Get a Quote
Compliance › GDPR

GDPR Compliance for AI-Built Apps

GDPR (Regulation (EU) 2016/679) applies to any app or SaaS processing personal data of people located in the EU/EEA — regardless of where the company is based. Enforcement is now aimed squarely at ordinary businesses: roughly €1.2B in fines across 2025, with France's CNIL alone levying €475M in cookie-consent fines in a single week. AI app builders ship no consent banner, no privacy policy, and no erasure mechanism by default — and a Lovable flaw left roughly 1 in 10 showcased apps leaking user data.

Get a Free Compliance Scan See Audit Pricing
Who It Applies To

Territorial scope & penalties

Article 3 makes GDPR apply to any organization established in the EU, and separately to any non-EU company that offers goods or services to people in the EU (even for free) or monitors their behavior — analytics and tracking included. It's about where the person is located, not their nationality. Mere accessibility of a website from the EU isn't enough to trigger it, but EU-language or EU-currency targeting, EU shipping, or tracking EU visitors is.

Penalty tierMaximumApplies to
Tier 1 (Art. 83)€10M or 2% of global turnoverSecurity & breach failures (Arts. 25, 32, 33)
Tier 2 (Art. 83)€20M or 4% of global turnoverBasic principles, consent, data-subject rights, unlawful transfers

Recent enforcement shows the scale: TikTok was fined €530M by Ireland's DPC in May 2025 (€485M for unlawful EEA→China transfers, €45M for transparency failures, with a 6-month deadline to comply). France's CNIL fined Google €325M and Shein €150M in September 2025 for tracking before consent and a non-functional "Reject all" button — exactly the default behavior of most AI-generated analytics setups. Cumulative GDPR fines have passed €7.1B since 2018 across 3,195+ actions, with an average fine around €2.4M.

Sources: gdpr-info.eu; Irish DPC (TikTok, 2025-05-02); CNIL (Google/Shein, Sept 2025); enforcementtracker.com; CMS GDPR Enforcement Tracker Report 2025/2026.

The Rule

What GDPR actually requires

RequirementWhat it means for your app
Lawful basis & consent (Art. 6/7)One of six legal bases for every processing activity; consent must be freely given, specific, informed, and as easy to withdraw as to give — pre-ticked boxes are invalid.
Data-subject rights (Art. 15–20)Real access, rectification, erasure ("right to be forgotten"), restriction, and machine-readable export — respond within one month.
Privacy by design/default (Art. 25)Data minimization and protective defaults built in at construction time, not bolted on later.
Security of processing (Art. 32)Encryption at rest/in transit, access controls, pseudonymization, tested backups — an exposed database is a direct Art. 32 violation.
Breach notification (Art. 33/34)Notify the supervisory authority within 72 hours of awareness; notify high-risk users without undue delay.
Records of processing (Art. 30)Written register of what data, why, retention, and recipients — the <250-employee exemption doesn't apply if processing is non-occasional or risky, which covers most apps.
Processor contracts (Art. 28)A signed Data Processing Agreement with every processor and sub-processor — the GDPR equivalent of a HIPAA BAA.
International transfers (Ch. V)Data can leave the EEA only via adequacy decision, the EU-US Data Privacy Framework, Standard Contractual Clauses, or Binding Corporate Rules.
Cookie consent (ePrivacy + GDPR)Prior opt-in before any non-essential cookie or tracker fires; "Reject all" must be as prominent as "Accept all" and must actually work.

Sources: gdpr-info.eu Art. 3/6/7/25/28/30/32/33/83; EDPB Guidelines 3/2018; iubenda.com cookie/GDPR requirements.

The Core Problem

Why AI-built apps fail GDPR on day one

  • No consent layer. Scaffolds ship no banner or consent management platform; generated analytics fire on page load before consent — the exact pattern CNIL fined Google €325M and Shein €150M for.
  • No privacy policy or legal pages. Art. 13/14 notices explaining what's collected and why are simply missing.
  • No erasure or export mechanisms. Signup flows exist but there's no working delete-account or data-export button — a direct Art. 17/20 breach.
  • Insecure storage exposes PII. CVE-2025-48757 affected Lovable apps on Supabase without RLS enabled; roughly 1 in 10 of 1,645 showcased apps were found leaking data, with an average 48-day exposure window.
  • PII lands in logs and LLM prompts. Apps log full request bodies and pass user data to LLM APIs with no minimization and no DPA covering that flow.
  • No DPA chain. Sub-processors like Supabase, OpenAI, Stripe, and Resend get wired in without any Art. 28 Data Processing Agreement executed.
  • US-by-default hosting. Replit deploys to GCP US by default and Vercel offers no permanent EU storage — EU user data crosses the Atlantic with no documented transfer mechanism unless the founder deliberately sets one up.

Net effect: a vibe-coded app with EU users typically violates Articles 6, 13, 17, 25, 28, 32, and the Chapter V transfer rules on the day it launches.

Sources: thenextweb.com (Lovable vibe-coding security crisis); blog.barracuda.com (2025-12-22, 40-62% of AI code has vulnerabilities); debevoisedatablog.com.

Platform By Platform

DPA & EU-residency posture, by platform

PlatformDPAEU residency
LovableYes — public, EU SCCs Modules 2&3 + UK Addendum (signed 2025-11-17); ISO 27001:2022Region selectable EU/US/AU (Lovable Cloud); platform DPA doesn't fix the generated app's own RLS gaps
Bolt (StackBlitz)"Where applicable" (enterprise); policy updated 2026-05-12None; not DPF-certified — weakest documented posture
ReplitYes (replit.com/dpa, EEA/Swiss/UK auto-bound) + SCCsGCP US data centers; no dedicated EU residency for deployments
v0 / VercelYes (vercel.com/legal/dpa); EU-US DPF certifiedNo permanent EU storage — EU caching is ephemeral only
Base44 (Wix)Yes (base44.com/dpa; GDPR/UK GDPR + SCCs)No standalone EU-residency guarantee
SupabaseYes (2025-03-14) + SCCs + published sub-processor list; SOC 2 Type IIGenuine EU region selection — Frankfurt, Ireland, London, Paris (AWS); Supabase Inc. itself is US-based (CLOUD Act debate remains)
OpenAIYes + SCCs + sub-processor listEuropean API data residency launched Feb 2025 (new Projects only, approval-gated)
AnthropicYes, effective 2025-02-24, auto-incorporated + SCC Modules 2/3No native EU residency (US inference); EU alt via Claude on AWS Bedrock Frankfurt

Signing these DPAs is on the customer, not automatic — and every one of them covers the builder's own platform, not the analytics or ad SDKs your generated app embeds.

Sources: lovable.dev/data-processing-agreement; stackblitz.com/privacy-policy; replit.com/dpa; vercel.com/legal/dpa; base44.com/dpa; supabase.com/legal/dpa; openai.com/index/introducing-data-residency-in-europe; privacy.claude.com data-processing-addendum.

The Fix

Remediation checklist

  • Map the data (Art. 30) — inventory every personal-data field, sub-processor, and storage location.
  • Kill leaks first (Art. 32) — enable RLS/auth on every table, strip secrets and PII from client code and logs, encrypt at rest and in transit.
  • Establish lawful bases (Art. 6) and publish a real privacy policy (Arts. 13/14) covering purposes, bases, recipients, and retention.
  • Deploy an actual consent management platform — block non-essential cookies until opt-in, equal-prominence "Reject all," log every consent.
  • Build working data-subject-rights mechanics (Arts. 15–20) — delete-account that cascades to backups and sub-processors, export, one-month SLA.
  • Execute Art. 28 DPAs with every processor in your stack.
  • Fix transfers (Ch. V) — move EU data to EU regions where possible or document DPF/SCC reliance for certified US processors.
  • Write the Art. 30 record and a 72-hour breach runbook; appoint an EU/UK representative (Art. 27) if you have no EU establishment.
  • Re-test after every AI regeneration — a regen can silently reintroduce pre-consent tracking or drop a security policy.
What changed recently: The EU-US Data Privacy Framework survived the Latombe challenge (dismissed 2025-09-03) but is on appeal to the CJEU as of 2025-10-31 — keep SCCs as a fallback. The proposed Digital Omnibus (2025-11-19) would raise the Art. 30 recordkeeping exemption to under-750-employee firms, but it remains a proposal, not law, as of July 2026. The EDPB issued AI-specific guidance (Opinion 28/2024, 2024-12-17) confirming that models trained on personal data are generally not anonymous.
FAQ

GDPR compliance questions, answered

Does GDPR apply to my app if my company isn't in the EU?

Yes, if you offer goods or services to people in the EU (even for free) or monitor their behavior through analytics or tracking. Article 3(2) makes this about where your users are located, not where your company is registered.

Do I need a cookie banner on my website?

If you use any non-essential cookie or tracker — analytics, ad pixels, session replay — on EU visitors, yes. Prior opt-in is required, and "Reject all" must be as prominent and functional as "Accept all"; CNIL fined Google €325M and Shein €150M in September 2025 specifically for getting this wrong.

Is my Lovable or Supabase app GDPR compliant by default?

No. CVE-2025-48757 exposed data in Lovable apps built on Supabase without Row Level Security enabled, and roughly 1 in 10 showcased apps were found leaking data. Lovable's own platform DPA and Supabase's EU regions don't fix access-control gaps in your generated app.

What's the difference between a DPA and a BAA?

They serve the same purpose under different laws: a BAA (Business Associate Agreement) is the HIPAA term; a DPA (Data Processing Agreement) is the GDPR equivalent, required under Article 28 with every processor and sub-processor that touches EU personal data.

How much are GDPR fines for a small business or startup?

Penalties scale to the violation and turnover: up to €10M or 2% of global turnover for security/breach failures, and up to €20M or 4% for consent or data-subject-rights violations. Enforcement in 2025 spread well beyond Big Tech into retail, SaaS, and services.

Can I store EU user data on US servers like Vercel or Replit?

Only with a valid transfer mechanism — the EU-US Data Privacy Framework (for certified companies), Standard Contractual Clauses, or Binding Corporate Rules. Replit defaults to GCP US hosting and Vercel offers no permanent EU storage, so you need to actively document how the transfer is lawful.

Would your app survive a GDPR complaint?

We audit AI-built apps against GDPR — consent, RLS, DPAs, transfer mechanisms — and hand you a fix-it list before a regulator or a user complaint finds the gap.

Get a Free Compliance Scan

Related searches: does GDPR apply to my app · GDPR compliance checklist for SaaS · do I need a cookie banner on my website · is Lovable GDPR compliant · is Supabase GDPR compliant · GDPR fines for small business website · GDPR data processing agreement template · GDPR right to be forgotten delete user data app · EU data residency requirements SaaS