GDPR (Regulation (EU) 2016/679) applies to any app or SaaS processing personal data of people located in the EU/EEA — regardless of where the company is based. Enforcement is now aimed squarely at ordinary businesses: roughly €1.2B in fines across 2025, with France's CNIL alone levying €475M in cookie-consent fines in a single week. AI app builders ship no consent banner, no privacy policy, and no erasure mechanism by default — and a Lovable flaw left roughly 1 in 10 showcased apps leaking user data.
Get a Free Compliance Scan See Audit PricingArticle 3 makes GDPR apply to any organization established in the EU, and separately to any non-EU company that offers goods or services to people in the EU (even for free) or monitors their behavior — analytics and tracking included. It's about where the person is located, not their nationality. Mere accessibility of a website from the EU isn't enough to trigger it, but EU-language or EU-currency targeting, EU shipping, or tracking EU visitors is.
| Penalty tier | Maximum | Applies to |
|---|---|---|
| Tier 1 (Art. 83) | €10M or 2% of global turnover | Security & breach failures (Arts. 25, 32, 33) |
| Tier 2 (Art. 83) | €20M or 4% of global turnover | Basic principles, consent, data-subject rights, unlawful transfers |
Recent enforcement shows the scale: TikTok was fined €530M by Ireland's DPC in May 2025 (€485M for unlawful EEA→China transfers, €45M for transparency failures, with a 6-month deadline to comply). France's CNIL fined Google €325M and Shein €150M in September 2025 for tracking before consent and a non-functional "Reject all" button — exactly the default behavior of most AI-generated analytics setups. Cumulative GDPR fines have passed €7.1B since 2018 across 3,195+ actions, with an average fine around €2.4M.
Sources: gdpr-info.eu; Irish DPC (TikTok, 2025-05-02); CNIL (Google/Shein, Sept 2025); enforcementtracker.com; CMS GDPR Enforcement Tracker Report 2025/2026.
| Requirement | What it means for your app |
|---|---|
| Lawful basis & consent (Art. 6/7) | One of six legal bases for every processing activity; consent must be freely given, specific, informed, and as easy to withdraw as to give — pre-ticked boxes are invalid. |
| Data-subject rights (Art. 15–20) | Real access, rectification, erasure ("right to be forgotten"), restriction, and machine-readable export — respond within one month. |
| Privacy by design/default (Art. 25) | Data minimization and protective defaults built in at construction time, not bolted on later. |
| Security of processing (Art. 32) | Encryption at rest/in transit, access controls, pseudonymization, tested backups — an exposed database is a direct Art. 32 violation. |
| Breach notification (Art. 33/34) | Notify the supervisory authority within 72 hours of awareness; notify high-risk users without undue delay. |
| Records of processing (Art. 30) | Written register of what data, why, retention, and recipients — the <250-employee exemption doesn't apply if processing is non-occasional or risky, which covers most apps. |
| Processor contracts (Art. 28) | A signed Data Processing Agreement with every processor and sub-processor — the GDPR equivalent of a HIPAA BAA. |
| International transfers (Ch. V) | Data can leave the EEA only via adequacy decision, the EU-US Data Privacy Framework, Standard Contractual Clauses, or Binding Corporate Rules. |
| Cookie consent (ePrivacy + GDPR) | Prior opt-in before any non-essential cookie or tracker fires; "Reject all" must be as prominent as "Accept all" and must actually work. |
Sources: gdpr-info.eu Art. 3/6/7/25/28/30/32/33/83; EDPB Guidelines 3/2018; iubenda.com cookie/GDPR requirements.
Net effect: a vibe-coded app with EU users typically violates Articles 6, 13, 17, 25, 28, 32, and the Chapter V transfer rules on the day it launches.
Sources: thenextweb.com (Lovable vibe-coding security crisis); blog.barracuda.com (2025-12-22, 40-62% of AI code has vulnerabilities); debevoisedatablog.com.
| Platform | DPA | EU residency |
|---|---|---|
| Lovable | Yes — public, EU SCCs Modules 2&3 + UK Addendum (signed 2025-11-17); ISO 27001:2022 | Region selectable EU/US/AU (Lovable Cloud); platform DPA doesn't fix the generated app's own RLS gaps |
| Bolt (StackBlitz) | "Where applicable" (enterprise); policy updated 2026-05-12 | None; not DPF-certified — weakest documented posture |
| Replit | Yes (replit.com/dpa, EEA/Swiss/UK auto-bound) + SCCs | GCP US data centers; no dedicated EU residency for deployments |
| v0 / Vercel | Yes (vercel.com/legal/dpa); EU-US DPF certified | No permanent EU storage — EU caching is ephemeral only |
| Base44 (Wix) | Yes (base44.com/dpa; GDPR/UK GDPR + SCCs) | No standalone EU-residency guarantee |
| Supabase | Yes (2025-03-14) + SCCs + published sub-processor list; SOC 2 Type II | Genuine EU region selection — Frankfurt, Ireland, London, Paris (AWS); Supabase Inc. itself is US-based (CLOUD Act debate remains) |
| OpenAI | Yes + SCCs + sub-processor list | European API data residency launched Feb 2025 (new Projects only, approval-gated) |
| Anthropic | Yes, effective 2025-02-24, auto-incorporated + SCC Modules 2/3 | No native EU residency (US inference); EU alt via Claude on AWS Bedrock Frankfurt |
Signing these DPAs is on the customer, not automatic — and every one of them covers the builder's own platform, not the analytics or ad SDKs your generated app embeds.
Sources: lovable.dev/data-processing-agreement; stackblitz.com/privacy-policy; replit.com/dpa; vercel.com/legal/dpa; base44.com/dpa; supabase.com/legal/dpa; openai.com/index/introducing-data-residency-in-europe; privacy.claude.com data-processing-addendum.
Yes, if you offer goods or services to people in the EU (even for free) or monitor their behavior through analytics or tracking. Article 3(2) makes this about where your users are located, not where your company is registered.
If you use any non-essential cookie or tracker — analytics, ad pixels, session replay — on EU visitors, yes. Prior opt-in is required, and "Reject all" must be as prominent and functional as "Accept all"; CNIL fined Google €325M and Shein €150M in September 2025 specifically for getting this wrong.
No. CVE-2025-48757 exposed data in Lovable apps built on Supabase without Row Level Security enabled, and roughly 1 in 10 showcased apps were found leaking data. Lovable's own platform DPA and Supabase's EU regions don't fix access-control gaps in your generated app.
They serve the same purpose under different laws: a BAA (Business Associate Agreement) is the HIPAA term; a DPA (Data Processing Agreement) is the GDPR equivalent, required under Article 28 with every processor and sub-processor that touches EU personal data.
Penalties scale to the violation and turnover: up to €10M or 2% of global turnover for security/breach failures, and up to €20M or 4% for consent or data-subject-rights violations. Enforcement in 2025 spread well beyond Big Tech into retail, SaaS, and services.
Only with a valid transfer mechanism — the EU-US Data Privacy Framework (for certified companies), Standard Contractual Clauses, or Binding Corporate Rules. Replit defaults to GCP US hosting and Vercel offers no permanent EU storage, so you need to actively document how the transfer is lawful.
We audit AI-built apps against GDPR — consent, RLS, DPAs, transfer mechanisms — and hand you a fix-it list before a regulator or a user complaint finds the gap.
Get a Free Compliance ScanRelated searches: does GDPR apply to my app · GDPR compliance checklist for SaaS · do I need a cookie banner on my website · is Lovable GDPR compliant · is Supabase GDPR compliant · GDPR fines for small business website · GDPR data processing agreement template · GDPR right to be forgotten delete user data app · EU data residency requirements SaaS