View 07 · GDPR Compliance

Full GDPR alignment, by design — not as an afterthought.

LEIP was architected with EU data protection law as a first-class constraint. This chapter walks the Executive Board through the legal basis, the role split, the safeguards in place, and the three myths we hear most often.

Data Controller

the network

Defines the purpose: enforce carbon and compliance accountability across its subcontractor network. Owns the relationship with carriers and the lawful basis for processing their operational data.

Data Processor

ZeroPact

Processes data only under controller instructions, governed by an Art. 28 GDPR Data Processing Agreement. ZeroPact never repurposes carrier data, never sells it, never uses it to train models outside the operator tenant.

Operational safeguards — what the operator gets at contract

Art. 28 Data Processing Agreement
Signed at contract
DPIA (Data Protection Impact Assessment)
Delivered before go-live
Appointed DPO contact
dpo@zeropact.co
Breach notification SLA
≤ 24h to the controller · 72h to CNPD
Sub-processor register
Public, versioned, opt-out window
Right to audit
Annual + on-incident

Three concerns we hear — and the answer

Concern

"Behavioral scoring is automated decision-making under Art. 22."

How LEIP handles it

LEIP scoring informs human auditors — it never produces legal or similarly significant effects on a data subject without human review. A flagged carrier always triggers a human-led Conditional Proof Request before any enforcement action.

Concern

"You're processing driver personal data."

How LEIP handles it

We don't. LEIP operates on vehicle-level and shipment-level data. Where carrier feeds include driver identifiers, ZeroPact pseudonymizes them at ingestion — the controller-side keys are never accessible to ZeroPact.

Concern

"Cloud means data leaves the EU."

How LEIP handles it

LEIP runs on EU-region infrastructure with contractual guarantees against cross-border transfer. We publish the sub-processor list and notify the controller 30 days before any change, with a documented objection right.

Recommendation to the Executive Board

Let's make LEIP your operator standard.
Carbon engine live on day one. Compliance enforcement in 75 days.

Schedule a 30-minute working session with the ZeroPact team to map your subcontractor portfolio onto LEIP and validate the activation plan.