GDPR Compliance
NoPII supports GDPR right-to-erasure through the token purge feature in the admin console. When a data subject requests deletion, you can remove their tokens and all associated audit log entries directly from the console.
How NoPII supports GDPR
- 1PII never reaches the LLM - Tokenization ensures no personal data is stored by OpenAI, Anthropic, or any other provider.
- 2Audit trail without PII - The audit log records entity types and tokens, never plaintext PII.
- 3Right to erasure - The token purge feature in the admin console deletes tokens, audit entries, and session caches for specific individuals.
- 4Automatic token expiration - Vault tokens expire automatically based on configurable TTL policies, supporting data minimization. Expired tokens are permanently deleted without manual intervention.
Token purge
You can purge tokens from the admin console. Provide the plaintext PII values belonging to the data subject, and NoPII will search for and delete the matching tokens along with all associated audit log entries. You can submit up to 1,000 plaintext values per purge request.
What happens during a purge
- 1Search - NoPII searches for existing tokens matching each plaintext value. No new tokens are created.
- 2Delete tokens - Matching tokens are permanently deleted.
- 3Purge audit log - Audit log entries referencing the deleted tokens are removed.
- 4Invalidate caches - Active session caches containing the deleted tokens are invalidated.
Purge by token value
If you have token values rather than the original plaintext (e.g., from audit log entries), the admin console also supports purging directly by token value.
Audit log scrubbing
When tokens are purged, NoPII also scrubs the audit log. Token values in audit entries are replaced with null, and each scrubbed entry is stamped with purged_at and purged_by (the admin who initiated the purge) for compliance audit trails.
Active session cleanup
Purged tokens are automatically removed from all active sessions. This prevents deleted PII from being served from the in-memory session cache after a purge.
Automatic token expiration
In addition to on-demand purge, NoPII supports automatic token expiration through configurable TTL (time-to-live) policies. This supports GDPR's data minimization principle by ensuring tokenized PII is not retained longer than necessary.
Free tier tokens expire after 1 day. Pro tier can configure retention from 1 day to permanent in the admin console. When a token expires, the underlying PII is permanently deleted from the vault.
TTL-based expiration and manual purge are complementary. Use TTL for automatic lifecycle management and purge for specific data subject erasure requests. See Billing & Pricing for plan-specific TTL details.
Related
- How It Works - Understand how PII is tokenized and why it never reaches the LLM
- API Reference - Full endpoint documentation