Skip to main content
Glama
CSOAI-ORG

GDPR Compliance for AI Systems MCP Server

README.md
<!-- mcp-name: io.github.CSOAI-ORG/gdpr-compliance-ai-mcp -->

> Verification is free and public: signed measurement cards and live verification at **https://councilof.ai** โ€” measurement, not certification.

[![MCP Scorecard: 86/100](https://img.shields.io/badge/proofof.ai-86%2F100-5b21b6)](https://proofof.ai/scorecard/gdpr-compliance-ai-mcp.html)

# Gdpr Compliance Ai MCP


[![Council of AI](https://img.shields.io/badge/MEOK-AI%20Labs-667eea)](https://councilof.ai)
[![PAYG enabled](https://img.shields.io/badge/PAYG-%C2%A30.05%2Fcall-7c3aed?logo=stripe&logoColor=white&labelColor=1a1a2e)](https://councilof.ai/payg)
[![GSPC](https://img.shields.io/badge/GSPC-UNMEASURED-9ca3af)](https://councilof.ai/api/gspc)
[![License](https://img.shields.io/badge/License-MIT-blue.svg)](LICENSE)
[![PyPI](https://img.shields.io/badge/PyPI-Install-3775a9)](https://pypi.org/project/gdpr_compliance_ai_mcp/)

> GDPR compliance MCP โ€” DPIA automation, Article 30 records, Article 22 automated decision-making a...

GDPR compliance MCP โ€” DPIA automation, Article 30 records, Article 22 automated decision-making audit, data subject request workflow.

---

## ๐Ÿš€ Quick Start

```bash
# Install via pip
pip install gdpr_compliance_ai_mcp

# Or install via Smithery
npx -y @smithery/cli@latest install gdpr-compliance-ai-mcp --client claude
```

## โšก Pay-per-call (PAYG) โ€” no subscription

This MCP supports universal pay-per-call billing across the MEOK compliance fleet:

```bash
# One-time setup
export MEOK_PAYG_KEY="your_topup_token"

# Every tool call now deducts ยฃ0.05 from your balance.
# When balance hits zero, the tool returns a top-up URL.
# Works across all 7 MEOK compliance MCPs with the same token.
```

- **No subscription** โ€” top up once, deduct per call.
- **ยฃ0.05/call default** (configurable via `MEOK_PAYG_RATE_GBP`).
- **USDC on Base L2 accepted** โ€” set `MEOK_X402_RECEIVER` and pay via stablecoin.
- **Backward-compatible** โ€” when `MEOK_PAYG_KEY` is unset, behaviour is unchanged.

**Get a token**: [councilof.ai/payg](https://councilof.ai/payg) (ยฃ10 / ยฃ50 / ยฃ200 top-up tiers).


## โœจ Features

- GDPR Chapter V compliance
- Cross-region data guard
- Data localization
- Transfer mechanism validation
- Breach detection

## ๐Ÿ“– Documentation

- [Full Documentation](https://docs.councilof.ai/gdpr-compliance-ai-mcp)
- [API Reference](https://councilof.ai/api-docs)
- [EU AI Act Compliance Guide](https://councilof.ai)

## ๐Ÿ›ก๏ธ Compliance

This MCP server is built with **EU AI Act compliance** built-in:

- โœ… Article 9 โ€” Risk Management System
- โœ… Article 13 โ€” Transparency & Instructions for Use
- โœ… Article 15 โ€” Bias Detection & Testing
- โœ… Article 26 โ€” FRIA Support (where applicable)
- โœ… Article 50 โ€” AI Content Watermarking (where applicable)

Need help getting compliant? **[Book a free 15-min diagnostic โ†’](mailto:nicholas@councilof.ai?subject=Compliance%20diagnostic)**

## ๐Ÿข Enterprise

Need custom development, SLA guarantees, or white-label deployment?


[View Pricing โ†’](https://councilof.ai/payg) | [Contact Sales โ†’](mailto:sales@councilof.ai)

## ๐Ÿค Part of the MEOK Ecosystem

This server is part of the **[Council of AI](https://councilof.ai)** ecosystem โ€” 26 PyPI packages ยท ~public measurement tools.

| Domain | Purpose |
|--------|---------|
| [councilof.ai](https://councilof.ai) | EU AI Act compliance marketplace |
| [safetyof.ai](https://safetyof.ai) | AI safety & monitoring |
| [councilof.ai](https://councilof.ai) | Sovereign AI platform |
| [cobolbridge.ai](https://cobolbridge.ai) | Legacy modernization |

## ๐Ÿ“œ License

MIT ยฉ [CSOAI-ORG](https://github.com/CSOAI-ORG)

---

<p align="center">
  <sub>Built with ๐Ÿ’œ by <a href="https://councilof.ai">Council of AI</a> ยท UK Companies House 16939677</sub>
</p>


## Configuration

Add to your `claude_desktop_config.json` (Claude Desktop) or your MCP client config:

```json
{
  "mcpServers": {
    "gdpr-compliance-ai-mcp": {
      "command": "uvx",
      "args": ["gdpr-compliance-ai-mcp"]
    }
  }
}
```

Or: `pip install gdpr-compliance-ai-mcp` then run the `gdpr-compliance-ai-mcp` command (stdio transport).

## Examples

Once configured, ask your assistant, for example:
- "Use `classify_processing` to โ€ฆ"
- "Use `lawful_basis_assessment` to โ€ฆ"
- "Use `dpia_generator` to โ€ฆ"

TDQS

A4.1/5.0

Scored across 6 tools

Disambiguation5/5

Each tool addresses a distinct GDPR compliance area (breach notification, processing classification, lawful basis, DPIA, rights requests, and EU AI Act mapping) with no overlap in purpose or functionality.

Naming Consistency5/5

All tool names follow a consistent descriptive_pattern (noun_verb or adjective_noun) using snake_case, e.g., breach_notification, classify_processing, dpia_generator.

Tool Count5/5

With 6 tools, the server covers the essential GDPR compliance tasks for AI systems without being too sparse or overly numerous. The count feels well-scoped for the domain.

Completeness4/5

The tool set covers major AI-relevant GDPR areas (DPIA, lawful basis, rights, breach, and crosswalk to AI Act). Minor gaps exist, such as tools for consent management or records of processing activities, but these are less critical for the stated purpose.

Maintenance

ActivityMaintained
ResponsivenessUnresponsive