How does iDBQuery help with GDPR obligations?

iDBQuery is designed to support your GDPR obligations through architecture: it minimises data movement by querying sources in place, lets you choose where data resides (including your own VPC or fully air-gapped), enforces role-based access, and cites every figure to its source rows so you can answer access and deletion requests precisely.

iDBQuery doesn't make GDPR someone else's promise — it gives you the architecture to meet your own obligations. A few principles line up directly with the regulation.

  • Data minimisation. iDBQuery queries your sources in place and builds one live model instead of force-copying everything into a warehouse, so personal data isn't needlessly duplicated.
  • Residency and control. Deploy in the region you choose, inside your own VPC, on a single on-premise server, or fully air-gapped, so personal data can stay within a specific jurisdiction and never leave your perimeter.
  • Access controls. Role-based access limits who can reach which sources, enforced on every query.
  • Right of access and erasure. Because every answer is cited to its exact source rows, you can locate precisely where an individual's data appears, and because iDBQuery holds little beyond metadata and cached results, honouring a deletion request is straightforward.
  • No secondary use. Your data isn't used to train any AI model — it's used only to answer your questions.

A note on honesty: this is about supporting your GDPR programme, not a certification. iDBQuery gives you the technical means — minimisation, residency, access control, auditability and precise lineage — while you remain the data controller. For teams with strict legal requirements, the air-gapped and Desktop deployment options are usually the deciding factor, because personal data can be analysed in plain language while never crossing your organisation's boundary.

Updated 2026-06-22