GDPR Compliance for AI Systems MCP Server
<!-- mcp-name: io.github.CSOAI-ORG/gdpr-compliance-ai-mcp -->
> Verification is free and public: signed measurement cards and live verification at **https://councilof.ai** โ measurement, not certification.
[](https://proofof.ai/scorecard/gdpr-compliance-ai-mcp.html)
# Gdpr Compliance Ai MCP
[](https://councilof.ai)
[](https://councilof.ai/payg)
[](https://councilof.ai/api/gspc)
[](LICENSE)
[](https://pypi.org/project/gdpr_compliance_ai_mcp/)
> GDPR compliance MCP โ DPIA automation, Article 30 records, Article 22 automated decision-making a...
GDPR compliance MCP โ DPIA automation, Article 30 records, Article 22 automated decision-making audit, data subject request workflow.
---
## ๐ Quick Start
```bash
# Install via pip
pip install gdpr_compliance_ai_mcp
# Or install via Smithery
npx -y @smithery/cli@latest install gdpr-compliance-ai-mcp --client claude
```
## โก Pay-per-call (PAYG) โ no subscription
This MCP supports universal pay-per-call billing across the MEOK compliance fleet:
```bash
# One-time setup
export MEOK_PAYG_KEY="your_topup_token"
# Every tool call now deducts ยฃ0.05 from your balance.
# When balance hits zero, the tool returns a top-up URL.
# Works across all 7 MEOK compliance MCPs with the same token.
```
- **No subscription** โ top up once, deduct per call.
- **ยฃ0.05/call default** (configurable via `MEOK_PAYG_RATE_GBP`).
- **USDC on Base L2 accepted** โ set `MEOK_X402_RECEIVER` and pay via stablecoin.
- **Backward-compatible** โ when `MEOK_PAYG_KEY` is unset, behaviour is unchanged.
**Get a token**: [councilof.ai/payg](https://councilof.ai/payg) (ยฃ10 / ยฃ50 / ยฃ200 top-up tiers).
## โจ Features
- GDPR Chapter V compliance
- Cross-region data guard
- Data localization
- Transfer mechanism validation
- Breach detection
## ๐ Documentation
- [Full Documentation](https://docs.councilof.ai/gdpr-compliance-ai-mcp)
- [API Reference](https://councilof.ai/api-docs)
- [EU AI Act Compliance Guide](https://councilof.ai)
## ๐ก๏ธ Compliance
This MCP server is built with **EU AI Act compliance** built-in:
- โ
Article 9 โ Risk Management System
- โ
Article 13 โ Transparency & Instructions for Use
- โ
Article 15 โ Bias Detection & Testing
- โ
Article 26 โ FRIA Support (where applicable)
- โ
Article 50 โ AI Content Watermarking (where applicable)
Need help getting compliant? **[Book a free 15-min diagnostic โ](mailto:nicholas@councilof.ai?subject=Compliance%20diagnostic)**
## ๐ข Enterprise
Need custom development, SLA guarantees, or white-label deployment?
[View Pricing โ](https://councilof.ai/payg) | [Contact Sales โ](mailto:sales@councilof.ai)
## ๐ค Part of the MEOK Ecosystem
This server is part of the **[Council of AI](https://councilof.ai)** ecosystem โ 26 PyPI packages ยท ~public measurement tools.
| Domain | Purpose |
|--------|---------|
| [councilof.ai](https://councilof.ai) | EU AI Act compliance marketplace |
| [safetyof.ai](https://safetyof.ai) | AI safety & monitoring |
| [councilof.ai](https://councilof.ai) | Sovereign AI platform |
| [cobolbridge.ai](https://cobolbridge.ai) | Legacy modernization |
## ๐ License
MIT ยฉ [CSOAI-ORG](https://github.com/CSOAI-ORG)
---
<p align="center">
<sub>Built with ๐ by <a href="https://councilof.ai">Council of AI</a> ยท UK Companies House 16939677</sub>
</p>
## Configuration
Add to your `claude_desktop_config.json` (Claude Desktop) or your MCP client config:
```json
{
"mcpServers": {
"gdpr-compliance-ai-mcp": {
"command": "uvx",
"args": ["gdpr-compliance-ai-mcp"]
}
}
}
```
Or: `pip install gdpr-compliance-ai-mcp` then run the `gdpr-compliance-ai-mcp` command (stdio transport).
## Examples
Once configured, ask your assistant, for example:
- "Use `classify_processing` to โฆ"
- "Use `lawful_basis_assessment` to โฆ"
- "Use `dpia_generator` to โฆ"
TDQS
Scored across 6 tools
Each tool addresses a distinct GDPR compliance area (breach notification, processing classification, lawful basis, DPIA, rights requests, and EU AI Act mapping) with no overlap in purpose or functionality.
All tool names follow a consistent descriptive_pattern (noun_verb or adjective_noun) using snake_case, e.g., breach_notification, classify_processing, dpia_generator.
With 6 tools, the server covers the essential GDPR compliance tasks for AI systems without being too sparse or overly numerous. The count feels well-scoped for the domain.
The tool set covers major AI-relevant GDPR areas (DPIA, lawful basis, rights, breach, and crosswalk to AI Act). Minor gaps exist, such as tools for consent management or records of processing activities, but these are less critical for the stated purpose.