ACF
acfstandard.io
Developer docs
FR
Mapping

ACF® × GDPR

Mapping of the 17 ACF® cards to the GDPR articles pivotal for agentic systems — notably Art. 22 (automated individual decisions), Art. 30 (records), Art. 35 (DPIA), Art. 37-39 (DPO).

!Warning
GDPR Art. 22 prohibits, in principle, individual decisions made entirely by automated means that produce legal or similarly significant effects. Any agentic architecture that approaches this must demonstrate (a) explicit consent, OR (b) contractual necessity, OR (c) authorisation by Member-State law — and in every case, the right to human intervention is non-negotiable. Card ACF-01 (Decision Map) is designed precisely for this test.

Regulation (EU) 2016/679 — General Data Protection Regulation

GDPR — Regulation (EU) 2016/679. The European data protection regulation. For agentic systems, three articles are pivotal: Art. 22 (automated individual decision-making), Art. 30 (records of processing activities), Art. 35 (DPIA).

ACF® mapping → GDPR

Each row below is an ACF® methodological card and the principal article of the standard it maps to. The mapping is deliberately conservative — when a card covers several articles, only the principal article is cited here. The full multi-standard view is on the matrix.

CardTitleGDPR
ACF-00ACF Sovereignty ScoreArt. 35
ACF-01Decision MapArt. 22
ACF-02Criticality MatrixArt. 35
ACF-03Agentic ConstitutionArt. 25
ACF-04Agent CardArt. 30
ACF-05Supervision & GovernanceArt. 22 + 37-39
ACF-06Kill SwitchArt. 22(3)
ACF-07First Agent DossierArt. 30 + 35
ACF-08Agentic Decision RegisterArt. 30
ACF-09Action & Improvement PlanArt. 24 + 32
ACF-1030-Day Governance AuditArt. 32
ACF-11Agentic Risk AssessmentArt. 35
ACF-12Agent MandateArt. 28 + 24
ACF-13Guided Practical CaseArt. 22
ACF-14Teacher GuideArt. 39
ACF-15Governance SimulationArt. 32
ACF-16Accountability by DesignArt. 5(2) + 24 + 25