A technical-control map for EU AI Act and GDPR obligations — not legal advice or a certification. Applicability depends on your deployed use case, data, operator role, and surrounding system.
SuperLocalMemory ships a per-mode EU AI Act self-assessment. It is a technical-control map, not a legal certification — applicability depends on deployment, data, operator role, and surrounding system.
Self-assessment tooling, not a certification. Checker results cover the core memory-content path only. Optional connectors, backups, client applications, and model downloads retain their own network behavior and must be assessed separately.
Technical controls that can support GDPR subject-rights procedures. The operator must validate completeness against the full deployment, including derived stores, backups, clients, and logs.
slm export. Supplies all stored memory records for a workspace. Verify completeness across indexes, logs, backups, and surrounding systems.Three roles per workspace. Workspaces are isolated — one workspace cannot read another workspace's memories. Single-user installs require no login.
require_login setting activates authentication; first-run admin account creation is required; no default credentials shipped.Bounded-loop runs write a durable, auditable ledger. Each iteration is tagged and reviewable — relevant for human-oversight and traceability obligations under EU AI Act Art. 14.
How each relevant EU AI Act and GDPR requirement maps to Mode A and Mode C in the built-in checker. Self-assessment posture only — not a legal compliance determination.
| Article | Scope | Mode A self-assessment posture | Mode C self-assessment posture |
|---|---|---|---|
| Art. 10 — Data Governance | Data quality, relevance, and representativeness requirements may apply to the complete system. | ✓ local path Local controls and export tools provide evidence; the operator verifies data quality and governance. | ⚑ provider-flagged Provider processing and terms become part of the assessment. |
| Art. 13 — Transparency | Applicable systems may need information that lets deployers interpret outputs. | ✓ local path Candidate, fusion, and reranker diagnostics provide retrieval evidence. | ⚑ provider-flagged Model synthesis adds another component to document. |
| Art. 14 — Human Oversight | Humans must be able to understand, intervene, and override AI decisions. | ✓ local path Full dashboard visibility. Trust gates. Manual memory management. | ✓ local path Same oversight tools available. Cloud LLM output can be reviewed before use. |
| GDPR Art. 15 — Right of Access | Applicable deployments may need a complete subject-access procedure. | ✓ local path SLM export tools supply part of the evidence; indexes, logs, backups, clients, and surrounding systems remain in scope. | ⚑ provider-flagged Include provider-held data and logs in the complete procedure. |
| GDPR Art. 17 — Right to Erasure | Applicable deployments may need verified erasure across every copy and processor. | ✓ local path Hard delete with verification; operation logged before execution. Verify derived state, backups, and surrounding systems separately. | ⚑ provider-flagged Verify local deletion and the provider's deletion and retention process. |
| GDPR Art. 20 — Right to Portability | Applicable deployments may need structured, machine-readable export for portability. | ✓ local path SLM export produces structured, machine-readable JSON output. Verify completeness against all local data stores. | ⚑ provider-flagged Include provider-held data representations in the portability scope. |
"Local path" and "provider-flagged" are outputs of the built-in checker — not legal determinations. Mode B follows the same local-path assessment as Mode A. Engage qualified legal counsel for the complete compliance evaluation of your deployed system.