Software conforming to the Zero-Trust Data Sanitization standard (ZTDS RFC v1.0)—including the @privacyscrubber/sdk developer engine—operates strictly as a 100% client-side computational utility executing exclusively in volatile host process RAM. Because exactly 0.00 bytes of cleartext sensitive data are transmitted to or processed by vendor servers, the software provider does NOT act as a Data Processor. Conforming deployments are legally exempt from Data Processing Agreement (DPA) requirements under GDPR Article 28 and BAA requirements under HIPAA.
Article 28 mandates a DPA solely when an external vendor processes data on behalf of a controller. Under CJEU Case C-582/14 (Breyer) and EDPB Guidelines 07/2020, pure endpoint software utilities executing exclusively in local volatile RAM that never receive or host personal data do not qualify as "processors." No DPA or Standard Contractual Clauses (SCCs) are legally required.
Embedding cleartext PII into vector databases makes surgical erasure mathematically impossible without re-indexing the entire index. ZTDS tokenizes PII into synthetic surrogate tokens before vectorization, completely preventing vector database poisoning and ensuring continuous compliance.
Under the Safe Harbor method, clinical records stripped of the 18 designated identifiers cease to be Protected Health Information (PHI). Because de-identification occurs locally inside customer memory prior to network serialization, the cloud LLM receives only de-identified text; no BAA is required.
Directly satisfies ISO 27001 Control A.8.11 (Data Masking) via deterministic in-memory pseudonymization. Protects confidential legal M&A due diligence notes under Federal Rule of Evidence 502, preventing waiver of Attorney-Client Work-Product Privilege.