
Moreover, the platform’s architecture supports human oversight by never allowing irreversible actions without explicit human approval and by providing full traceability of AI outputs back to their sources. This approach aligns with the EU AI Act’s requirements for transparency and human control.
conclusion
Configuring Unless for GDPR, DORA, the EU AI Act, and sector-specific rules is straightforward because compliance is integral to the platform’s design. By leveraging built-in controls, audit trails, and configurable guardrails, you can confidently deploy AI-powered customer agents that meet stringent EU regulatory standards while maintaining operational flexibility and transparency. The Compliance tab in the dashboard centralizes these capabilities, making it easier for your teams to manage and demonstrate compliance on an ongoing basis.