dtwo Policy Store
GDPR · DATA MINIMISATION

GDPR-aligned controls for AI agents handling personal data

Almost every connector an agent touches holds personal data. These policies support GDPR and CCPA-aligned minimisation and special-category controls on the MCP path.

For: Privacy and data-governance owners with EU or California exposure

GDPR's data-minimisation principle (Art. 5(1)(c)) asks that processing touch only the personal data a task needs — and an agent, left alone, does the opposite. It pulls whole mailboxes, full record sets, and entire conversation histories into its context because nothing tells it not to. The agent channel is exactly where minimisation can be enforced.

These policies support alignment with the minimisation, special-category, and by-default controls (Arts. 5, 9, 25, 32; CPRA §1798.121) on that channel. cap-bulk-export clamps how much a single call returns. redact-pii-egress and redact-conversation-pii mask personal and special-category data in responses across files, CRM, and support tools. fence-user-directory keeps the agent out of people-directory data unless it's authorized.

Be candid about the edges: this covers the MCP path, not data-subject-rights fulfilment, lawful basis, retention, or cross-border transfer mechanisms — those stay with your privacy program. What the bundle adds is a demonstrable minimisation control on the one surface agents actually use.

Policies in this guide