# Mindset AI's Compliance Architecture

> You're reading the Mindset v3 documentation. v3 is no longer sold; this is reference for existing customers. Mindset 4 docs are at /docs.

Learn more about how we meet compliance requirements

We've built Agent Memory to not just meet compliance requirements, but to make compliance effortless for your organization:

**Automatic Legal Framework Compliance**

Agent Memory provides built-in compliance with:

- **EU AI Act (2024)**: Automatic logging, human oversight, and decision transparency with 6+ month retention requirements
- **GDPR (European Union)**: Complete data subject rights with 30-day response automation covering all Articles 15-22
- **CCPA/CPRA (California)**: Consumer rights management with 45-day processing and comprehensive deletion capabilities
- **US State Privacy Laws**: Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA) coverage
- **PIPEDA (Canada)**: Full accountability and access rights implementation following 10 Fair Information Principles

**Built-In Data Subject Rights**

Every compliance requirement becomes a simple admin action:

- **Right to Access**: Users can ask agents _"Show me what you know about me"_ or administrators can instantly view all collected facts through the Human Facts interface.
- **Right to Rectification**: When someone says _"Update my job title to Senior Manager,"_ the system processes the change immediately across all agent memories with full audit trails.
- **Right to Erasure**: Whether someone requests _"Delete my communication preferences"_ or complete erasure, the system ensures removal from all memories, backups, and connected systems.
- **Right to Portability**: One-click exports provide professionally formatted data in machine-readable formats, complete with collection context and metadata.
